{"data":{"skill":{"slug":"atri10-executor-planning","name":"executor-planning","icon":"📦","repo":"https://github.com/atri10/executor/tree/39ddcfe1d9f3497102622b72aa235fb0770187fe/skills/executor-planning","status":"approved","author":"atri10","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"340c0631-82ba-40de-95bd-bd2b2cecbb9f","skill_id":"3860bb62-b190-4001-8d41-8cc43a77f6f9","version":1,"content_hash":"v3:6d0b11444384184b7ae743742a7e233a9a705cd9:649171eec3e1639ce56df65ec31b51523417bd74567b35889e04e9ea00648ebc:495b7c8a460c49d25f609b12c8a79c67b3c4cfbe26e0b7be56c8072919ae312b:736b696c6c732f6174726931302f6578656375746f722d706c616e6e696e67:d9bba711f46482c9a87299ffc36e586c","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most of the 221 static findings are Markdown formatting, legitimate companion references, or routine planning commands. Two temporary-file findings remain confirmed, and a semantic finding identifies overly broad Git staging. No evidence found of prompt injection or exfiltration; companion script implementations are outside the reviewed package.","remediation":[{"issue":"Brief verification writes and reads a predictable shared temporary file.","severity":"medium","suggestion":"Create a private temporary directory with mktemp, stop on extraction failure, and read only successfully generated briefs. Clean up with a trap."},{"issue":"Directory-wide Git staging can include unrelated initiative files.","severity":"medium","suggestion":"Stage only the reviewed plan, index, and specification files. Inspect the staged diff and scan every staged file for secrets before committing."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":8,"line_start":8},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":45,"line_start":44},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":83,"line_start":79},{"file":"SKILL.md","line_end":85,"line_start":83},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":93,"line_start":88},{"file":"SKILL.md","line_end":95,"line_start":93},{"file":"SKILL.md","line_end":96,"line_start":95},{"file":"SKILL.md","line_end":101,"line_start":96},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":116,"line_start":113},{"file":"SKILL.md","line_end":119,"line_start":116},{"file":"SKILL.md","line_end":121,"line_start":119},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":122,"line_start":122},{"file":"SKILL.md","line_end":128,"line_start":126},{"file":"SKILL.md","line_end":128,"line_start":128},{"file":"SKILL.md","line_end":132,"line_start":129},{"file":"SKILL.md","line_end":167,"line_start":132},{"file":"SKILL.md","line_end":169,"line_start":167},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":176,"line_start":176},{"file":"SKILL.md","line_end":177,"line_start":177},{"file":"SKILL.md","line_end":193,"line_start":190}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":473,"line_start":473},{"file":"SKILL.md","line_end":570,"line_start":570},{"file":"SKILL.md","line_end":580,"line_start":580},{"file":"SKILL.md","line_end":637,"line_start":637},{"file":"SKILL.md","line_end":640,"line_start":640},{"file":"SKILL.md","line_end":644,"line_start":644},{"file":"SKILL.md","line_end":676,"line_start":676},{"file":"SKILL.md","line_end":685,"line_start":685},{"file":"SKILL.md","line_end":687,"line_start":687},{"file":"SKILL.md","line_end":707,"line_start":707},{"file":"SKILL.md","line_end":749,"line_start":749},{"file":"SKILL.md","line_end":581,"line_start":581},{"file":"SKILL.md","line_end":581,"line_start":581},{"file":"SKILL.md","line_end":582,"line_start":582}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Temp directory access","locations":[{"file":"SKILL.md","line_end":581,"line_start":581}],"confidence":0.75,"description":"\"$n\" /tmp/brief-check.md >/dev/null || echo \"TASK $n FAILS\"","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The example writes each brief to a predictable shared temporary pathname without showing exclusive creation. Concurrent runs or precreated links could corrupt or redirect output."},{"title":"Temp directory access","locations":[{"file":"SKILL.md","line_end":582,"line_start":582}],"confidence":0.7,"description":"grep -m1 '^\\*\\*Task:\\*\\*' /tmp/brief-check.md","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The loop reads the same shared temporary file even after extraction failure. Stale output or another concurrent run could substitute the task identity being verified."},{"title":"Broad Git Staging Can Include Unrelated Changes","locations":[{"file":"SKILL.md","line_end":715,"line_start":710}],"confidence":0.95,"description":"The handoff runs 'git add docs/executor/INIT-0004-cloud-tenant-cells' before committing. Directory-wide staging can include unrelated or sensitive initiative files beyond the intended plan, index, and specification updates.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The example explicitly stages the entire initiative directory instead of the three intended document updates. Actual exposure depends on other changes in that directory."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":773,"audit_model":"codex","audited_at":"2026-10-05T18:00:28.775+00:00","created_at":"2026-10-06T06:52:30.513434+00:00","static_findings":[{"id":"external_commands:SKILL.md:8:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Turn `INIT-NNNN-SPEC-nn` into `INIT-NNNN-Pnn`: a document whose every task","category":"external_commands","line_end":8,"severity":"medium","line_start":8},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"That framing is not politeness. Under `executor-execution` each task is","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `../executor/SKILL.md` | ID grammar, citation rule, phase gates, rulings policy |","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `../executor/references/frontmatter.md` | plan frontmatter is contract, not style |","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `../executor/references/layout.md` | plans live in `plans/`, nothing else |","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `../executor/references/indexes.md` | the two index updates planning owns |","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The spec `INIT-NNNN-SPEC-nn` | the plan argues from it; you copy from it |","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Its `INIT-NNNN-IFCE-nn` | every signature you write comes from here |","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The ADRs the spec lists in `decisions:` | a plan that reopens a decided question is a defect |","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prerequisites.** The spec's phase gate passed (`status: active`, phase log","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"row for `specification` has a gate date). No approved spec → stop; route to","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`executor-spec`. No interface document and the work spans components → stop;","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"route to `executor-architecture`. Planning does not invent structure.","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Brainstorm the decomposition first — required.** `exec-initiative phase","category":"external_commands","line_end":45,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"planning: an `executor-brainstorm` decision session (`feeds: [planning]`,","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`status: active`) that compared at least three ways to split the spec into","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"spike — and recorded the human's pick. The design session's `## Handoff`","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"plan's own initiative. A task needing something from `INIT-0002` states the","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"initiative INDEX `depends_on`.","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `INIT-0004-SPEC-01-R07` | requirement 7 of that spec |","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `INIT-0004-SPEC-01-C03` | global constraint 3 of that spec |","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"These never collide with review rounds: a round ID always carries a `-T<nn>-`","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"segment before its `-R<nn>` (`INIT-0004-P01-T03-R02`), while a requirement","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"hangs off `-SPEC-<nn>-`. Requirement IDs are what make the spec-coverage","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Plans are numbered per-initiative from `01`: `INIT-0004-P01`,","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INIT-0004-P02`. Allocate by **listing `plans/` immediately before writing**","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and taking the next free number — or let `exec-id` do both:","category":"external_commands","line_end":77,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":83,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":85,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-id` handles the plan kind correctly: `P` is the one kind whose grammar","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"has no separator, so it prints `INIT-0004-P01`, never `INIT-0004-P-01`. Its","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INIT-0004-P01` reserves its number even when the file sits in the wrong","category":"external_commands","line_end":93,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INDEX.md`. Never overwrite.","category":"external_commands","line_end":95,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"File path: `<initiative>/plans/INIT-0004-P01-<topic-slug>.md`. The slug is","category":"external_commands","line_end":96,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"cosmetic; every script resolves through the `id:` frontmatter field, so","category":"external_commands","line_end":101,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Split into `P01`, `P02`, ... when the spec covers subsystems that can ship","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and every later plan carries an `## Assumes` section naming exactly what it","category":"external_commands","line_end":116,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":119,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INIT-0004-P01` has landed and provides:","category":"external_commands","line_end":121,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `placeCell(tenantId: str, weight: int) -> CellId` in `src/cells/placement.py`","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `class CellId(NamedTuple): region: str; index: int` in `src/cells/types.py`","category":"external_commands","line_end":122,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":128,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Ordering statement in `P01`: `Execution order: P01 → P02 → P03. P02 does not","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"start until P01's final review is clean.