{"data":{"skill":{"slug":"atri10-executor-spec","name":"executor-spec","icon":"📦","repo":"https://github.com/atri10/executor/tree/39ddcfe1d9f3497102622b72aa235fb0770187fe/skills/executor-spec","status":"approved","author":"atri10","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"87dc1840-f702-4d65-a5e6-ef4a73c8f2d3","skill_id":"cd6cb555-8af0-4fdf-86b6-07b3f3edf4fc","version":1,"content_hash":"v3:6d0b11444384184b7ae743742a7e233a9a705cd9:1301fbbc32818539db823b4d02086b8924f1d48604534fcca71f8a35618635a5:5c16273bcee4b72c0ce365663f3167a15af1f08fa8657451268731eb1f504ad7:736b696c6c732f6174726931302f6578656375746f722d73706563:9e1327c7994849048a3810c16411c835","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most findings are Markdown formatting, legitimate test examples, or fixed sibling references, not shell substitution, reconnaissance, or exploitable traversal. The verification example writes to predictable /tmp/b, creating a local symlink overwrite risk if copied and executed. No evidence found of credential exfiltration or prompt injection; referenced sibling helpers are outside the reviewed package.","remediation":[{"issue":"The verification example writes an HTTP response to predictable /tmp/b, which another local user could replace with a symlink.","severity":"medium","suggestion":"Use a uniquely created private temporary file, quote its path, and remove it after checking the response."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/risk-template.md","line_end":78,"line_start":71},{"file":"references/risk-template.md","line_end":78,"line_start":78},{"file":"references/risk-template.md","line_end":116,"line_start":83},{"file":"references/spec-template.md","line_end":48,"line_start":47},{"file":"references/spec-template.md","line_end":49,"line_start":48},{"file":"references/spec-template.md","line_end":56,"line_start":49},{"file":"references/spec-template.md","line_end":67,"line_start":56},{"file":"references/spec-template.md","line_end":68,"line_start":67},{"file":"references/spec-template.md","line_end":70,"line_start":68},{"file":"references/spec-template.md","line_end":73,"line_start":70},{"file":"references/spec-template.md","line_end":88,"line_start":73},{"file":"references/spec-template.md","line_end":89,"line_start":88},{"file":"references/spec-template.md","line_end":94,"line_start":89},{"file":"references/spec-template.md","line_end":95,"line_start":94},{"file":"references/spec-template.md","line_end":99,"line_start":95},{"file":"references/spec-template.md","line_end":100,"line_start":99},{"file":"references/spec-template.md","line_end":112,"line_start":100},{"file":"references/spec-template.md","line_end":129,"line_start":112},{"file":"references/spec-template.md","line_end":135,"line_start":129},{"file":"references/verification-template.md","line_end":46,"line_start":46},{"file":"references/verification-template.md","line_end":47,"line_start":47},{"file":"references/verification-template.md","line_end":48,"line_start":48},{"file":"references/verification-template.md","line_end":49,"line_start":49},{"file":"references/verification-template.md","line_end":50,"line_start":50},{"file":"references/verification-template.md","line_end":51,"line_start":51},{"file":"references/verification-template.md","line_end":52,"line_start":52},{"file":"references/verification-template.md","line_end":53,"line_start":53},{"file":"references/verification-template.md","line_end":55,"line_start":55},{"file":"references/verification-template.md","line_end":69,"line_start":69},{"file":"references/verification-template.md","line_end":71,"line_start":70},{"file":"references/verification-template.md","line_end":72,"line_start":71},{"file":"references/verification-template.md","line_end":72,"line_start":72},{"file":"references/verification-template.md","line_end":74,"line_start":73},{"file":"references/verification-template.md","line_end":75,"line_start":74},{"file":"references/verification-template.md","line_end":77,"line_start":75},{"file":"references/verification-template.md","line_end":78,"line_start":77},{"file":"references/verification-template.md","line_end":84,"line_start":78},{"file":"references/verification-template.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":57,"line_start":50},{"file":"SKILL.md","line_end":59,"line_start":57},{"file":"SKILL.md","line_end":60,"line_start":59},{"file":"SKILL.md","line_end":66,"line_start":60}]},{"factor":"network","evidence":[{"file":"references/verification-template.md","line_end":69,"line_start":69}]},{"factor":"filesystem","evidence":[{"file":"references/verification-template.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":131,"line_start":131},{"file":"SKILL.md","line_end":213,"line_start":213},{"file":"SKILL.md","line_end":231,"line_start":231},{"file":"SKILL.md","line_end":352,"line_start":352},{"file":"SKILL.md","line_end":360,"line_start":360},{"file":"SKILL.md","line_end":514,"line_start":514},{"file":"SKILL.md","line_end":603,"line_start":603},{"file":"SKILL.md","line_end":666,"line_start":666},{"file":"SKILL.md","line_end":667,"line_start":667},{"file":"SKILL.md","line_end":668,"line_start":668},{"file":"SKILL.md","line_end":669,"line_start":669},{"file":"SKILL.md","line_end":514,"line_start":514}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Temp directory access","locations":[{"file":"references/verification-template.md","line_end":47,"line_start":47}],"confidence":0.94,"description":"| V02 | R02 unknown cell rejected | integration | `curl -s -o /tmp/b -w '%{http_code}' localhost:808","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"curl writes to predictable /tmp/b without exclusive creation. Another local user could pre-create a symlink and redirect the write to an accessible file."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":1175,"audit_model":"codex","audited_at":"2026-10-05T18:16:46.901+00:00","created_at":"2026-10-06T06:52:47.033126+00:00","static_findings":[{"id":"external_commands:references/risk-template.md:71:ruby-shell-backtick-execution","file":"references/risk-template.md","pattern":"Ruby/shell backtick execution","snippet":"| K01 | Placement service emits a `placement_latency_ms` histogram; a load check at 10k tenants is p","category":"external_commands","line_end":78,"severity":"medium","line_start":71},{"id":"external_commands:references/risk-template.md:78:ruby-shell-backtick-execution","file":"references/risk-template.md","pattern":"Ruby/shell backtick execution","snippet":"| This spec | A new or tightened `R<nn>` / `C<nn>` | Strongest — it becomes a requirement a review c","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:references/risk-template.md:83:ruby-shell-backtick-execution","file":"references/risk-template.md","pattern":"Ruby/shell backtick execution","snippet":"`mitigations_planned` counts landed mitigations only.","category":"external_commands","line_end":116,"severity":"medium","line_start":83},{"id":"blocker:references/risk-template.md:109:system-reconnaissance","file":"references/risk-template.md","pattern":"System reconnaissance","snippet":"Recorded so a reader sees the pre-mortem did work rather than decorating","category":"blocker","line_end":109,"severity":"low","line_start":109},{"id":"external_commands:references/spec-template.md:47:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| C01 | Node `>= 20.11.0`; the build fails on lower | INIT-0004-ADR-01 |","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:references/spec-template.md:48:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| C02 | No new runtime dependency outside `@platform/*` | charter constraints |","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:references/spec-template.md:49:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| C03 | Cell identifiers match `^cell-[0-9]{1,4}$` | INIT-0004-IFCE-01 |","category":"external_commands","line_end":56,"severity":"medium","line_start":49},{"id":"external_commands:references/spec-template.md:56:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"cells, `placeCell` returns the same cell on every call.","category":"external_commands","line_end":67,"severity":"medium","line_start":56},{"id":"external_commands:references/spec-template.md:67:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"available set is rejected with HTTP 422 and a body whose `error` field is","category":"external_commands","line_end":68,"severity":"medium","line_start":67},{"id":"external_commands:references/spec-template.md:68:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"`unknown_cell`. No placement is recorded.","category":"external_commands","line_end":70,"severity":"medium","line_start":68},{"id":"external_commands:references/spec-template.md:70:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"**Observable:** Response status and `error` field; the placement table","category":"external_commands","line_end":73,"severity":"medium","line_start":70},{"id":"external_commands:references/spec-template.md:73:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"**Source:** INIT-0004-IFCE-01 · `placeCell` error cases","category":"external_commands","line_end":88,"severity":"medium","line_start":73},{"id":"external_commands:references/spec-template.md:88:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| INIT-0004-IFCE-01 | `placeCell` | R01, R02, R03 |","category":"external_commands","line_end":89,"severity":"medium","line_start":88},{"id":"external_commands:references/spec-template.md:89:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| INIT-0004-IFCE-01 | `evictCell` | R14 (operator-invoked only; OOS-02 excludes automation) |","category":"external_commands","line_end":94,"severity":"medium","line_start":89},{"id":"external_commands:references/spec-template.md:94:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"document's `provides:` list is either specified or explicitly out of","category":"external_commands","line_end":95,"severity":"medium","line_start":94},{"id":"external_commands:references/spec-template.md:95:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"scope; every ADR whose `informs:` names this spec is reflected.","category":"external_commands","line_end":99,"severity":"medium","line_start":95},{"id":"external_commands:references/spec-template.md:99:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| INIT-0004-IFCE-01 | `placeCell` | R01, R02, R03 | — |","category":"external_commands","line_end":100,"severity":"medium","line_start":99},{"id":"external_commands:references/spec-template.md:100:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| INIT-0004-IFCE-01 | `evictCell` | R14 | Automated invocation excluded — OOS-02 |","category":"external_commands","line_end":112,"severity":"medium","line_start":100},{"id":"external_commands:references/spec-template.md:112:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"| OOS-02 | Automated eviction | `evictCell` stays operator-invoked |","category":"external_commands","line_end":129,"severity":"medium","line_start":112},{"id":"external_commands:references/spec-template.md:129:ruby-shell-backtick-execution","file":"references/spec-template.md","pattern":"Ruby/shell backtick execution","snippet":"`spec:` named the superseded document.