{"data":{"skill":{"slug":"bodhisearch-bodhi-sdk-react-integration","name":"bodhi-sdk-react-integration","icon":"📦","repo":"https://github.com/BodhiSearch/bodhi-js/tree/main/bodhi-js-sdk/skills/react-integration","status":"approved","author":"BodhiSearch","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"964b2651-213f-4b9a-a114-845297dd1fe3","skill_id":"012f6f8a-fe78-4142-8cf3-ca05c5b3f941","version":8,"content_hash":"v3:5ab1d37e83436c6eef84de88573e142b94f2a4ad:6590cf557f9aba8cec36262dae1acb711caf2a73834007ec03083489665b93c6:90de8502db0c51f0fd07c0e963a0cc2a69d12905604eb89c77cd19fb79d0d2db:736b696c6c732f626f6468697365617263682f626f6468692d73646b2d72656163742d696e746567726174696f6e:678a4a4650576afdafd6eeb4d4d529a5","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static findings are false positives from Markdown, TypeScript template literals, documented OAuth URLs, and public Vite configuration. No prompt injection evidence was found. One semantic issue remains: troubleshooting examples can expose OAuth tokens through full auth-state and localStorage logging.","remediation":[{"issue":"OAuth token state is exposed in troubleshooting examples.","severity":"high","suggestion":"Replace full auth and localStorage logging with redacted status fields. Never print access tokens, refresh tokens, or complete auth state."},{"issue":"Debug log sharing can include sensitive browser state.","severity":"medium","suggestion":"Tell users to redact tokens, auth state, localStorage values, and account identifiers before sharing console logs."},{"issue":"Environment examples could be mistaken for secret storage guidance.","severity":"low","suggestion":"State that Vite variables are public browser configuration and must not contain private secrets."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"code-examples.md","line_end":68,"line_start":66},{"file":"code-examples.md","line_end":77,"line_start":68},{"file":"code-examples.md","line_end":365,"line_start":339},{"file":"code-examples.md","line_end":430,"line_start":418},{"file":"code-examples.md","line_end":448,"line_start":430},{"file":"code-examples.md","line_end":498,"line_start":478},{"file":"code-examples.md","line_end":625,"line_start":567},{"file":"oauth-setup.md","line_end":131,"line_start":124},{"file":"oauth-setup.md","line_end":225,"line_start":224},{"file":"quick-start.md","line_end":170,"line_start":109},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":56,"line_start":54},{"file":"SKILL.md","line_end":60,"line_start":56},{"file":"SKILL.md","line_end":79,"line_start":60},{"file":"SKILL.md","line_end":83,"line_start":79},{"file":"SKILL.md","line_end":131,"line_start":83},{"file":"SKILL.md","line_end":166,"line_start":131},{"file":"SKILL.md","line_end":172,"line_start":166},{"file":"SKILL.md","line_end":190,"line_start":172},{"file":"SKILL.md","line_end":194,"line_start":190},{"file":"SKILL.md","line_end":218,"line_start":194},{"file":"SKILL.md","line_end":224,"line_start":218},{"file":"SKILL.md","line_end":235,"line_start":224},{"file":"SKILL.md","line_end":239,"line_start":235},{"file":"SKILL.md","line_end":241,"line_start":239},{"file":"SKILL.md","line_end":251,"line_start":241},{"file":"SKILL.md","line_end":257,"line_start":251},{"file":"SKILL.md","line_end":271,"line_start":257},{"file":"SKILL.md","line_end":275,"line_start":271},{"file":"SKILL.md","line_end":300,"line_start":275},{"file":"SKILL.md","line_end":304,"line_start":300},{"file":"SKILL.md","line_end":316,"line_start":304},{"file":"SKILL.md","line_end":332,"line_start":316},{"file":"SKILL.md","line_end":333,"line_start":332},{"file":"SKILL.md","line_end":334,"line_start":333},{"file":"SKILL.md","line_end":335,"line_start":334},{"file":"SKILL.md","line_end":336,"line_start":335},{"file":"SKILL.md","line_end":343,"line_start":336},{"file":"SKILL.md","line_end":353,"line_start":343},{"file":"SKILL.md","line_end":353,"line_start":353},{"file":"SKILL.md","line_end":354,"line_start":354},{"file":"SKILL.md","line_end":364,"line_start":355},{"file":"SKILL.md","line_end":365,"line_start":364},{"file":"SKILL.md","line_end":387,"line_start":365},{"file":"SKILL.md","line_end":388,"line_start":387},{"file":"SKILL.md","line_end":389,"line_start":388},{"file":"SKILL.md","line_end":394,"line_start":389},{"file":"SKILL.md","line_end":395,"line_start":394}]},{"factor":"network","evidence":[{"