`","category":"external_commands","line_end":132,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the requirement IDs it covers (`Covers: R01-R06, R11`), so no requirement","category":"external_commands","line_end":167,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Number contiguously from 1 within the plan | `exec-brief PLAN N` finds a task by its heading ordin","category":"external_commands","line_end":169,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Tasks are `T01`...`Tnn` **per plan**. `P02` starts again at `T01`; the plan","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-brief` extracts a task by scanning from its `Task N` heading to the","category":"external_commands","line_end":176,"severity":"medium","line_start":176},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**next `Task` heading or end of file**. Verified: a `## Dependency Map`","category":"external_commands","line_end":177,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. Assumes — `P02` and later only","category":"external_commands","line_end":193,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"8. `## Tasks`, then `### Task 1` ... `### Task N` and nothing else","category":"external_commands","line_end":193,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":218,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":222,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `id` | matches the filename's ID segment; scripts resolve the workspace from it |","category":"external_commands","line_end":223,"severity":"medium","line_start":222},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `spec` | the one spec this plan argues from; copied into every brief header |","category":"external_commands","line_end":224,"severity":"medium","line_start":223},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `interfaces` | every IFCE document a task's signatures came from |","category":"external_commands","line_end":225,"severity":"medium","line_start":224},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `tasks` | the actual count of `### Task` headings — fix it when you add one |","category":"external_commands","line_end":225,"severity":"medium","line_start":225},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `execution_mode` | `null` until the human picks; then `subagent` or `inline` |","category":"external_commands","line_end":226,"severity":"medium","line_start":226},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `workspace` | `.executor/<INIT>/<Pnn>` — must equal what `exec-workspace` computes from `id`, or t","category":"external_commands","line_end":227,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `status` | `draft` while writing, `active` when the human picks a mode |","category":"external_commands","line_end":228,"severity":"medium","line_start":228},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":235,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **For agentic workers:** dispatch this plan with `executor-execution`.","category":"external_commands","line_end":236,"severity":"medium","line_start":235},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Steps use checkbox (`- [ ]`) syntax for tracking. Do not begin Task 1","category":"external_commands","line_end":242,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INIT-0004-ARCH-01`]","category":"external_commands","line_end":246,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Spec:** `INIT-0004-SPEC-01` — `specs/INIT-0004-SPEC-01-cell-placement.md`","category":"external_commands","line_end":246,"severity":"medium","line_start":246},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Covers:** `R01`-`R06`, `R11` of `INIT-0004-SPEC-01`","category":"external_commands","line_end":248,"severity":"medium","line_start":248},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":261,"severity":"medium","line_start":249},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":266,"severity":"medium","line_start":261},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `C01` — Python >= 3.11; no new runtime dependencies beyond `pydantic>=2.6`.","category":"external_commands","line_end":266,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `C02` — All public functions carry type annotations; `mypy --strict` passes.","category":"external_commands","line_end":267,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `C03` — User-visible strings use the exact copy in `INIT-0004-SPEC-01 §4`.","category":"external_commands","line_end":268,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `C04` — No network calls in unit tests.","category":"external_commands","line_end":270,"severity":"medium","line_start":269},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":272,"severity":"medium","line_start":270},{"id":"external_commands:SKILL.md:272:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"IDs are the spec's own (`INIT-0004-SPEC-01-C03`, shortened to `C03` inside","category":"external_commands","line_end":272,"severity":"medium","line_start":272},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":290,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Source of truth: `INIT-0004-IFCE-01` —","category":"external_commands","line_end":291,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`architecture/INIT-0004-IFCE-01-service-contracts.md`. Signatures below are","category":"external_commands","line_end":294,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `placeCell(tenantId: str, weight: int) -> CellId`","category":"external_commands","line_end":295,"severity":"medium","line_start":294},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `evictCell(cell: CellId, reason: EvictReason) -> None`","category":"external_commands","line_end":296,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `class EvictReason(StrEnum): DRAIN; OVERLOAD; MANUAL`","category":"external_commands","line_end":297,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":300,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"to `executor-architecture`, get the interface defined, then resume. Do not","category":"external_commands","line_end":308,"severity":"medium","line_start":300},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"to `executor-execution`'s preflight scan; produce it here rather than making","category":"external_commands","line_end":311,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":316,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| T02 | T04 | `src/cells/types.py` | `CellId` NamedTuple definition |","category":"external_commands","line_end":316,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| T02 | T05 | `src/cells/types.py` | `CellId` NamedTuple definition |","category":"external_commands","line_end":317,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| T03 | T05 | `placeCell()` | signature and `CellError` raise contract |","category":"external_commands","line_end":318,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| T04 | T06 | `src/cells/router.py` | `Router.dispatch()` added, T06 extends it |","category":"external_commands","line_end":319,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":339,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":340,"severity":"medium","line_start":339},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Task 3: Cell placement scoring — `INIT-0004-P01-T03`","category":"external_commands","line_end":341,"severity":"medium","line_start":340},{"id":"external_commands:SKILL.md:341:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":345,"severity":"medium","line_start":341},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Heading starts `### Task <N>:` with the literal word `Task` and the ordinal | `exec-brief PLAN N` ","category":"external_commands","line_end":345,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:346:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The ID matches `INIT-NNNN-Pnn-Tnn` and sits on the heading line | `exec-brief` **errors out**; the","category":"external_commands","line_end":346,"severity":"medium","line_start":346},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The `Tnn` digits equal the heading ordinal, zero-padded | brief, report, diff, and verdict filenam","category":"external_commands","line_end":352,"severity":"medium","line_start":347},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"````markdown","category":"external_commands","line_end":353,"severity":"medium","line_start":352},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Task 3: Cell placement scoring — `INIT-0004-P01-T03`","category":"external_commands","line_end":355,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Implements:** `INIT-0004-SPEC-01-R04`, `INIT-0004-SPEC-01-R05`","category":"external_commands","line_end":355,"severity":"medium","line_start":355},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Constraints restated here:** `C01` (Python >= 3.11), `C02` (`mypy --strict`)","category":"external_commands","line_end":356,"severity":"medium","line_start":356},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Depends on:** `INIT-0004-P01-T02` — or `none` for the first task","category":"external_commands","line_end":357,"severity":"medium","line_start":357},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Create: `src/cells/scoring.py`","category":"external_commands","line_end":361,"severity":"medium","line_start":360},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Modify: `src/cells/placement.py:88-104`","category":"external_commands","line_end":362,"severity":"medium","line_start":361},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Test: `tests/cells/test_scoring.py`","category":"external_commands","line_end":365,"severity":"medium","line_start":362},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Consumes: `class CellId(NamedTuple): region: str; index: int` from","category":"external_commands","line_end":366,"severity":"medium","line_start":365},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`src/cells/types.py` (Task 2)","category":"external_commands","line_end":367,"severity":"medium","line_start":366},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Produces: `score(cell: CellId, load: int) -> float` — returns 0.0..1.0,","category":"external_commands","line_end":368,"severity":"medium","line_start":367},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"raises `ValueError` when `load < 0`. Task 5 calls this.","category":"external_commands","line_end":368,"severity":"medium","line_start":368},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"I/O (`INIT-0004-SPEC-01-R05`).","category":"external_commands","line_end":375,"severity":"medium","line_start":371},{"id":"external_commands:SKILL.md:375:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":382,"severity":"medium","line_start":375},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":386,"severity":"medium","line_start":382},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run: `pytest tests/cells/test_scoring.py -v`","category":"external_commands","line_end":387,"severity":"medium","line_start":386},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Expected: FAIL — `NameError: name 'score' is not defined`","category":"external_commands","line_end":391,"severity":"medium","line_start":387},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Sketch — the `Produces` signature, the `ValueError` contract, and purity are","category":"external_commands","line_end":391,"severity":"medium","line_start":391},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":399,"severity":"medium","line_start":394},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":403,"severity":"medium","line_start":399},{"id":"external_commands:SKILL.md:403:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run: `pytest tests/cells/test_scoring.py -v`","category":"external_commands","line_end":408,"severity":"medium","line_start":403},{"id":"external_commands:SKILL.md:408:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Check the implementation against the rest of `src/cells/` for duplication","category":"external_commands","line_end":412,"severity":"medium","line_start":408},{"id":"external_commands:SKILL.md:412:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run: `pytest tests/cells/test_scoring.py -v`","category":"external_commands","line_end":416,"severity":"medium","line_start":412},{"id":"external_commands:SKILL.md:416:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"````","category":"external_commands","line_end":427,"severity":"medium","line_start":416},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `**Files:**` create/modify/test lists | contract — verbatim; the implementer writes only these |","category":"external_commands","line_end":428,"severity":"medium","line_start":427},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Consumes:`/`Produces:` signatures and error contracts | contract — verbatim |","category":"external_commands","line_end":428,"severity":"medium","line_start":428},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `**Implements:**` requirement IDs | contract — what the reviewer grades against |","category":"external_commands","line_end":449,"severity":"medium","line_start":431},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"out, the design belongs upstream (IFCE, ADR, or a thicker `Consumes:`/","category":"external_commands","line_end":450,"severity":"medium","line_start":449},{"id":"external_commands:SKILL.md:450:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`Produces:` contract) — not in the task body.","category":"external_commands","line_end":459,"severity":"medium","line_start":450},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"NameError: name 'score' is not defined` is a correct RED; `FAIL` alone is","category":"external_commands","line_end":460,"severity":"medium","line_start":460},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[`../executor/references/test-quality.md`](../executor/references/test-quality.md):","category":"external_commands","line_end":509,"severity":"medium","line_start":473},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"be reading tasks out of order**, and under `executor-execution` they are","category":"external_commands","line_end":530,"severity":"medium","line_start":509},{"id":"external_commands:SKILL.md:530:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**1. Spec coverage.** Walk the spec's requirement IDs in order — `R01`,","category":"external_commands","line_end":531,"severity":"medium","line_start":530},{"id":"external_commands:SKILL.md:531:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`R02`, ... — and name the task that implements each. Write the mapping down;","category":"external_commands","line_end":537,"severity":"medium","line_start":531},{"id":"external_commands:SKILL.md:537:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `R01` | T01 |","category":"external_commands","line_end":538,"severity":"medium","line_start":537},{"id":"external_commands:SKILL.md:538:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `R02` | T01 |","category":"external_commands","line_end":539,"severity":"medium","line_start":538},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `R03` | T02 |","category":"external_commands","line_end":540,"severity":"medium","line_start":539},{"id":"external_commands:SKILL.md:540:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `R04` | T03 |","category":"external_commands","line_end":541,"severity":"medium","line_start":540},{"id":"external_commands:SKILL.md:541:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `R05` | T03 |","category":"external_commands","line_end":542,"severity":"medium","line_start":541},{"id":"external_commands:SKILL.md:542:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `R06` | T04 |","category":"external_commands","line_end":543,"severity":"medium","line_start":542},{"id":"external_commands:SKILL.md:543:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `R11` | T07 |","category":"external_commands","line_end":549,"severity":"medium","line_start":543},{"id":"external_commands:SKILL.md:549:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"later tasks match what earlier tasks defined? `clearLayers()` in Task 3 and","category":"external_commands","line_end":550,"severity":"medium","line_start":549},{"id":"external_commands:SKILL.md:550:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`clearFullLayers()` in Task 7 is a bug — the second dispatch fails on an","category":"external_commands","line_end":554,"severity":"medium","line_start":550},{"id":"external_commands:SKILL.md:554:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"character-identical to `INIT-0004-IFCE-nn`. A paraphrase is a defect.","category":"external_commands","line_end":561,"severity":"medium","line_start":554},{"id":"external_commands:SKILL.md:561:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"initiative's ID. `id`, `spec`, `interfaces`, the ID in every task heading,","category":"external_commands","line_end":561,"severity":"medium","line_start":561},{"id":"external_commands:SKILL.md:562:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and every `R`/`C` token resolve inside this initiative.","category":"external_commands","line_end":562,"severity":"medium","line_start":562},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"run, or stating `FAIL` without the expected failure, is a defect — fix the","category":"external_commands","line_end":570,"severity":"medium","line_start":568},{"id":"external_commands:SKILL.md:570:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`../executor/references/test-quality.md` — literals not mirror assertions,","category":"external_commands","line_end":578,"severity":"medium","line_start":570},{"id":"external_commands:SKILL.md:578:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":585,"severity":"medium","line_start":578},{"id":"external_commands:SKILL.md:585:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":587,"severity":"medium","line_start":585},{"id":"external_commands:SKILL.md:587:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every task prints its own `INIT-0004-P01-Tnn` and none errors. A task that","category":"external_commands","line_end":588,"severity":"medium","line_start":587},{"id":"external_commands:SKILL.md:588:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"errors cannot be dispatched. A task printing the wrong `Tnn` means the","category":"external_commands","line_end":595,"severity":"medium","line_start":588},{"id":"external_commands:SKILL.md:595:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**10. Mechanical lint.