>","category":"external_commands","line_end":135,"severity":"medium","line_start":129},{"id":"blocker:references/spec-template.md:158:system-reconnaissance","file":"references/spec-template.md","pattern":"System reconnaissance","snippet":"| The router handles invalid input gracefully | Unobservable, ambiguous | R02 above |","category":"blocker","line_end":158,"severity":"low","line_start":158},{"id":"external_commands:references/verification-template.md:46:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V01 | R01 deterministic placement | unit | `npx vitest run test/placement/deterministic.test.ts` |","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:references/verification-template.md:47:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V02 | R02 unknown cell rejected | integration | `curl -s -o /tmp/b -w '%{http_code}' localhost:808","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:references/verification-template.md:48:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V03 | R02 no placement recorded on rejection | integration | `psql -Atc \"select count(*) from plac","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:references/verification-template.md:49:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V04 | R09 isolation enforced in service | unit | `npx vitest run test/placement/isolation.test.ts`","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:references/verification-template.md:50:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V05 | R11 latency at 10k tenants | integration | `node scripts/loadgen.js --tenants 10000 --report","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:references/verification-template.md:51:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V06 | C01 Node floor | smoke | `node --version` | a version string `>= 20.11.0` | pending |","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:references/verification-template.md:52:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V07 | C02 no runtime dependency outside `@platform/*` | smoke | `jq -r '.dependencies\\|keys[]' pac","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:references/verification-template.md:53:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"| V08 | C03 cell identifier pattern | unit | `npx vitest run test/placement/cell-id.test.ts` | `4 pa","category":"external_commands","line_end":53,"severity":"medium","line_start":53},{"id":"external_commands:references/verification-template.md:55:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"`Status` stays `pending` until `executor-verification` runs the row. This","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:references/verification-template.md:69:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"1. Open `http://localhost:3000/cells` — the table lists `cell-1` ... `cell-4`.","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:references/verification-template.md:70:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"2. Click **Evict** on the `cell-3` row — a confirm dialog appears naming","category":"external_commands","line_end":71,"severity":"medium","line_start":70},{"id":"external_commands:references/verification-template.md:71:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"`cell-3`.","category":"external_commands","line_end":72,"severity":"medium","line_start":71},{"id":"external_commands:references/verification-template.md:72:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"3. Confirm — within 2 seconds the `cell-3` row's status reads `draining`.","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:references/verification-template.md:73:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"4. Reload the page — the status still reads `draining`.","category":"external_commands","line_end":74,"severity":"medium","line_start":73},{"id":"external_commands:references/verification-template.md:74:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"5. Run `psql -Atc \"select action,target from audit order by id desc limit 1\"`","category":"external_commands","line_end":75,"severity":"medium","line_start":74},{"id":"external_commands:references/verification-template.md:75:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"— output is `cell.evict|cell-3`.","category":"external_commands","line_end":77,"severity":"medium","line_start":75},{"id":"external_commands:references/verification-template.md:77:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"**Evidence:** step 3 shows `draining`, step 4 confirms it persisted, step","category":"external_commands","line_end":78,"severity":"medium","line_start":77},{"id":"external_commands:references/verification-template.md:78:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"5 prints `cell.evict|cell-3`.","category":"external_commands","line_end":84,"severity":"medium","line_start":78},{"id":"external_commands:references/verification-template.md:84:ruby-shell-backtick-execution","file":"references/verification-template.md","pattern":"Ruby/shell backtick execution","snippet":"Every `R<nn>` and every `C<nn>` in the spec appears at least once. This","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"network:references/verification-template.md:69:hardcoded-url","file":"references/verification-template.md","pattern":"Hardcoded URL","snippet":"1. Open `http://localhost:3000/cells` — the table lists `cell-1` ... `cell-4`.","category":"network","line_end":69,"severity":"low","line_start":69},{"id":"filesystem:references/verification-template.md:47:temp-directory-access","file":"references/verification-template.md","pattern":"Temp directory access","snippet":"| V02 | R02 unknown cell rejected | integration | `curl -s -o /tmp/b -w '%{http_code}' localhost:808","category":"filesystem","line_end":47,"severity":"medium","line_start":47},{"id":"blocker:references/verification-template.md:74:system-reconnaissance","file":"references/verification-template.md","pattern":"System reconnaissance","snippet":"5. Run `psql -Atc \"select action,target from audit order by id desc limit 1\"`","category":"blocker","line_end":74,"severity":"low","line_start":74},{"id":"blocker:references/verification-template.md:141:system-reconnaissance","file":"references/verification-template.md","pattern":"System reconnaissance","snippet":"| Rejects X with status S | Send X, observe S — not \"valid requests still work\" |","category":"blocker","line_end":141,"severity":"low","line_start":141},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 1 | Spec | `INIT-NNNN-SPEC-nn` | `specs/` | What must be true when this is done |","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 2 | Risk | `INIT-NNNN-RISK-nn` | `risks/` | How this ships and still fails |","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 3 | Verification | `INIT-NNNN-VRFY-nn` | `verification/` | What observed output proves each requir","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"before the spec leaves `draft`. The verification strategy must cover the","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `executor-planning` writes plans whose `spec:` frontmatter names this","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `executor-execution` resolves a plan-versus-spec conflict against the","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `executor-review` resolves a finding-versus-plan conflict against the","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `executor-verification` executes the VRFY document row by row.","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":57,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":59,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Two digits, sequential from `01`, allocated in writing order and **never","category":"external_commands","line_end":60,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"renumbered** — a plan, a verdict, or a VRFY row that cites `R07` must","category":"external_commands","line_end":66,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`-T<nn>-` segment before its `-R<nn>` (`INIT-0004-P01-T03-R02`). An `R`","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"directly after `-SPEC-<nn>` is a requirement.","category":"external_commands","line_end":75,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Architecture gate passed | Initiative `INDEX.md` phase log shows `architecture` gate passed, or a ","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Design approved or waived | Phase log `design` row shows passed or `**skipped**` | Stop; same owne","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Feature designed in a brainstorm session | A session under `brainstorm/sessions/` with `status: ac","category":"external_commands","line_end":77,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Inputs readable | `charter.md`, the design session's dossier, every `ARCH`, `ADR`, `IFCE`, `DSGN` ","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Requirements start from the design session.