file":"code-examples.md","line_end":68,"line_start":68},{"file":"code-examples.md","line_end":633,"line_start":633},{"file":"code-examples.md","line_end":634,"line_start":634},{"file":"code-examples.md","line_end":641,"line_start":641},{"file":"code-examples.md","line_end":642,"line_start":642},{"file":"github-pages.md","line_end":46,"line_start":46},{"file":"github-pages.md","line_end":215,"line_start":215},{"file":"oauth-setup.md","line_end":39,"line_start":39},{"file":"oauth-setup.md","line_end":40,"line_start":40},{"file":"oauth-setup.md","line_end":87,"line_start":87},{"file":"oauth-setup.md","line_end":88,"line_start":88},{"file":"oauth-setup.md","line_end":137,"line_start":137},{"file":"oauth-setup.md","line_end":138,"line_start":138},{"file":"oauth-setup.md","line_end":145,"line_start":145},{"file":"oauth-setup.md","line_end":146,"line_start":146},{"file":"oauth-setup.md","line_end":248,"line_start":248},{"file":"oauth-setup.md","line_end":277,"line_start":277},{"file":"oauth-setup.md","line_end":278,"line_start":278},{"file":"oauth-setup.md","line_end":292,"line_start":292},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":228,"line_start":228},{"file":"SKILL.md","line_end":357,"line_start":357},{"file":"SKILL.md","line_end":397,"line_start":397}]}],"critical_findings":[],"high_findings":[{"title":"OAuth Token Disclosure in Debug Examples","locations":[{"file":"troubleshooting.md","line_end":148,"line_start":137},{"file":"troubleshooting.md","line_end":443,"line_start":437},{"file":"troubleshooting.md","line_end":463,"line_start":454}],"confidence":0.88,"description":"Troubleshooting guidance logs full auth state and reads stored Bodhi auth state from localStorage. The same section shows auth state containing an access token, so shared console output could expose credentials.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The file explicitly logs the auth object and shows auth state with an accessToken field. Exploitation depends on users sharing logs or console output, so confidence is high but not absolute."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":6,"total_lines":2475,"audit_model":"codex","audited_at":"2026-07-05T03:41:45.792+00:00","created_at":"2026-07-16T17:26:37.313402+00:00","static_findings":[{"id":"external_commands:code-examples.md:66:ruby-shell-backtick-execution","file":"code-examples.md","pattern":"Ruby/shell backtick execution","snippet":"callbackPath={`${BASE_PATH}/callback`}","category":"external_commands","line_end":68,"severity":"medium","line_start":66},{"id":"external_commands:code-examples.md:68:ruby-shell-backtick-execution","file":"code-examples.md","pattern":"Ruby/shell backtick execution","snippet":"redirectUri: `https://username.github.io${BASE_PATH}/callback`,","category":"external_commands","line_end":77,"severity":"medium","line_start":68},{"id":"external_commands:code-examples.md:339:ruby-shell-backtick-execution","file":"code-examples.md","pattern":"Ruby/shell backtick execution","snippet":"setResponse(`Error: ${err instanceof Error ? err.message : String(err)}`);","category":"external_commands","line_end":365,"severity":"medium","line_start":339},{"id":"external_commands:code-examples.md:418:ruby-shell-backtick-execution","file":"code-examples.md","pattern":"Ruby/shell backtick execution","snippet":"content: `Error: ${err instanceof Error ? err.message : String(err)}`,","category":"external_commands","line_end":430,"severity":"medium","line_start":418},{"id":"external_commands:code-examples.md:430:ruby-shell-backtick-execution","file":"code-examples.md","pattern":"Ruby/shell backtick execution","snippet":"<div key={idx} className={`message ${msg.role}`}>","category":"external_commands","line_end":448,"severity":"medium","line_start":430},{"id":"external_commands:code-examples.md:478:ruby-shell-backtick-execution","file":"code-examples.md","pattern":"Ruby/shell backtick execution","snippet":"setResponse(`Error: ${err instanceof Error ? err.message : String(err)}`);","category":"external_commands","line_end":498,"severity":"medium","line_start":478},{"id":"external_commands:code-examples.md:567:ruby-shell-backtick-execution","file":"code-examples.md","pattern":"Ruby/shell backtick execution","snippet":"setResponse(`Error: ${err instanceof Error ? err.message : String(err)}`);","category":"external_commands","line_end":625,"severity":"medium","line_start":567},{"id":"network:code-examples.md:68:hardcoded-url","file":"code-examples.md","pattern":"Hardcoded URL","snippet":"redirectUri: `https://username.github.io${BASE_PATH}/callback`,","category":"network","line_end":68,"severity":"low","line_start":68},{"id":"network:code-examples.md:633:hardcoded-url","file":"code-examples.