** `exec-plan-lint` catches what reading re-derives","category":"external_commands","line_end":597,"severity":"medium","line_start":595},{"id":"external_commands:SKILL.md:597:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"resolved by `exec-workspace`/`exec-evidence`, never named in a plan — a","category":"external_commands","line_end":597,"severity":"medium","line_start":597},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every `### Task N:` carries all of these; `exec-plan-lint` fails a task","category":"external_commands","line_end":616,"severity":"medium","line_start":616},{"id":"external_commands:SKILL.md:621:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `**Implements:**` with a requirement ID | the reviewer grades the task against it | \"no **Implemen","category":"external_commands","line_end":622,"severity":"medium","line_start":621},{"id":"external_commands:SKILL.md:622:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `**Depends on:**` a task ID or `none` | the controller orders dispatch from it | \"no **Depends on:","category":"external_commands","line_end":622,"severity":"medium","line_start":622},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `**Files:**` with a Create/Modify/Test/Delete entry | the implementer writes only listed files | \"","category":"external_commands","line_end":624,"severity":"medium","line_start":623},{"id":"external_commands:SKILL.md:624:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `**Interfaces:**` (Consumes/Produces, or `none`) | an implicit seam is one the next task guesses |","category":"external_commands","line_end":624,"severity":"medium","line_start":624},{"id":"external_commands:SKILL.md:625:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `**Requirements:**` | invariants and exact values bind only when written | \"no **Requirements:** b","category":"external_commands","line_end":626,"severity":"medium","line_start":625},{"id":"external_commands:SKILL.md:626:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| At least three `- [ ]` steps | failing test, implementation, passing test at minimum | \"has N chec","category":"external_commands","line_end":627,"severity":"medium","line_start":626},{"id":"external_commands:SKILL.md:627:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| A `Run:` line followed by `Expected:` | every task proves itself with a command and its output | \"","category":"external_commands","line_end":627,"severity":"medium","line_start":627},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `../executor/scripts/exec-plan-lint PLAN_FILE` for every plan — exit 0.","category":"external_commands","line_end":640,"severity":"medium","line_start":637},{"id":"external_commands:SKILL.md:640:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `../executor/scripts/exec-store-check` — no finding for this","category":"external_commands","line_end":643,"severity":"medium","line_start":640},{"id":"external_commands:SKILL.md:643:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the spec — count them against the spec's `### R<nn>` headings.","category":"external_commands","line_end":644,"severity":"medium","line_start":643},{"id":"external_commands:SKILL.md:644:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. `../executor/scripts/exec-scan-secrets docs/executor/<INIT>-<slug>/plans`","category":"external_commands","line_end":650,"severity":"medium","line_start":644},{"id":"external_commands:SKILL.md:650:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"without the human *while a plan is running*, and `exec-ruling` records it","category":"external_commands","line_end":651,"severity":"medium","line_start":650},{"id":"external_commands:SKILL.md:651:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"into that plan's `rulings.md`. It requires a plan file, and a workspace, and","category":"external_commands","line_end":655,"severity":"medium","line_start":651},{"id":"external_commands:SKILL.md:655:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"boundary you moved — is an **ADR** (`INIT-0004-ADR-nn`), written into","category":"external_commands","line_end":656,"severity":"medium","line_start":655},{"id":"external_commands:SKILL.md:656:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`architecture/`, registered in the initiative INDEX, with the human in the","category":"external_commands","line_end":657,"severity":"medium","line_start":656},{"id":"external_commands:SKILL.md:657:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"loop. Do not call `exec-ruling` before execution starts.","category":"external_commands","line_end":661,"severity":"medium","line_start":657},{"id":"external_commands:SKILL.md:661:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`executor-architecture`), then resume. Planning around an unmade decision","category":"external_commands","line_end":672,"severity":"medium","line_start":661},{"id":"external_commands:SKILL.md:672:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"plan or five — route to `executor-plan-regression` before this section","category":"external_commands","line_end":675,"severity":"medium","line_start":672},{"id":"external_commands:SKILL.md:675:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":677,"severity":"medium","line_start":675},{"id":"external_commands:SKILL.md:677:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":681,"severity":"medium","line_start":677},{"id":"external_commands:SKILL.md:681:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`.executor/<INIT>/plan-regression/summary.md` reading clean-or-waived per","category":"external_commands","line_end":682,"severity":"medium","line_start":681},{"id":"external_commands:SKILL.md:682:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"plan. When `exec-plan-regression \"$PLAN\" check` exits 0:","category":"external_commands","line_end":684,"severity":"medium","line_start":682},{"id":"external_commands:SKILL.md:684:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":688,"severity":"medium","line_start":684},{"id":"external_commands:SKILL.md:688:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":691,"severity":"medium","line_start":688},{"id":"external_commands:SKILL.md:691:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-initiative phase INIT-0004 plan-regression skipped \"<reason>\"`.)","category":"external_commands","line_end":693,"severity":"medium","line_start":691},{"id":"external_commands:SKILL.md:693:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**1. Update the initiative INDEX** (`<initiative>/INDEX.md`) — append the","category":"external_commands","line_end":696,"severity":"medium","line_start":693},{"id":"external_commands:SKILL.md:696:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":697,"severity":"medium","line_start":696},{"id":"external_commands:SKILL.md:697:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| INIT-0004-P01 | plan | Cell router | active | `plans/INIT-0004-P01-cell-router.md` |","category":"external_commands","line_end":698,"severity":"medium","line_start":697},{"id":"external_commands:SKILL.md:698:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":700,"severity":"medium","line_start":698},{"id":"external_commands:SKILL.md:700:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**2. Update the spec's `plans:` field** to include this plan's ID, and bump","category":"external_commands","line_end":701,"severity":"medium","line_start":700},{"id":"external_commands:SKILL.md:701:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"its `updated_at`. The spec and the plan point at each other or the graph is","category":"external_commands","line_end":706,"severity":"medium","line_start":701},{"id":"external_commands:SKILL.md:706:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":708,"severity":"medium","line_start":706},{"id":"external_commands:SKILL.md:708:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":713,"severity":"medium","line_start":708},{"id":"external_commands:SKILL.md:713:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":716,"severity":"medium","line_start":713},{"id":"external_commands:SKILL.md:716:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":720,"severity":"medium","line_start":716},{"id":"external_commands:SKILL.md:720:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **Plan complete: `INIT-0004-P01` — 7 tasks, saved to","category":"external_commands","line_end":721,"severity":"medium","line_start":720},{"id":"external_commands:SKILL.md:721:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> `plans/INIT-0004-P01-cell-router.md`. Two execution options:**","category":"external_commands","line_end":723,"severity":"medium","line_start":721},{"id":"external_commands:SKILL.md:723:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **1. Subagent-driven (recommended)** — `executor-execution` dispatches a","category":"external_commands","line_end":735,"severity":"medium","line_start":723},{"id":"external_commands:SKILL.md:735:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"has not picked yet, and `execution_mode` stays `null` until they do.","category":"external_commands","line_end":735,"severity":"medium","line_start":735},{"id":"external_commands:SKILL.md:745:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**6. Record the choice** in the plan's `execution_mode` (`subagent` or","category":"external_commands","line_end":745,"severity":"medium","line_start":745},{"id":"external_commands:SKILL.md:746:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`inline`), flip `status` to `active`, bump `updated_at`, and pass the gate:","category":"external_commands","line_end":746,"severity":"medium","line_start":746},{"id":"external_commands:SKILL.md:748:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":750,"severity":"medium","line_start":748},{"id":"external_commands:SKILL.md:750:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":752,"severity":"medium","line_start":750},{"id":"external_commands:SKILL.md:752:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Then hand to `executor-execution`. **Once execution starts it runs to","category":"external_commands","line_end":762,"severity":"medium","line_start":752},{"id":"external_commands:SKILL.md:762:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"I'll add the task IDs when execution starts\" | `exec-brief` errors out; the plan is undispatchabl","category":"external_commands","line_end":766,"severity":"medium","line_start":762},{"id":"external_commands:SKILL.md:81:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"ls \"$(../executor/scripts/exec-initiative resolve INIT-0004)/plans/\"","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:579:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"for n in $(seq 1 7); do","category":"external_commands","line_end":579,"severity":"medium","line_start":579},{"id":"external_commands:SKILL.md:79:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":83,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:578:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":585,"severity":"medium","line_start":578},{"id":"filesystem:SKILL.md:31:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| `../executor/SKILL.md` | ID grammar, citation rule, phase gates, rulings policy |","category":"filesystem","line_end":31,"severity":"high","line_start":31},{"id":"filesystem:SKILL.md:32:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| `../executor/references/frontmatter.md` | plan frontmatter is contract, not style |","category":"filesystem","line_end":32,"severity":"high","line_start":32},{"id":"filesystem:SKILL.md:33:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| `../executor/references/layout.md` | plans live in `plans/`, nothing else |","category":"filesystem","line_end":33,"severity":"high","line_start":33},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| `../executor/references/indexes.md` | the two index updates planning owns |","category":"filesystem","line_end":34,"severity":"high","line_start":34},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative resolve INIT-0004        # → the initiative folder","category":"filesystem","line_end":80,"severity":"high","line_start":80},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"ls \"$(../executor/scripts/exec-initiative resolve INIT-0004)/plans/\"","category":"filesystem","line_end":81,"severity":"high","line_start":81},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-id INIT-0004 P                      # → INIT-0004-P01","category":"filesystem","line_end":82,"severity":"high","line_start":82},{"id":"filesystem:SKILL.md:473:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[`../executor/references/test-quality.md`](../executor/references/test-quality.md):","category":"filesystem","line_end":473,"severity":"high","line_start":473},{"id":"filesystem:SKILL.md:570:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"`../executor/references/test-quality.md` — literals not mirror assertions,","category":"filesystem","line_end":570,"severity":"high","line_start":570},{"id":"filesystem:SKILL.md:580:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-brief docs/executor/INIT-0004-.../plans/INIT-0004-P01-....md \\","category":"filesystem","line_end":580,"severity":"high","line_start":580},{"id":"filesystem:SKILL.md:637:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. `../executor/scripts/exec-plan-lint PLAN_FILE` for every plan — exit 0.","category":"filesystem","line_end":637,"severity":"high","line_start":637},{"id":"filesystem:SKILL.md:640:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"3. `../executor/scripts/exec-store-check` — no finding for this","category":"filesystem","line_end":640,"severity":"high","line_start":640},{"id":"filesystem:SKILL.md:644:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"5. `../executor/scripts/exec-scan-secrets docs/executor/<INIT>-<slug>/plans`","category":"filesystem","line_end":644,"severity":"high","line_start":644},{"id":"filesystem:SKILL.md:676:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-plan-regression \"$PLAN\" init   # seeds the summary","category":"filesystem","line_end":676,"severity":"high","line_start":676},{"id":"filesystem:SKILL.md:685:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 plan-regression entered \"P01..P03 audit\"","category":"filesystem","line_end":685,"severity":"high","line_start":685},{"id":"filesystem:SKILL.md:687:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 plan-regression passed \"3 plans clean\"","category":"filesystem","line_end":687,"severity":"high","line_start":687},{"id":"filesystem:SKILL.md:707:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 planning entered \"P01 drafted, 7 tasks\"","category":"filesystem","line_end":707,"severity":"high","line_start":707},{"id":"filesystem:SKILL.md:749:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 planning passed \"subagent mode\"","category":"filesystem","line_end":749,"severity":"high","line_start":749},{"id":"filesystem:SKILL.md:581:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"\"$n\" /tmp/brief-check.md >/dev/null || echo \"TASK $n FAILS\"","category":"filesystem","line_end":581,"severity":"low","line_start":581},{"id":"filesystem:SKILL.md:581:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"\"$n\" /tmp/brief-check.md >/dev/null || echo \"TASK $n FAILS\"","category":"filesystem","line_end":581,"severity":"medium","line_start":581},{"id":"filesystem:SKILL.md:582:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"grep -m1 '^\\*\\*Task:\\*\\*' /tmp/brief-check.md","category":"filesystem","line_end":582,"severity":"medium","line_start":582},{"id":"blocker:SKILL.md:82:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"../executor/scripts/exec-id INIT-0004 P                      # → INIT-0004-P01","category":"blocker","line_end":82,"severity":"low","line_start":82}],"finding_verdicts":[{"id":"external_commands:SKILL.md:8:ruby-shell-backtick-execution","reason":"Backticks format specification and plan identifiers in Markdown, not executable Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The backticks format a companion skill name in prose, not a command execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Backticks mark a companion documentation path in a Markdown table, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"Backticks mark a companion frontmatter reference path in a Markdown table, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"Backticks format documentation and plan-directory paths in Markdown, not command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"This is a Markdown reference to companion index documentation, not a Ruby or shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The backticks format a specification identifier in a documentation table, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The backticks format an interface-document identifier, not a command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The marked text is a frontmatter field name in prose, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backticks format the prerequisite status value in Markdown, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The marked text names a workflow phase in prose; it is not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks identify a companion specification skill, not a command execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The backticks identify a companion architecture skill in routing instructions, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"Markdown formats a documented phase-entry command. Its stated purpose is recording a planning transition, not injecting shell code.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The marked spans name a companion skill and a frontmatter field, not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The backticks format a session-status prerequisite, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The marked text is a Markdown heading name used as a documentation reference.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The backticks format an initiative identifier in the citation policy, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The marked text is a dependency metadata field name, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The table uses backticks to display a requirement identifier, not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The table uses backticks to display a constraint identifier, not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The marked text illustrates the task segment of an identifier grammar, not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The marked spans illustrate review identifiers and their suffix grammar, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks display an identifier segment in explanatory prose, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The marked spans show plan numbering examples in Markdown, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"Backticks format a plan identifier and directory name; listing existing plans is legitimate allocation guidance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The marked span names the companion identifier-allocation tool, not a backtick execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The triple backticks open a Bash example fence; they are Markdown delimiters, not shell execution operators.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The triple backticks close a Bash example fence, not a command substitution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"Backticks format a tool name and plan-kind token in identifier documentation, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The marked spans compare valid and invalid plan identifiers, not command expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backticks mark an existing plan identifier in allocation guidance, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The marked text names the initiative index file and explicitly prohibits overwriting existing plans.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"The backticks format a plan file-path template, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The marked text is the identifier frontmatter key in documentation, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"Backticks format plan numbering examples in decomposition guidance, not command invocations.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The marked span names an assumptions section in a plan, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The backticks open a Markdown example fence, not a Ruby execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"The marked text identifies a predecessor plan in an assumptions example, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"Backticks display an example function signature and source path; the Markdown does not execute either.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"Backticks display an example type signature and source path, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The triple backticks close a Markdown example fence, not an execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"Backticks format a plan identifier and a cross-plan ordering statement, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"This closes an inline Markdown ordering statement; it is not a shell backtick operator.