** Its `## Handoff` lists","category":"external_commands","line_end":84,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`informed_by:`. A requirement with no candidate behind it is scope the human","category":"external_commands","line_end":92,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the initiative has no `ARCH` document at all, architecture was skipped","category":"external_commands","line_end":99,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```mermaid","category":"external_commands","line_end":110,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":114,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":117,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":119,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`date -u` is the only source of `created_at` and `updated_at` in all three","category":"external_commands","line_end":119,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"document. `exec-initiative phase` updates the phase-log row, the","category":"external_commands","line_end":122,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"initiative `INDEX.md` header, and the root registry row in one call, and","category":"external_commands","line_end":123,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"prints `INIT-0004: specification entered` as confirmation; it does not","category":"external_commands","line_end":128,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":132,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":134,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-id` scans filenames **and** file contents, so a misfiled document","category":"external_commands","line_end":137,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"race in the initiative `INDEX.md`.","category":"external_commands","line_end":141,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Path: `<initiative>/specs/INIT-0004-SPEC-01-<topic-slug>.md`.","category":"external_commands","line_end":142,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Frontmatter per the contract, `status: draft`:","category":"external_commands","line_end":144,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":150,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":152,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`global_constraints` is a count and must equal the number of `C<nn>`","category":"external_commands","line_end":152,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"entries in the body. `verification` is filled in now even though the VRFY","category":"external_commands","line_end":162,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Global constraints | `C01...Cnn`, exact values copied verbatim | Every requirement implicitly incl","category":"external_commands","line_end":163,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Requirements | `R01...Rnn`, one testable statement each | The unit a plan implements and a review ","category":"external_commands","line_end":164,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Interfaces | `IFCE` IDs and the symbols this spec relies on | The seam where two tasks build incom","category":"external_commands","line_end":168,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Verbatim means verbatim.** Copy `node >= 20.11.0`, not \"recent Node\".","category":"external_commands","line_end":174,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INIT-0004-IFCE-01 · placeCell`. Copying a signature into the spec","category":"external_commands","line_end":177,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`executor-architecture` change, not a spec workaround.","category":"external_commands","line_end":186,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"go back into the spec now, while it is still `draft` and no plan exists.","category":"external_commands","line_end":200,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Spec frontmatter `verification:` names the VRFY ID.","category":"external_commands","line_end":201,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. VRFY frontmatter `spec:` names the SPEC ID.","category":"external_commands","line_end":203,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Append three rows to the initiative `INDEX.md` document table, sorted","category":"external_commands","line_end":208,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"words and put the dependency in the charter's `depends_on`.","category":"external_commands","line_end":212,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":214,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":216,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Exit 0 clean, exit 1 findings. It prints `file:line: possible <kind>` and","category":"external_commands","line_end":219,"severity":"medium","line_start":216},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"variable name, not the value; `<placeholder>`, `REDACTED`, `YOUR_*`, and","category":"external_commands","line_end":219,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`${VAR}` forms are ignored by the scan by design.","category":"external_commands","line_end":230,"severity":"medium","line_start":220},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":232,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":234,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Set all three documents `status: active`, update their `updated_at`, fix","category":"external_commands","line_end":234,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the three `INDEX.md` status cells, then route to `executor-planning`.","category":"external_commands","line_end":235,"severity":"medium","line_start":235},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Stated once** | Appears in exactly one `R<nn>` | Duplicated requirements drift, and then the spe","category":"external_commands","line_end":269,"severity":"medium","line_start":248},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| A type, function, endpoint, or field named nowhere in this spec or any referenced `IFCE`/`DSGN` | ","category":"external_commands","line_end":269,"severity":"medium","line_start":269},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Grep case-insensitively for at least: `TBD`, `TODO`, `appropriate`,","category":"external_commands","line_end":289,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`edge case`, `similar to`, `as needed`, `robust`, `performant`,","category":"external_commands","line_end":290,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`sensible`, `reasonable`, `etc\\.`, `and/or`. Every hit is either rewritten","category":"external_commands","line_end":291,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`consequences_accepted`, or the charter's non-goals? Does the spec's scope","category":"external_commands","line_end":319,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `INIT-0004-IFCE-01` | `placeCell` | R03, R04 | — |","category":"external_commands","line_end":319,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `INIT-0004-IFCE-01` | `evictCell` | — | OOS-02: automated eviction not built |","category":"external_commands","line_end":320,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `INIT-0004-ADR-02` | Tenant isolation boundary | R09 | — |","category":"external_commands","line_end":323,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every symbol in every referenced `IFCE` document's `provides:` list is","category":"external_commands","line_end":323,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`informs:` names this spec is reflected in a requirement or a constraint.","category":"external_commands","line_end":330,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the gate in one glance, and how a later reader sees that `evictCell` was","category":"external_commands","line_end":333,"severity":"medium","line_start":330},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**6. Design traceability.** Walk the design session's `## Handoff`","category":"external_commands","line_end":352,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `../executor/scripts/exec-store-check` — no finding for this","category":"external_commands","line_end":353,"severity":"medium","line_start":352},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"initiative. D8 checks the spec's `### R<nn>` headings, its verification","category":"external_commands","line_end":357,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Count `### R<nn>` headings in the spec and rows in the VRFY — equal,","category":"external_commands","line_end":358,"severity":"medium","line_start":357},{"id":"external_commands:SKILL.md:358:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and the VRFY's `criteria_count` matches.","category":"external_commands","line_end":360,"severity":"medium","line_start":358},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. `../executor/scripts/exec-scan-secrets docs/executor/<INIT>-<slug>/specs`","category":"external_commands","line_end":363,"severity":"medium","line_start":360},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"## Risk Documents (`RISK`)","category":"external_commands","line_end":369,"severity":"medium","line_start":363},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":374,"severity":"medium","line_start":369},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":423,"severity":"medium","line_start":374},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| This spec | A new or tightened `R<nn>` or `C<nn>` |","category":"external_commands","line_end":423,"severity":"medium","line_start":423},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"a `placement_latency_ms` histogram, proven by criterion V11\" is a","category":"external_commands","line_end":431,"severity":"medium","line_start":430},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"mitigation. `mitigations_planned` counts landed mitigations only.","category":"external_commands","line_end":435,"severity":"medium","line_start":431},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Do this before the gate, while the spec is `draft`. A risk whose","category":"external_commands","line_end":454,"severity":"medium","line_start":435},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**`accepted_without_mitigation` must equal the number of accepted risks","category":"external_commands","line_end":455,"severity":"medium","line_start":454},{"id":"external_commands:SKILL.md:455:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"named in the body.