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_AUTH_SERVER=https://main-id.getbodhi.app/realms/bodhi","category":"network","line_end":633,"severity":"low","line_start":633},{"id":"network:code-examples.md:634:hardcoded-url","file":"code-examples.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_REDIRECT_URI=http://localhost:5173/callback","category":"network","line_end":634,"severity":"low","line_start":634},{"id":"network:code-examples.md:641:hardcoded-url","file":"code-examples.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_AUTH_SERVER=https://id.getbodhi.app/realms/bodhi","category":"network","line_end":641,"severity":"low","line_start":641},{"id":"network:code-examples.md:642:hardcoded-url","file":"code-examples.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_REDIRECT_URI=https://myapp.com/callback","category":"network","line_end":642,"severity":"low","line_start":642},{"id":"sensitive:code-examples.md:32:environment-file-access","file":"code-examples.md","pattern":"Environment file access","snippet":"const CLIENT_ID = import.meta.env.VITE_BODHI_CLIENT_ID;","category":"sensitive","line_end":32,"severity":"high","line_start":32},{"id":"sensitive:code-examples.md:33:environment-file-access","file":"code-examples.md","pattern":"Environment file access","snippet":"const AUTH_SERVER = import.meta.env.VITE_BODHI_AUTH_SERVER;","category":"sensitive","line_end":33,"severity":"high","line_start":33},{"id":"sensitive:code-examples.md:41:environment-file-access","file":"code-examples.md","pattern":"Environment file access","snippet":"logLevel: import.meta.env.DEV ? 'debug' : 'warn',","category":"sensitive","line_end":41,"severity":"high","line_start":41},{"id":"sensitive:code-examples.md:58:environment-file-access","file":"code-examples.md","pattern":"Environment file access","snippet":"const CLIENT_ID = import.meta.env.VITE_BODHI_CLIENT_ID;","category":"sensitive","line_end":58,"severity":"high","line_start":58},{"id":"sensitive:code-examples.md:509:environment-file-access","file":"code-examples.md","pattern":"Environment file access","snippet":"const CLIENT_ID = import.meta.env.VITE_BODHI_CLIENT_ID;","category":"sensitive","line_end":509,"severity":"high","line_start":509},{"id":"sensitive:code-examples.md:629:environment-file-access","file":"code-examples.md","pattern":"Environment file access","snippet":"**.env.development**:","category":"sensitive","line_end":629,"severity":"high","line_start":629},{"id":"sensitive:code-examples.md:637:environment-file-access","file":"code-examples.md","pattern":"Environment file access","snippet":"**.env.production**:","category":"sensitive","line_end":637,"severity":"high","line_start":637},{"id":"sensitive:code-examples.md:629:environment-variant-files","file":"code-examples.md","pattern":"Environment variant files","snippet":"**.env.development**:","category":"sensitive","line_end":629,"severity":"high","line_start":629},{"id":"sensitive:code-examples.md:637:environment-variant-files","file":"code-examples.md","pattern":"Environment variant files","snippet":"**.env.production**:","category":"sensitive","line_end":637,"severity":"high","line_start":637},{"id":"blocker:code-examples.md:632:system-reconnaissance","file":"code-examples.md","pattern":"System reconnaissance","snippet":"VITE_BODHI_CLIENT_ID=app-dev-client-id-uuid","category":"blocker","line_end":633,"severity":"low","line_start":632},{"id":"blocker:code-examples.md:640:system-reconnaissance","file":"code-examples.md","pattern":"System reconnaissance","snippet":"VITE_BODHI_CLIENT_ID=app-prod-client-id-uuid","category":"blocker","line_end":641,"severity":"low","line_start":640},{"id":"network:github-pages.md:46:hardcoded-url","file":"github-pages.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'https://username.github.io/repo-name/callback',","category":"network","line_end":46,"severity":"low","line_start":46},{"id":"network:github-pages.md:215:hardcoded-url","file":"github-pages.