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The marked text illustrates requirement coverage notation, not a command expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"The marked command documents extracting a numbered task brief, a legitimate planning check rather than shell injection.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The backticks show task and plan numbering tokens in Markdown, not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"Backticks mark the brief tool name and task-heading text in documentation, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"The marked span names the dependency-map heading used in task-extraction documentation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The backticks format a plan identifier in a section-order list, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"The marked spans illustrate required Markdown task headings, not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"The backticks open a YAML frontmatter example fence, not Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"The backticks close the YAML frontmatter example fence, not an execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","reason":"The marked text is the identifier metadata key in a frontmatter rules table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","reason":"The backticks format the specification metadata key, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","reason":"The backticks format the interface metadata key in a documentation table, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","reason":"The marked spans describe a task-count field and heading syntax, not execution expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","reason":"Backticks format execution-mode metadata and allowed values; the surrounding rule preserves human choice.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"The marked spans describe workspace metadata and a companion resolver name, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","reason":"Backticks format plan-status metadata and its allowed states, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The triple backticks open a Markdown plan-header example fence, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","reason":"The backticks name a companion execution skill in an example header, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The marked span illustrates checkbox Markdown syntax, not a command expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The backticks format an architecture-document identifier in the plan-header example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","reason":"The marked spans identify an example specification and its path, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","reason":"Backticks format requirement identifiers and their specification reference, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","reason":"The triple backticks close a Markdown header example fence, not an execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","reason":"The backticks open a Markdown constraints example fence, not Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"Backticks format a constraint ID and dependency-version requirement, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"The marked type-checking command is an ordinary acceptance check; Markdown backticks do not execute it.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The marked spans identify a constraint and specification reference, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","reason":"The backticks format a constraint identifier; the text prohibits network calls in unit tests.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","reason":"The backticks close a Markdown constraint example fence, not an execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:272:ruby-shell-backtick-execution","reason":"The marked spans demonstrate full and abbreviated constraint identifiers in prose.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"The backticks open a Markdown interface-contract example fence, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"The backticks format an interface-document identifier in a documentation example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"The marked text is an example interface-document path, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","reason":"Backticks display an example function signature in Markdown, not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The marked text is an example function contract, not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The backticks format an enumeration signature example, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"The backticks close a Markdown interface example fence, not a command substitution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","reason":"The backticks name a companion architecture skill in missing-interface guidance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"The marked span names a companion execution skill in dependency-map documentation, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The backticks open a Markdown dependency-map example fence, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"Backticks format an example shared source path and type name in a dependency table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The marked spans identify an example shared file and type, not execution expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"Backticks format function and exception names in a dependency-map example, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"Backticks display an example source path and method name in a dependency table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"The backticks close a Markdown dependency-map example fence, not an execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","reason":"The backticks open a Markdown task-heading example fence, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","reason":"Backticks format a task identifier inside a heading example, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:341:ruby-shell-backtick-execution","reason":"The triple backticks close a task-heading example fence, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"The table formats task-heading syntax and a brief-extraction command used for plan validation, not shell injection.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:346:ruby-shell-backtick-execution","reason":"The marked spans describe task identifier grammar and the brief tool name, not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","reason":"The backticks format task-number grammar in a heading-consistency rule, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","reason":"The four backticks open a nested Markdown task example fence, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"The backticks format the task identifier in an example task heading.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","reason":"The marked spans identify requirements implemented by the example task, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","reason":"The example restates constraint identifiers and a standard type-checking command; these are acceptance requirements, not injected shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","reason":"Backticks format a predecessor task identifier and the no-dependency value, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","reason":"The marked span is an example source file to create, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","reason":"The backticks display an example modification path and line range, not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","reason":"The marked span is an example test-file path in the task contract, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","reason":"The backticks format a consumed type signature in a Markdown task example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","reason":"The marked span identifies the example source file providing the consumed type, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","reason":"The marked text is a produced function signature in a task contract, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","reason":"Backticks format an exception type and input-boundary condition, not execution expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","reason":"The marked text is a requirement identifier in a purity contract, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:375:ruby-shell-backtick-execution","reason":"The triple backticks open a Python test example fence, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","reason":"The backticks close a Python test example fence, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","reason":"The example invokes pytest on a fixed test-file path as an acceptance check, with no visible command injection.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","reason":"The backticks format the exact expected test failure text, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","reason":"Backticks mark a contract label and exception type while explaining a nonbinding implementation sketch.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"The backticks open a Python implementation-sketch fence, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","reason":"The backticks close a Python implementation-sketch fence, not a command expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:403:ruby-shell-backtick-execution","reason":"The fixed pytest invocation verifies the example task; Markdown delimiters do not perform command substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:408:ruby-shell-backtick-execution","reason":"The marked text is an example source directory used for refactoring review, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:412:ruby-shell-backtick-execution","reason":"The fixed pytest invocation reruns acceptance tests after refactoring; no untrusted shell input is shown.