** Same for `risks_identified` and","category":"external_commands","line_end":456,"severity":"medium","line_start":455},{"id":"external_commands:SKILL.md:456:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`mitigations_planned`. A count that disagrees with the body is how a risk","category":"external_commands","line_end":460,"severity":"medium","line_start":456},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"## Verification Strategy (`VRFY`)","category":"external_commands","line_end":464,"severity":"medium","line_start":460},{"id":"external_commands:SKILL.md:464:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":468,"severity":"medium","line_start":464},{"id":"external_commands:SKILL.md:468:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":470,"severity":"medium","line_start":468},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`criteria_count` equals the number of criteria — table rows plus manual","category":"external_commands","line_end":471,"severity":"medium","line_start":470},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"criteria blocks. `evidence_types` lists only the methods actually used.","category":"external_commands","line_end":478,"severity":"medium","line_start":471},{"id":"external_commands:SKILL.md:478:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every `R<nn>` gets at least one row. A requirement needing two methods —","category":"external_commands","line_end":480,"severity":"medium","line_start":478},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"result — gets two rows. **Every `C<nn>` global constraint gets a row","category":"external_commands","line_end":485,"severity":"medium","line_start":480},{"id":"external_commands:SKILL.md:485:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| ID | `V<nn>`, sequential, never renumbered — plans and verdicts cite them |","category":"external_commands","line_end":486,"severity":"medium","line_start":485},{"id":"external_commands:SKILL.md:486:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Criterion | The `R<nn>` or `C<nn>` being proven |","category":"external_commands","line_end":486,"severity":"medium","line_start":486},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Method | `unit` \\| `integration` \\| `manual` \\| `smoke` |","category":"external_commands","line_end":487,"severity":"medium","line_start":487},{"id":"external_commands:SKILL.md:490:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Status | `pending` until `executor-verification` runs it |","category":"external_commands","line_end":490,"severity":"medium","line_start":490},{"id":"external_commands:SKILL.md:494:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`executor-verification` executes this document later and can only report","category":"external_commands","line_end":513,"severity":"medium","line_start":494},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `pytest tests/placement/test_scoring.py -v` → `12 passed`, exit 0","category":"external_commands","line_end":513,"severity":"medium","line_start":513},{"id":"external_commands:SKILL.md:514:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `curl -s -o /dev/null -w '%{http_code}' .../place -d '{\"cell\":\"nope\"}'`","category":"external_commands","line_end":515,"severity":"medium","line_start":514},{"id":"external_commands:SKILL.md:515:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"→ `422`","category":"external_commands","line_end":516,"severity":"medium","line_start":515},{"id":"external_commands:SKILL.md:516:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `node --version` → a version string `>= 20.11.0` (constraint `C02`)","category":"external_commands","line_end":516,"severity":"medium","line_start":516},{"id":"external_commands:SKILL.md:517:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Manual: (1) open the cell list; (2) click **Evict** on `cell-3`; (3)","category":"external_commands","line_end":518,"severity":"medium","line_start":517},{"id":"external_commands:SKILL.md:518:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the row shows `draining` within 2s; (4) the audit log gains one","category":"external_commands","line_end":519,"severity":"medium","line_start":518},{"id":"external_commands:SKILL.md:519:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`cell.evict` entry naming `cell-3`","category":"external_commands","line_end":519,"severity":"medium","line_start":519},{"id":"external_commands:SKILL.md:537:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Specification written for `INIT-0004`:","category":"external_commands","line_end":538,"severity":"medium","line_start":537},{"id":"external_commands:SKILL.md:538:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - `specs/INIT-0004-SPEC-01-cell-placement.md` — 14 requirements, 7 global constraints","category":"external_commands","line_end":539,"severity":"medium","line_start":538},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - `risks/INIT-0004-RISK-01-premortem.md` — 9 risks, 6 mitigated, 3 accepted","category":"external_commands","line_end":540,"severity":"medium","line_start":539},{"id":"external_commands:SKILL.md:540:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - `verification/INIT-0004-VRFY-01-acceptance-strategy.md` — 24 criteria","category":"external_commands","line_end":555,"severity":"medium","line_start":540},{"id":"external_commands:SKILL.md:555:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Only explicit approval passes the phase gate | `exec-initiative phase ... passed` claims a human a","category":"external_commands","line_end":572,"severity":"medium","line_start":555},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**While `status: draft` and no plan exists**, edit in place and bump","category":"external_commands","line_end":573,"severity":"medium","line_start":572},{"id":"external_commands:SKILL.md:573:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`updated_at`. Nothing downstream depends on the document yet.","category":"external_commands","line_end":575,"severity":"medium","line_start":573},{"id":"external_commands:SKILL.md:575:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Once any plan exists** — the spec's `plans:` list is non-empty, or any","category":"external_commands","line_end":576,"severity":"medium","line_start":575},{"id":"external_commands:SKILL.md:576:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"plan's `spec:` names this spec — a material change is a **new spec","category":"external_commands","line_end":603,"severity":"medium","line_start":576},{"id":"external_commands:SKILL.md:603:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `../executor/scripts/exec-id INIT-0004 SPEC` → the new ID.","category":"external_commands","line_end":604,"severity":"medium","line_start":603},{"id":"external_commands:SKILL.md:604:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Write the new spec. `supersedes: INIT-0004-SPEC-01`. Requirement","category":"external_commands","line_end":610,"severity":"medium","line_start":604},{"id":"external_commands:SKILL.md:610:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Old spec: `status: superseded`, `superseded_by: INIT-0004-SPEC-02`,","category":"external_commands","line_end":610,"severity":"medium","line_start":610},{"id":"external_commands:SKILL.md:611:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`updated_at` bumped. **Body untouched** — a superseded document keeps","category":"external_commands","line_end":613,"severity":"medium","line_start":611},{"id":"external_commands:SKILL.md:613:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Re-link verification.** New VRFY ID via `exec-id`, `spec:` naming the","category":"external_commands","line_end":613,"severity":"medium","line_start":613},{"id":"external_commands:SKILL.md:615:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"number or meaning, point the existing VRFY's `spec:` at the new ID and","category":"external_commands","line_end":616,"severity":"medium","line_start":615},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"bump `updated_at` instead — but the VRFY must never name a superseded","category":"external_commands","line_end":618,"severity":"medium","line_start":616},{"id":"external_commands:SKILL.md:618:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Notify plan authors.** Every plan whose `spec:` names the old ID is","category":"external_commands","line_end":623,"severity":"medium","line_start":618},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. Update the initiative `INDEX.md`: new rows appended, old rows'","category":"external_commands","line_end":624,"severity":"medium","line_start":623},{"id":"external_commands:SKILL.md:624:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"status cells edited to `superseded`. Rows are never deleted.","category":"external_commands","line_end":632,"severity":"medium","line_start":624},{"id":"external_commands:SKILL.md:632:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| ADR | Discovery, architecture, design, specification | `architecture/INIT-NNNN-ADR-nn-*.md`, track","category":"external_commands","line_end":633,"severity":"medium","line_start":632},{"id":"external_commands:SKILL.md:633:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Ruling | Execution, controller deciding without the human mid-plan | Per-plan `rulings.md` plus `.","category":"external_commands","line_end":633,"severity":"medium","line_start":633},{"id":"external_commands:SKILL.md:635:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Never call `exec-ruling` in this phase.