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'https://username.github.io/my-chat-app/callback',","category":"network","line_end":215,"severity":"low","line_start":215},{"id":"sensitive:github-pages.md:37:environment-file-access","file":"github-pages.md","pattern":"Environment file access","snippet":"const CLIENT_ID = import.meta.env.VITE_BODHI_CLIENT_ID;","category":"sensitive","line_end":37,"severity":"high","line_start":37},{"id":"sensitive:github-pages.md:211:environment-file-access","file":"github-pages.md","pattern":"Environment file access","snippet":"authClientId={import.meta.env.VITE_BODHI_CLIENT_ID}","category":"sensitive","line_end":211,"severity":"high","line_start":211},{"id":"external_commands:oauth-setup.md:124:ruby-shell-backtick-execution","file":"oauth-setup.md","pattern":"Ruby/shell backtick execution","snippet":"redirectUri: REDIRECT_URI || `${window.location.origin}/callback`,","category":"external_commands","line_end":131,"severity":"medium","line_start":124},{"id":"external_commands:oauth-setup.md:224:ruby-shell-backtick-execution","file":"oauth-setup.md","pattern":"Ruby/shell backtick execution","snippet":"redirectUri: `${window.location.origin}/callback`","category":"external_commands","line_end":225,"severity":"medium","line_start":224},{"id":"network:oauth-setup.md:39:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"authServerUrl: 'https://main-id.getbodhi.app/realms/bodhi',","category":"network","line_end":39,"severity":"low","line_start":39},{"id":"network:oauth-setup.md:40:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'http://localhost:5173/callback',","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"network:oauth-setup.md:87:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"authServerUrl: 'https://id.getbodhi.app/realms/bodhi',","category":"network","line_end":87,"severity":"low","line_start":87},{"id":"network:oauth-setup.md:88:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'https://myapp.com/callback',","category":"network","line_end":88,"severity":"low","line_start":88},{"id":"network:oauth-setup.md:137:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_AUTH_SERVER=https://main-id.getbodhi.app/realms/bodhi","category":"network","line_end":137,"severity":"low","line_start":137},{"id":"network:oauth-setup.md:138:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_REDIRECT_URI=http://localhost:5173/callback","category":"network","line_end":138,"severity":"low","line_start":138},{"id":"network:oauth-setup.md:145:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_AUTH_SERVER=https://id.getbodhi.app/realms/bodhi","category":"network","line_end":145,"severity":"low","line_start":145},{"id":"network:oauth-setup.md:146:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"VITE_BODHI_REDIRECT_URI=https://myapp.com/callback","category":"network","line_end":146,"severity":"low","line_start":146},{"id":"network:oauth-setup.md:248:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'https://username.github.io/my-repo/callback',","category":"network","line_end":248,"severity":"low","line_start":248},{"id":"network:oauth-setup.md:277:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"authServerUrl: 'https://main-id.getbodhi.app/realms/bodhi',","category":"network","line_end":277,"severity":"low","line_start":277},{"id":"network:oauth-setup.md:278:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'http://localhost:5173/callback',","category":"network","line_end":278,"severity":"low","line_start":278},{"id":"network:oauth-setup.md:292:hardcoded-url","file":"oauth-setup.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'https://myapp.com/app/callback',","category":"network","line_end":292,"severity":"low","line_start":292},{"id":"sensitive:oauth-setup.md:114:environment-file-access","file":"oauth-setup.md","pattern":"Environment file access","snippet":"const CLIENT_ID = import.meta.env.VITE_BODHI_CLIENT_ID;","category":"sensitive","line_end":114,"severity":"high","line_start":114},{"id":"sensitive:oauth-setup.md:115:environment-file-access","file":"oauth-setup.md","pattern":"Environment file access","snippet":"const AUTH_SERVER = import.meta.env.VITE_BODHI_AUTH_SERVER;","category":"sensitive","line_end":115,"severity":"high","line_start":115},{"id":"sensitive:oauth-setup.md:116:environment-file-access","file":"oauth-setup.md","pattern":"Environment file access","snippet":"const