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:416:ruby-shell-backtick-execution","reason":"The four backticks close the nested Markdown task example, not a Ruby or shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","reason":"The marked span names the task file-list label in a documentation table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","reason":"Backticks format consumed and produced interface labels in prose, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","reason":"The backticks format the requirement-traceability label in a task-contract table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","reason":"The marked span names an interface-contract label in design guidance, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:450:ruby-shell-backtick-execution","reason":"The backticks format a produced-interface label in prose, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","reason":"The marked spans format expected test-failure text and a failure label, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","reason":"The backticks format a Markdown link label for companion test-quality documentation, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","reason":"The marked span names a companion execution skill in self-contained-task guidance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:530:ruby-shell-backtick-execution","reason":"The backticks format a requirement identifier in the coverage-check instructions, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:531:ruby-shell-backtick-execution","reason":"The marked text is a requirement identifier in coverage guidance, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:537:ruby-shell-backtick-execution","reason":"The table uses backticks to display a requirement identifier mapped to a task.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:538:ruby-shell-backtick-execution","reason":"The backticks format a requirement identifier in the coverage table, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","reason":"The marked span is a requirement identifier in an example coverage mapping.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:540:ruby-shell-backtick-execution","reason":"The backticks display a requirement identifier in Markdown, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:541:ruby-shell-backtick-execution","reason":"The marked span is a requirement identifier in the task-coverage table, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:542:ruby-shell-backtick-execution","reason":"The backticks format a requirement identifier in a documentation table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:543:ruby-shell-backtick-execution","reason":"The marked span displays a requirement identifier mapped to an example task.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:549:ruby-shell-backtick-execution","reason":"Backticks format an example method name used to illustrate interface inconsistency, not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:550:ruby-shell-backtick-execution","reason":"The marked span is a contrasting method-name example in a consistency check, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:554:ruby-shell-backtick-execution","reason":"The backticks format an interface-document identifier pattern in verification guidance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:561:ruby-shell-backtick-execution","reason":"The marked spans name frontmatter keys for citation validation, not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:562:ruby-shell-backtick-execution","reason":"Backticks format requirement and constraint token prefixes, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","reason":"The backticks format a test-failure label in TDD guidance, not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:570:ruby-shell-backtick-execution","reason":"The marked span is a companion test-quality reference path, not a command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:578:ruby-shell-backtick-execution","reason":"The triple backticks open a Bash example fence, not an execution operator. Temporary-file risks are adjudicated separately.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:585:ruby-shell-backtick-execution","reason":"The triple backticks close a Bash example fence, not a shell command substitution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:587:ruby-shell-backtick-execution","reason":"The marked text describes the expected task identifier output, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:588:ruby-shell-backtick-execution","reason":"The backticks format the task-number token checked after extraction, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:595:ruby-shell-backtick-execution","reason":"The marked span names the companion plan-linting tool in documentation, not a backtick execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:597:ruby-shell-backtick-execution","reason":"Backticks format companion workspace and evidence resolver names in explanatory prose.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","reason":"The marked spans name task-heading syntax and the plan linter, not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:621:ruby-shell-backtick-execution","reason":"The backticks format the task requirement-traceability label in a lint-contract table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:622:ruby-shell-backtick-execution","reason":"The marked spans format a dependency label and its no-dependency value, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","reason":"The backticks format the file-list label in a task-depth documentation table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:624:ruby-shell-backtick-execution","reason":"The marked spans display the interface-block label and its empty value, not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:625:ruby-shell-backtick-execution","reason":"The backticks format a requirements-block label in a lint-contract table.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:626:ruby-shell-backtick-execution","reason":"The marked span illustrates Markdown checkbox syntax, not an executable shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:627:ruby-shell-backtick-execution","reason":"Backticks format run-command and expected-output labels required by task linting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","reason":"The documented companion command lints the plan file, a legitimate verification operation rather than backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:640:ruby-shell-backtick-execution","reason":"The documented companion command checks initiative-store consistency, not arbitrary injected shell input.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:643:ruby-shell-backtick-execution","reason":"The marked text is a specification-heading pattern used for coverage counting, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:644:ruby-shell-backtick-execution","reason":"The marked command documents secret scanning of the plans directory, a protective verification step rather than shell injection.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:650:ruby-shell-backtick-execution","reason":"Backticks format an execution-time ruling tool name while explaining that planning must not invoke it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:651:ruby-shell-backtick-execution","reason":"The marked text names a ruling artifact in prose, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:655:ruby-shell-backtick-execution","reason":"The backticks format an architecture-decision identifier pattern, not a command expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:656:ruby-shell-backtick-execution","reason":"The marked text is an architecture-document directory in human-reviewed decision guidance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:657:ruby-shell-backtick-execution","reason":"The backticks name a tool that the surrounding sentence explicitly prohibits invoking during planning.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:661:ruby-shell-backtick-execution","reason":"The marked span names a companion architecture skill for resolving missing decisions, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:672:ruby-shell-backtick-execution","reason":"The backticks identify the companion plan-regression skill used before execution handoff.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:675:ruby-shell-backtick-execution","reason":"The triple backticks open a Bash handoff example fence, not an execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:677:ruby-shell-backtick-execution","reason":"The triple backticks close a Bash handoff example fence, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:681:ruby-shell-backtick-execution","reason":"The marked span is the documented plan-regression summary path, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:682:ruby-shell-backtick-execution","reason":"The documented regression check passes the plan argument as a quoted variable, not interpolated shell source.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:684:ruby-shell-backtick-execution","reason":"The triple backticks open a Bash phase-transition example fence, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:688:ruby-shell-backtick-execution","reason":"The backticks close a Bash phase-transition example fence, not a command expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:691:ruby-shell-backtick-execution","reason":"The documented skip command records a reason only when the human waives regression; no bypass of human approval is instructed.