** It appends to a plan's","category":"external_commands","line_end":636,"severity":"medium","line_start":635},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`rulings.md`, and in this phase there is no plan. A structural gap you","category":"external_commands","line_end":637,"severity":"medium","line_start":636},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"discover while specifying goes to `executor-architecture` as an ADR with","category":"external_commands","line_end":638,"severity":"medium","line_start":637},{"id":"external_commands:SKILL.md:638:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`informs: [INIT-0004-SPEC-01]`.","category":"external_commands","line_end":652,"severity":"medium","line_start":638},{"id":"filesystem:SKILL.md:116:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 specification entered","category":"filesystem","line_end":116,"severity":"high","line_start":116},{"id":"filesystem:SKILL.md:129:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-id INIT-0004 SPEC","category":"filesystem","line_end":129,"severity":"high","line_start":129},{"id":"filesystem:SKILL.md:130:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-id INIT-0004 RISK","category":"filesystem","line_end":130,"severity":"high","line_start":130},{"id":"filesystem:SKILL.md:131:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-id INIT-0004 VRFY","category":"filesystem","line_end":131,"severity":"high","line_start":131},{"id":"filesystem:SKILL.md:213:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-scan-secrets docs/executor/INIT-0004-<slug>","category":"filesystem","line_end":213,"severity":"high","line_start":213},{"id":"filesystem:SKILL.md:231:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 specification passed \"3 docs, 14 reqs\"","category":"filesystem","line_end":231,"severity":"high","line_start":231},{"id":"filesystem:SKILL.md:352:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. `../executor/scripts/exec-store-check` — no finding for this","category":"filesystem","line_end":352,"severity":"high","line_start":352},{"id":"filesystem:SKILL.md:360:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"5. `../executor/scripts/exec-scan-secrets docs/executor/<INIT>-<slug>/specs`","category":"filesystem","line_end":360,"severity":"high","line_start":360},{"id":"filesystem:SKILL.md:514:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- `curl -s -o /dev/null -w '%{http_code}' .../place -d '{\"cell\":\"nope\"}'`","category":"filesystem","line_end":514,"severity":"high","line_start":514},{"id":"filesystem:SKILL.md:603:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. `../executor/scripts/exec-id INIT-0004 SPEC` → the new ID.","category":"filesystem","line_end":603,"severity":"high","line_start":603},{"id":"filesystem:SKILL.md:666:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[layout](../executor/references/layout.md) ·","category":"filesystem","line_end":666,"severity":"high","line_start":666},{"id":"filesystem:SKILL.md:667:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[frontmatter](../executor/references/frontmatter.md) ·","category":"filesystem","line_end":667,"severity":"high","line_start":667},{"id":"filesystem:SKILL.md:668:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[indexes](../executor/references/indexes.md) ·","category":"filesystem","line_end":668,"severity":"high","line_start":668},{"id":"filesystem:SKILL.md:669:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[safety](../executor/references/safety.md)","category":"filesystem","line_end":669,"severity":"high","line_start":669},{"id":"filesystem:SKILL.md:514:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"- `curl -s -o /dev/null -w '%{http_code}' .../place -d '{\"cell\":\"nope\"}'`","category":"filesystem","line_end":514,"severity":"low","line_start":514},{"id":"blocker:SKILL.md:99:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"```mermaid","category":"blocker","line_end":100,"severity":"low","line_start":99},{"id":"blocker:SKILL.md:129:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"../executor/scripts/exec-id INIT-0004 SPEC","category":"blocker","line_end":129,"severity":"low","line_start":129},{"id":"blocker:SKILL.md:130:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"../executor/scripts/exec-id INIT-0004 RISK","category":"blocker","line_end":130,"severity":"low","line_start":130},{"id":"blocker:SKILL.md:131:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"../executor/scripts/exec-id INIT-0004 VRFY","category":"blocker","line_end":131,"severity":"low","line_start":131},{"id":"blocker:SKILL.md:389:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"> did not exist.","category":"blocker","line_end":389,"severity":"low","line_start":389},{"id":"blocker:SKILL.md:529:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"observing 422 — not by observing that valid requests still work.","category":"blocker","line_end":529,"severity":"low","line_start":529},{"id":"blocker:SKILL.md:603:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"1. `../executor/scripts/exec-id INIT-0004 SPEC` → the new ID.","category":"blocker","line_end":603,"severity":"low","line_start":603}],"finding_verdicts":[{"id":"external_commands:references/risk-template.md:71:ruby-shell-backtick-execution","reason":"Backticks format a histogram identifier in a mitigation table. The Markdown context shows no shell substitution or executable Ruby.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/risk-template.md:78:ruby-shell-backtick-execution","reason":"Backticks format requirement and constraint citation placeholders. These are document identifiers, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/risk-template.md:83:ruby-shell-backtick-execution","reason":"The formatted mitigations_planned name is a frontmatter count. The surrounding template describes risk accounting, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/risk-template.md:109:system-reconnaissance","reason":"This sentence explains why requirement changes are recorded. It contains no host inspection command or reconnaissance instruction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:47:ruby-shell-backtick-execution","reason":"Backticks format the required Node version in a constraint table. A version bound is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:48:ruby-shell-backtick-execution","reason":"The backticked package namespace is an example dependency constraint. No command or dynamic execution appears here.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:49:ruby-shell-backtick-execution","reason":"Backticks delimit a cell identifier validation expression. The expression is documentation, not an executed shell or Ruby string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:56:ruby-shell-backtick-execution","reason":"placeCell is a formatted interface symbol inside a requirement. It is not invoked through a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:67:ruby-shell-backtick-execution","reason":"The error field name is formatted inline in an HTTP rejection requirement. This is descriptive Markdown, not executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:68:ruby-shell-backtick-execution","reason":"unknown_cell is an example response value enclosed in Markdown backticks. No execution instruction accompanies it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:70:ruby-shell-backtick-execution","reason":"The error field is named as an observable response property. Markdown formatting does not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:73:ruby-shell-backtick-execution","reason":"The formatted placeCell symbol identifies the source interface. This is a citation, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:88:ruby-shell-backtick-execution","reason":"The interface table associates placeCell with requirement IDs. Backticks format a symbol without invoking it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:89:ruby-shell-backtick-execution","reason":"evictCell is an interface reference with an operator-only scope restriction. It is not executed by the template.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:94:ruby-shell-backtick-execution","reason":"provides is a formatted document field used for coverage review. No shell substitution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:95:ruby-shell-backtick-execution","reason":"informs is a frontmatter field named in a traceability rule. The backticks are Markdown delimiters.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:99:ruby-shell-backtick-execution","reason":"placeCell appears in a requirements coverage table. The formatted symbol is not an executable shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:100:ruby-shell-backtick-execution","reason":"evictCell appears as an interface symbol in a scope table. No automatic invocation or command substitution is requested.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:112:ruby-shell-backtick-execution","reason":"The out-of-scope row explicitly excludes automated eviction. Backticks only format the interface name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/spec-template.md:129:ruby-shell-backtick-execution","reason":"spec is a document relationship field in supersession guidance. It is not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/spec-template.md:158:system-reconnaissance","reason":"This table contrasts ambiguous and testable requirements about invalid input. It does not inspect the operating system.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:46:ruby-shell-backtick-execution","reason":"The table documents a named Vitest test and expected results. Markdown backticks are not shell substitution; no injected argument is shown.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/verification-template.md:47:ruby-shell-backtick-execution","reason":"Markdown backticks delimit explicit curl and jq test commands, not command substitution. The temporary-file risk is adjudicated separately.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:48:ruby-shell-backtick-execution","reason":"The example SQL command reads a fixture row count after rejection. It contains no dynamic shell substitution or destructive SQL.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/verification-template.md:49:ruby-shell-backtick-execution","reason":"This is a documented Vitest isolation test with a named repository test file. The backticks are Markdown, not executable substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/verification-template.md:50:ruby-shell-backtick-execution","reason":"The command describes a local load-test procedure with fixed arguments. No shell substitution or untrusted argument concatenation appears.