REDIRECT_URI = import.meta.env.VITE_BODHI_REDIRECT_URI;","category":"sensitive","line_end":116,"severity":"high","line_start":116},{"id":"sensitive:oauth-setup.md:133:environment-file-access","file":"oauth-setup.md","pattern":"Environment file access","snippet":"**.env.development**:","category":"sensitive","line_end":133,"severity":"high","line_start":133},{"id":"sensitive:oauth-setup.md:141:environment-file-access","file":"oauth-setup.md","pattern":"Environment file access","snippet":"**.env.production**:","category":"sensitive","line_end":141,"severity":"high","line_start":141},{"id":"sensitive:oauth-setup.md:133:environment-variant-files","file":"oauth-setup.md","pattern":"Environment variant files","snippet":"**.env.development**:","category":"sensitive","line_end":133,"severity":"high","line_start":133},{"id":"sensitive:oauth-setup.md:141:environment-variant-files","file":"oauth-setup.md","pattern":"Environment variant files","snippet":"**.env.production**:","category":"sensitive","line_end":141,"severity":"high","line_start":141},{"id":"blocker:oauth-setup.md:136:system-reconnaissance","file":"oauth-setup.md","pattern":"System reconnaissance","snippet":"VITE_BODHI_CLIENT_ID=app-dev-client-id","category":"blocker","line_end":137,"severity":"low","line_start":136},{"id":"blocker:oauth-setup.md:144:system-reconnaissance","file":"oauth-setup.md","pattern":"System reconnaissance","snippet":"VITE_BODHI_CLIENT_ID=app-prod-client-id","category":"blocker","line_end":145,"severity":"low","line_start":144},{"id":"blocker:oauth-setup.md:311:system-reconnaissance","file":"oauth-setup.md","pattern":"System reconnaissance","snippet":"### \"Invalid redirect_uri\"","category":"blocker","line_end":311,"severity":"low","line_start":311},{"id":"blocker:oauth-setup.md:321:system-reconnaissance","file":"oauth-setup.md","pattern":"System reconnaissance","snippet":"**Cause**: Wrong client_id or client not registered.","category":"blocker","line_end":321,"severity":"low","line_start":321},{"id":"blocker:oauth-setup.md:324:system-reconnaissance","file":"oauth-setup.md","pattern":"System reconnaissance","snippet":"- Verify client_id copied correctly from developer portal","category":"blocker","line_end":324,"severity":"low","line_start":324},{"id":"external_commands:quick-start.md:109:ruby-shell-backtick-execution","file":"quick-start.md","pattern":"Ruby/shell backtick execution","snippet":"setResponse(`Error: ${err instanceof Error ? err.message : String(err)}`);","category":"external_commands","line_end":170,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Install**: `npm install @bodhiapp/bodhi-js-react`","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Wrap App**: Add `<BodhiProvider authClientId={...}>` around your app","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Use Hook**: Access `useBodhi()` for client, auth state, and actions","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@bodhiapp/bodhi-js-react` - Preset package for web apps (auto-creates WebUIClient)","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@bodhiapp/bodhi-js-react-ext` - Preset package for Chrome extensions (auto-creates ExtUIClient)","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Dev**: `https://main-id.getbodhi.app/realms/bodhi` (allows localhost)","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Prod**: `https://id.getbodhi.app/realms/bodhi` (requires real domain)","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":56,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":60,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":79,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":83,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":131,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"setResponse(`Error: ${err instanceof Error ? err.message : String(err)}`);","category":"external_commands","line_end":166,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":172,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":190,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":194,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":218,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":224,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":235,"severity":"medium","line_start":224},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":239,"severity":"medium","line_start":235},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When