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:693:ruby-shell-backtick-execution","reason":"The marked span identifies the initiative index path in document-update guidance, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:696:ruby-shell-backtick-execution","reason":"The triple backticks open a Markdown index-row example fence, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:697:ruby-shell-backtick-execution","reason":"The backticks format a plan path in an example index row, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:698:ruby-shell-backtick-execution","reason":"The triple backticks close a Markdown index-row example fence, not an execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:700:ruby-shell-backtick-execution","reason":"The marked text is the specification plans metadata key, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:701:ruby-shell-backtick-execution","reason":"The backticks format the update-timestamp metadata key in document-linking guidance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:706:ruby-shell-backtick-execution","reason":"The triple backticks open a Bash phase-entry example fence, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:708:ruby-shell-backtick-execution","reason":"The triple backticks close a Bash phase-entry example fence, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:713:ruby-shell-backtick-execution","reason":"This is a Markdown Bash fence, not backtick execution. Directory-wide Git staging is addressed as a separate semantic finding.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:716:ruby-shell-backtick-execution","reason":"The triple backticks close the Git-command example fence, not an executable shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:720:ruby-shell-backtick-execution","reason":"The backticks format a completed plan identifier in the example human handoff message.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:721:ruby-shell-backtick-execution","reason":"The marked span is a saved plan path in the example handoff message, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:723:ruby-shell-backtick-execution","reason":"The backticks name the companion execution skill in a human-selected execution option, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:735:ruby-shell-backtick-execution","reason":"The marked spans describe execution-mode metadata remaining unset until human approval, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:745:ruby-shell-backtick-execution","reason":"Backticks format the execution-mode key and an allowed value after the human selects a mode.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:746:ruby-shell-backtick-execution","reason":"The marked spans format execution-mode, status, and timestamp metadata, not command expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:748:ruby-shell-backtick-execution","reason":"The triple backticks open a Bash planning-gate example fence, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:750:ruby-shell-backtick-execution","reason":"The triple backticks close the planning-gate example fence, not a command substitution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:752:ruby-shell-backtick-execution","reason":"The marked text names a companion execution skill after the explicit human mode-selection gate.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:762:ruby-shell-backtick-execution","reason":"The backticks format the brief tool name in a warning about missing task identifiers.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:shell-command-substitution","reason":"The resolver output is quoted as one ls pathname, not evaluated as shell source. The command lists plans for identifier allocation.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:579:shell-command-substitution","reason":"The substitution runs seq with fixed numeric arguments to enumerate tasks. No untrusted command text is incorporated.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:template-literal-with-command-substitution","reason":"This is a Markdown Bash fence, not a JavaScript template literal. Its quoted substitution supplies a directory pathname to ls.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:578:template-literal-with-command-substitution","reason":"This is a Markdown Bash example, not a JavaScript template literal. The substitution enumerates fixed task numbers; temporary-file risks are separate.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:31:path-traversal-sequence","reason":"The fixed relative path references companion Executor documentation. No attacker-controlled traversal or protected-file target is shown.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:32:path-traversal-sequence","reason":"The fixed relative path references companion frontmatter documentation, not a user-controlled path escaping a security boundary.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:33:path-traversal-sequence","reason":"The fixed parent-relative path locates companion layout documentation. No malicious filesystem target or dynamic traversal input appears.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","reason":"The fixed relative path locates companion index documentation. Parent-directory notation alone does not establish unsafe traversal.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","reason":"The parent-relative path names the expected companion initiative resolver, not attacker-selected traversal. Its implementation is not included in this package.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","reason":"The fixed companion resolver locates the initiative plans directory for listing. No dynamic traversal payload or protected-file access is shown.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","reason":"The fixed companion tool path allocates a plan identifier using an initiative ID. No attacker-controlled traversal sequence is provided.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:SKILL.md:473:path-traversal-sequence","reason":"The parent-relative path is a Markdown link to companion test-quality documentation, not a filesystem exploit.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:570:path-traversal-sequence","reason":"The path is a fixed companion documentation reference in test-quality guidance, not untrusted path input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:580:path-traversal-sequence","reason":"The parent-relative path locates the companion brief extractor for plan verification. Its separate temporary-output risk is adjudicated under the temporary-file findings.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:637:path-traversal-sequence","reason":"The fixed companion script path identifies the plan linter. No attacker-controlled path traversal is shown; the script implementation is unavailable.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:640:path-traversal-sequence","reason":"The fixed relative path identifies the companion store checker, not an arbitrary protected-file target. Its implementation is outside this package.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:644:path-traversal-sequence","reason":"The fixed companion path identifies the secret scanner used on plan documents, not user-controlled filesystem traversal.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:676:path-traversal-sequence","reason":"The fixed companion path identifies a regression-summary initializer with a quoted plan argument. No traversal payload is shown.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:685:path-traversal-sequence","reason":"The fixed relative script path records an initiative phase transition using literal arguments, not attacker-controlled filesystem traversal.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:SKILL.md:687:path-traversal-sequence","reason":"The fixed companion path records a regression phase result. Parent-directory notation locates a sibling package rather than a protected-file target.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:SKILL.md:707:path-traversal-sequence","reason":"The fixed companion path records the planning phase entry with literal initiative arguments. No malicious traversal input is present.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:SKILL.md:749:path-traversal-sequence","reason":"The fixed companion path records planning approval after human mode selection, not arbitrary filesystem traversal.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:SKILL.md:581:standard-device-file-access","reason":"The command redirects routine stdout to /dev/null. It does not read a device containing sensitive data or modify a privileged device.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:581:temp-directory-access","reason":"The example writes each brief to a predictable shared temporary pathname without showing exclusive creation. Concurrent runs or precreated links could corrupt or redirect output.","verdict":"confirmed","confidence":0.75},{"id":"filesystem:SKILL.md:582:temp-directory-access","reason":"The loop reads the same shared temporary file even after extraction failure. Stale output or another concurrent run could substitute the task identity being verified.","verdict":"confirmed","confidence":0.7},{"id":"blocker:SKILL.md:82:system-reconnaissance","reason":"exec-id is documented as a plan-identifier allocator, not a host identity or system reconnaissance command. No reconnaissance intent is visible.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Broad Git Staging Can Include Unrelated Changes","severity":"medium","locations":[{"file":"SKILL.md","line_end":715,"line_start":710}],"confidence":0.95,"description":"The handoff runs 'git add docs/executor/INIT-0004-cloud-tenant-cells' before committing. Directory-wide staging can include unrelated or sensitive initiative files beyond the intended plan, index, and specification updates.","confidence_reasoning":"The example explicitly stages the entire initiative directory instead of the three intended document updates. Actual exposure depends on other changes in that directory."}],"subject_marketplace_commit_sha":"6d0b11444384184b7ae743742a7e233a9a705cd9","subject_content_hash":"649171eec3e1639ce56df65ec31b51523417bd74567b35889e04e9ea00648ebc","subject_tree_hash":"495b7c8a460c49d25f609b12c8a79c67b3c4cfbe26e0b7be56c8072919ae312b","subject_plugin_path":"skills/atri10/executor-planning","audit_payload_hash":"d9bba711f46482c9a87299ffc36e586c","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"6d0b11444384184b7ae743742a7e233a9a705cd9","contentHash":"649171eec3e1639ce56df65ec31b51523417bd74567b35889e04e9ea00648ebc","treeHash":"495b7c8a460c49d25f609b12c8a79c67b3c4cfbe26e0b7be56c8072919ae312b","pluginPath":"skills/atri10/executor-planning","auditPayloadHash":"d9bba711f46482c9a87299ffc36e586c"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/atri10-executor-planning/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}