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/verification-template.md:51:ruby-shell-backtick-execution","reason":"node --version is a benign version-floor check. Markdown backticks do not turn it into Ruby or shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:52:ruby-shell-backtick-execution","reason":"The jq example reads dependency names from package.json. It is a static inspection command, not dynamic code execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:53:ruby-shell-backtick-execution","reason":"The example runs a named cell-identifier test. Backticks document the test command and expected count, not shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/verification-template.md:55:ruby-shell-backtick-execution","reason":"Status and pending are formatted document values. This sentence forbids claiming results before verification; it does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:69:ruby-shell-backtick-execution","reason":"The backticks format a localhost page URL and fixture identifiers. A manual navigation instruction is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:70:ruby-shell-backtick-execution","reason":"cell-3 is a formatted fixture identifier in a manual confirmation step. It is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:71:ruby-shell-backtick-execution","reason":"The continuation names cell-3 in a confirmation dialog. The Markdown identifier is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:72:ruby-shell-backtick-execution","reason":"The fixture identifier and draining state are manual-test observations. Backticks provide formatting, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:73:ruby-shell-backtick-execution","reason":"draining is an expected persisted UI state. It is not an executed command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:74:ruby-shell-backtick-execution","reason":"The psql example selects the latest application audit event. It is read-only test evidence, not shell substitution or injected SQL.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/verification-template.md:75:ruby-shell-backtick-execution","reason":"cell.evict|cell-3 is expected database output in Markdown. The pipe character is data, not a shell pipeline.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:77:ruby-shell-backtick-execution","reason":"draining names an expected screen state in the evidence description. It is not executable shell text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:78:ruby-shell-backtick-execution","reason":"The formatted audit result is an observation expected from a previous step. It is not a command or executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/verification-template.md:84:ruby-shell-backtick-execution","reason":"Backticks format requirement and constraint ID patterns in a coverage rule. No code execution is requested.","verdict":"false_positive","confidence":0.99},{"id":"network:references/verification-template.md:69:hardcoded-url","reason":"The URL targets a localhost fixture console for manual verification. No external recipient, secret transmission, or remote download is shown.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/verification-template.md:47:temp-directory-access","reason":"curl writes to predictable /tmp/b without exclusive creation. Another local user could pre-create a symlink and redirect the write to an accessible file.","verdict":"confirmed","confidence":0.94},{"id":"blocker:references/verification-template.md:74:system-reconnaissance","reason":"The SELECT reads an application audit event to verify a fixture action. It does not enumerate users, hosts, or operating-system configuration.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/verification-template.md:141:system-reconnaissance","reason":"The row explains negative-path testing using abstract input and status placeholders. It contains no system reconnaissance command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"Backticks format a specification ID pattern and directory name. Neither is shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The table formats a risk document ID and output directory. These are documentation labels, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"The verification ID pattern and directory are formatted table entries. No shell or Ruby execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"draft is a formatted document status. The sentence describes document ordering, not execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The skill name and spec field are Markdown references to downstream planning. They are not executable substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"executor-execution names a workflow phase in conflict-resolution guidance. Backticks do not invoke a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"executor-review is a formatted workflow reference. No shell command or execution payload is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The sentence identifies the later verification skill. Its Markdown name is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"This opens a fenced text block showing citation grammar. The fence is Markdown syntax, not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"This closes the citation grammar text block. A Markdown fence does not execute shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"01 is formatted as the starting citation number. It is a document numbering rule, not code execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"R07 is a requirement citation used to explain stable numbering. It is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The formatted segments illustrate review-round ID grammar. Markdown delimiters do not execute these identifiers.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The SPEC segment is part of a citation grammar explanation. It is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The precondition row formats phase-log fields and a workflow owner. It contains no executable backtick substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The design gate row formats document states. These are approval preconditions, not shell expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"Backticks document session fields and a phase-entry command. The command uses explicit workflow arguments, not dynamic shell substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The row names architecture input documents to read. Markdown filenames and document kinds are not execution expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The Handoff heading is cited as an input section. Its backticks are formatting, not executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"informed_by is a frontmatter relationship field. The sentence requests traceability, not code execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"ARCH is a formatted architecture document kind. The text explains an explicitly skipped phase.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The mermaid fence introduces a workflow diagram. Markdown diagram syntax is not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The backticks close the workflow diagram fence. No executable substitution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"This opens a fenced Bash example with timestamp and phase-entry commands. The Markdown fence is not shell backtick substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"This is the closing delimiter of a Markdown command example. It is not evaluated by a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"date -u is documented as the timestamp source for frontmatter. Inline Markdown does not execute it as substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The text describes the phase-log helper and a document field. No dynamic shell expression appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"INDEX.md is the documented initiative registry filename. Its formatting does not invoke external commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The formatted text is expected phase-entry confirmation output. It is not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"The Bash fence documents fixed helper calls for allocating document IDs. Markdown fences are not command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"This closes the ID-allocation command example. The closing fence has no shell execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"exec-id is a helper name in prose about duplicate document IDs. The backticks only format the name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"INDEX.md is named as the location for recording an allocation race. It is not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The backticked path is a specification output naming template. No execution instruction or substitution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"status: draft is a document metadata value. Markdown formatting does not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The fence introduces YAML frontmatter relationships and counts. This is structured document metadata, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"The backticks close the YAML metadata example. A Markdown fence is not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The sentence relates a frontmatter count to constraint headings. Backticks delimit field and citation names.