your app runs on a sub-path (e.g., GitHub Pages at `/repo-name/`):","category":"external_commands","line_end":241,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":251,"severity":"medium","line_start":241},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":257,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":271,"severity":"medium","line_start":257},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":275,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":300,"severity":"medium","line_start":275},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":304,"severity":"medium","line_start":300},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":316,"severity":"medium","line_start":304},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":332,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/quick-start.md` - Official quick start","category":"external_commands","line_end":333,"severity":"medium","line_start":332},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/react-integration.md` - Deep dive into React integration","category":"external_commands","line_end":334,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/authentication.md` - OAuth flow details","category":"external_commands","line_end":335,"severity":"medium","line_start":334},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/streaming.md` - Streaming patterns","category":"external_commands","line_end":336,"severity":"medium","line_start":335},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/api-reference.md` - Complete API documentation","category":"external_commands","line_end":343,"severity":"medium","line_start":336},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Install package**: Run `npm install @bodhiapp/bodhi-js-react`","category":"external_commands","line_end":353,"severity":"medium","line_start":343},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Check connection status**: Use `isOverallReady`, `isReady`, `isServerReady`","category":"external_commands","line_end":353,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Verify auth state**: Check `isAuthenticated`, `auth` object","category":"external_commands","line_end":354,"severity":"medium","line_start":354},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Inspect logs**: Look for `[Bodhi/Web]` prefixed logs in console","category":"external_commands","line_end":364,"severity":"medium","line_start":355},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Extension detection**: Check console for `[Bodhi/Web] Extension detected`","category":"external_commands","line_end":365,"severity":"medium","line_start":364},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Server connection**: Verify `[Bodhi/Web] Server ready`","category":"external_commands","line_end":387,"severity":"medium","line_start":365},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/quick-start.md` - Primary integration guide","category":"external_commands","line_end":388,"severity":"medium","line_start":387},{"id":"external_commands:SKILL.md:388:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/react-integration.md` - React-specific patterns","category":"external_commands","line_end":389,"severity":"medium","line_start":388},{"id":"external_commands:SKILL.md:389:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bodhi-js-sdk/docs/` - Comprehensive documentation and examples","category":"external_commands","line_end":394,"severity":"medium","line_start":389},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Always use `@bodhiapp/bodhi-js-react` preset package (simplest)","category":"external_commands","line_end":395,"severity":"medium","line_start":394},{"id":"network:SKILL.md:24:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"2. **Register**: Create OAuth client at https://developer.getbodhi.app","category":"network","line_end":24,"severity":"low","line_start":24},{"id":"network:SKILL.md:47:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Dev**: `https://main-id.getbodhi.app/realms/bodhi` (allows localhost)","category":"network","line_end":47,"severity":"low","line_start":47},{"id":"network:SKILL.md:48:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Prod**: `https://id.getbodhi.app/realms/bodhi` (requires real