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"verification is a document relationship field filled with an allocated ID. It is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The table formats the range of constraint identifiers. It describes specification contents, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The formatted requirement range is citation notation in a section table. It has no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"IFCE is a document kind used for interface references. It is not an executable shell string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The formatted Node version floor illustrates verbatim constraint copying. It is not an actual command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The inline text pairs an interface document ID with placeCell. It is a citation, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"executor-architecture names the workflow responsible for interface changes. Markdown formatting does not execute the name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"draft is the document state during risk feedback. No executable expression appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"verification is named as a frontmatter link to the verification document. It is not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"spec is a relationship field used for reciprocal document linking. Its backticks are Markdown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"INDEX.md names the initiative document table to update. No shell substitution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"depends_on is a charter relationship field for declared dependencies. It is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"The Markdown fence introduces a local secret-scanning helper example. It is not shell backtick substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"This closes the secret-scan Bash example. The delimiter itself cannot execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","reason":"The backticked string describes a scanner diagnostic format without secret values. It is expected output, not an execution payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"The formatted placeholders illustrate redaction of secret values. No command substitution or credential extraction is requested.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","reason":"The variable placeholder is described as literal documentation text ignored by scanning. It is not expanded or executed here.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"The Bash fence introduces a phase-update example gated on explicit approval. It is Markdown syntax, not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"This is the closing Markdown fence for the approved phase update. No shell substitution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The formatted status, timestamp field, and index filename describe document updates. They are not shell expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","reason":"executor-planning is a downstream workflow reference after approval. Its inline formatting does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","reason":"The requirement ID pattern explains uniqueness of statements. It is citation notation, not executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","reason":"IFCE and DSGN are referenced document kinds in a dangling-reference rule. They are not shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"Backticks delimit literal terms to search for in documentation. They are search inputs, not executable shell strings.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"The formatted phrases are ambiguity-check search terms. No command substitution or injected argument is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"Backticks format search terms and an escaped search expression. The context is document quality review, not execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"consequences_accepted is an ADR field checked for consistency. It is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"The coverage row formats an interface ID and placeCell symbol. It is traceability data, not execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The coverage example explicitly excludes automated eviction. Formatted document and symbol names are not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"An ADR identifier is formatted in a requirements coverage table. No command is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"IFCE and provides identify source documents and metadata for coverage checks. They are not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"informs is a relationship field used to trace ADRs into requirements. Backticks only format its name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","reason":"evictCell is named in an explanation of explicit exclusions. The interface symbol is not invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The Handoff section heading is cited for design traceability. It is Markdown content, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","reason":"The inline helper command documents an initiative consistency check. There is no shell backtick substitution or attacker-controlled argument.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"The formatted requirement-heading pattern describes what the consistency checker validates. It is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","reason":"The requirement-heading pattern is used for counting document entries. Markdown backticks do not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:358:ruby-shell-backtick-execution","reason":"criteria_count is a frontmatter count to reconcile with verification entries. No execution expression appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","reason":"The command documents secret scanning of the initiative specification directory. Inline backticks are Markdown, not command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","reason":"RISK is a formatted document kind in a section heading. It is not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","reason":"This opens a fenced YAML example of risk metadata counts. A Markdown fence is not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","reason":"This closes the YAML risk frontmatter example. No command substitution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","reason":"The backticks format requirement and constraint ID placeholders for mitigation links. These are document citations, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","reason":"placement_latency_ms names an example histogram metric. It is not an executable shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","reason":"mitigations_planned is a risk accounting field named in prose. Markdown formatting does not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","reason":"draft is a specification status during risk feedback. There is no executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","reason":"accepted_without_mitigation is a document count checked against listed risks. The backticks are formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:455:ruby-shell-backtick-execution","reason":"risks_identified is a frontmatter count in a reconciliation rule. It is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:456:ruby-shell-backtick-execution","reason":"mitigations_planned is another count reconciled with the document body. No shell substitution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","reason":"VRFY is a formatted document kind in a section heading. It is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:464:ruby-shell-backtick-execution","reason":"The YAML fence introduces verification document metadata. Markdown fences are not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:468:ruby-shell-backtick-execution","reason":"This closes the verification metadata example. No shell or Ruby substitution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","reason":"criteria_count is a document field defining the number of verification criteria. It is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","reason":"evidence_types is a metadata list describing verification methods. Inline formatting has no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:478:ruby-shell-backtick-execution","reason":"The requirement ID pattern is used to define verification coverage. It is not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","reason":"The constraint ID pattern describes additional verification rows. Markdown backticks do not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:485:ruby-shell-backtick-execution","reason":"The verification ID pattern is a table column specification. It is citation grammar, not code execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:486:ruby-shell-backtick-execution","reason":"Requirement and constraint ID patterns specify which item a criterion proves. They are document identifiers.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","reason":"Backticks format allowed method labels such as unit and integration. These are categorical values, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:490:ruby-shell-backtick-execution","reason":"pending is a verification status and executor-verification names a later phase. Neither is shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:494:ruby-shell-backtick-execution","reason":"The sentence names a verification workflow and discusses required observations. The formatted name is not executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","reason":"The example names a pytest file and expected passing count as evidence. Backticks document a local test, not command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:514:ruby-shell-backtick-execution","reason":"The curl example demonstrates checking a rejection status with a placeholder endpoint. Markdown backticks are not executable shell substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:515:ruby-shell-backtick-execution","reason":"422 is expected HTTP status output from the preceding example. It is not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:516:ruby-shell-backtick-execution","reason":"node --version is a benign version check with a documented expected bound. No dynamic code execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:517:ruby-shell-backtick-execution","reason":"cell-3 names a fixture in a manual UI verification example. The formatted identifier is not executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:518:ruby-shell-backtick-execution","reason":"draining is an expected fixture state after a manual action. It is not executable shell text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:519:ruby-shell-backtick-execution","reason":"cell.evict and cell-3 are expected audit event values. Markdown formatting does not invoke commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:537:ruby-shell-backtick-execution","reason":"The initiative ID appears in an example review presentation. It is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:538:ruby-shell-backtick-execution","reason":"The formatted specification filename is an output artifact in a review summary. No shell execution is requested.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","reason":"The risk document filename is part of an example output summary. It is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:540:ruby-shell-backtick-execution","reason":"The verification filename identifies a completed drafting artifact for human review. Inline Markdown does not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:555:ruby-shell-backtick-execution","reason":"The phase command is discussed as an approval claim that requires explicit consent. No dynamic shell substitution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","reason":"status: draft is document metadata defining when in-place edits are permitted. It is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:573:ruby-shell-backtick-execution","reason":"updated_at is the timestamp field to update during a draft edit. The formatted field name is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:575:ruby-shell-backtick-execution","reason":"plans is a specification relationship list determining supersession requirements. No execution occurs through Markdown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:576:ruby-shell-backtick-execution","reason":"spec is a plan relationship field naming its source document. It is not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:603:ruby-shell-backtick-execution","reason":"The inline command allocates a replacement specification ID using fixed example arguments. Markdown backticks are not executable substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:604:ruby-shell-backtick-execution","reason":"supersedes names a document metadata relationship in replacement guidance. It is not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:610:ruby-shell-backtick-execution","reason":"The formatted status and superseded_by fields describe old document metadata. They are not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:611:ruby-shell-backtick-execution","reason":"updated_at is named while preserving the old document body. Its Markdown formatting does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:613:ruby-shell-backtick-execution","reason":"exec-id and spec name an allocation helper and relationship field. The prose requests document linking, not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:615:ruby-shell-backtick-execution","reason":"spec is the verification document pointer being re-linked during supersession. It is a metadata field, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","reason":"updated_at is a frontmatter timestamp field. The sentence constrains verification links, not execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:618:ruby-shell-backtick-execution","reason":"spec identifies the plan dependency used to notify affected authors. Backticks only format a metadata name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","reason":"INDEX.md is the initiative index to update after supersession. It is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:624:ruby-shell-backtick-execution","reason":"superseded is a document status value with a row-preservation rule. No executable expression appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:632:ruby-shell-backtick-execution","reason":"The backticked architecture path is an ADR naming template. It is a documentation location, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:633:ruby-shell-backtick-execution","reason":"rulings.md and the local decisions directory describe execution-phase artifacts. Their Markdown formatting is not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:635:ruby-shell-backtick-execution","reason":"The text explicitly forbids calling exec-ruling during specification. A formatted helper name is not execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","reason":"rulings.md is named while explaining why that helper must not run. This is a filename reference, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","reason":"executor-architecture is a workflow reference for resolving structural gaps. It is not executable shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:638:ruby-shell-backtick-execution","reason":"informs is example ADR relationship metadata. The formatted field is not executed.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:116:path-traversal-sequence","reason":"The fixed sibling path invokes the documented Executor phase helper. No user-controlled traversal or arbitrary filesystem target is shown; helper implementation is outside this package.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:129:path-traversal-sequence","reason":"The fixed sibling exec-id path allocates a specification identifier. The parent segment locates a companion skill, not an attacker-controlled traversal payload.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:130:path-traversal-sequence","reason":"The fixed companion helper path allocates a risk document identifier. No input is used to construct an escaping filesystem path.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:131:path-traversal-sequence","reason":"The parent-relative path locates the documented companion ID helper for verification documents. No arbitrary path selection or traversal input appears.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:213:path-traversal-sequence","reason":"The fixed sibling helper is documented to scan initiative documents for secrets without printing values. No attacker-controlled traversal is shown; implementation is not bundled.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:231:path-traversal-sequence","reason":"The fixed companion phase helper updates workflow status only after explicit approval. A parent-relative dependency path alone is not exploitable traversal.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:352:path-traversal-sequence","reason":"The fixed sibling reference identifies an initiative consistency checker. No user input or arbitrary target is used to escape a filesystem boundary.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:360:path-traversal-sequence","reason":"The fixed sibling secret-scan helper targets specification documents. The parent segment locates a companion dependency, not a traversal attack.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:514:path-traversal-sequence","reason":"The endpoint begins with a typographic ellipsis denoting omitted URL context. It is not a filesystem parent-directory traversal sequence.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:603:path-traversal-sequence","reason":"The fixed companion exec-id path allocates a replacement specification ID. No attacker-controlled path or arbitrary filesystem access is demonstrated.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:666:path-traversal-sequence","reason":"This is a fixed Markdown link to the companion layout reference. It does not construct a path from untrusted input or execute a file.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:667:path-traversal-sequence","reason":"The parent-relative Markdown link names a companion frontmatter reference. It is ordinary documentation navigation, not a traversal exploit.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:668:path-traversal-sequence","reason":"The fixed Markdown link points to companion index documentation. No arbitrary path construction or sensitive-file access is requested.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:669:path-traversal-sequence","reason":"The fixed Markdown link names companion safety documentation. A parent-relative documentation reference is not an attacker-controlled traversal path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:514:standard-device-file-access","reason":"curl discards the response body through /dev/null while checking an HTTP status. This standard output sink does not expose device data.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:99:system-reconnaissance","reason":"The location opens a Mermaid workflow diagram. It contains no operating-system discovery command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:129:system-reconnaissance","reason":"exec-id allocates document identifiers according to surrounding prose. It is not the operating-system id command or a host reconnaissance instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:130:system-reconnaissance","reason":"The helper allocates a risk document identifier. The id substring does not imply system identity enumeration.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:131:system-reconnaissance","reason":"exec-id is the documented verification document numbering helper. No system user or host information is requested.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:389:system-reconnaissance","reason":"The phrase did not exist concludes a hypothetical failure narrative. It is prose, not a system discovery command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:529:system-reconnaissance","reason":"The sentence explains observing an HTTP rejection during negative testing. It contains no host enumeration or reconnaissance procedure.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:603:system-reconnaissance","reason":"The exec-id helper allocates a replacement document ID during supersession. The documented purpose is numbering, not operating-system identity discovery.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"6d0b11444384184b7ae743742a7e233a9a705cd9","subject_content_hash":"1301fbbc32818539db823b4d02086b8924f1d48604534fcca71f8a35618635a5","subject_tree_hash":"5c16273bcee4b72c0ce365663f3167a15af1f08fa8657451268731eb1f504ad7","subject_plugin_path":"skills/atri10/executor-spec","audit_payload_hash":"9e1327c7994849048a3810c16411c835","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"6d0b11444384184b7ae743742a7e233a9a705cd9","contentHash":"1301fbbc32818539db823b4d02086b8924f1d48604534fcca71f8a35618635a5","treeHash":"5c16273bcee4b72c0ce365663f3167a15af1f08fa8657451268731eb1f504ad7","pluginPath":"skills/atri10/executor-spec","auditPayloadHash":"9e1327c7994849048a3810c16411c835"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/atri10-executor-spec/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}