domain)","category":"network","line_end":48,"severity":"low","line_start":48},{"id":"network:SKILL.md:228:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"redirectUri: 'https://myapp.com/callback',","category":"network","line_end":228,"severity":"low","line_start":228},{"id":"network:SKILL.md:357:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"5. **Test backend**: Ensure local server at http://localhost:1135","category":"network","line_end":357,"severity":"low","line_start":357},{"id":"network:SKILL.md:397:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Default backend: http://localhost:1135","category":"network","line_end":397,"severity":"low","line_start":397},{"id":"blocker:SKILL.md:176:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"isAuthenticated, // User has valid OAuth token","category":"blocker","line_end":176,"severity":"low","line_start":176},{"id":"sensitive:troubleshooting.md:413:environment-file-access","file":"troubleshooting.md","pattern":"Environment file access","snippet":"- `.env.development` → Dev client ID, dev auth server","category":"sensitive","line_end":413,"severity":"high","line_start":413},{"id":"sensitive:troubleshooting.md:414:environment-file-access","file":"troubleshooting.md","pattern":"Environment file access","snippet":"- `.env.production` → Prod client ID, prod auth server (or default)","category":"sensitive","line_end":414,"severity":"high","line_start":414},{"id":"sensitive:troubleshooting.md:417:environment-file-access","file":"troubleshooting.md","pattern":"Environment file access","snippet":"console.log('Client ID:', import.meta.env.VITE_BODHI_CLIENT_ID);","category":"sensitive","line_end":417,"severity":"high","line_start":417},{"id":"sensitive:troubleshooting.md:413:environment-variant-files","file":"troubleshooting.md","pattern":"Environment variant files","snippet":"- `.env.development` → Dev client ID, dev auth server","category":"sensitive","line_end":413,"severity":"high","line_start":413},{"id":"sensitive:troubleshooting.md:414:environment-variant-files","file":"troubleshooting.md","pattern":"Environment variant files","snippet":"- `.env.production` → Prod client ID, prod auth server (or default)","category":"sensitive","line_end":414,"severity":"high","line_start":414},{"id":"sensitive:troubleshooting.md:458:certificate-key-files","file":"troubleshooting.md","pattern":"Certificate/key files","snippet":"Object.keys(localStorage).filter(k => k.startsWith('bodhi'));","category":"sensitive","line_end":458,"severity":"high","line_start":458},{"id":"blocker:troubleshooting.md:120:system-reconnaissance","file":"troubleshooting.md","pattern":"System reconnaissance","snippet":"- Invalid client ID","category":"blocker","line_end":120,"severity":"low","line_start":120},{"id":"blocker:troubleshooting.md:480:system-reconnaissance","file":"troubleshooting.md","pattern":"System reconnaissance","snippet":"| \"Invalid client_id\"     | Wrong OAuth client ID           | Verify client ID from developer portal","category":"blocker","line_end":480,"severity":"low","line_start":480},{"id":"blocker:troubleshooting.md:482:system-reconnaissance","file":"troubleshooting.md","pattern":"System reconnaissance","snippet":"| \"Unauthorized\"          | Tokens expired/invalid          | Logout and login again                ","category":"blocker","line_end":482,"severity":"low","line_start":482}],"finding_verdicts":[{"id":"external_commands:code-examples.md:66:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:code-examples.md:68:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:code-examples.md:339:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:code-examples.md:418:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:code-examples.md:430:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:code-examples.md:478:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:code-examples.md:567:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"network:code-examples.md:68:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:code-examples.md:633:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:code-examples.md:634:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:code-examples.md:641:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:code-examples.md:642:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:code-examples.md:32:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:33:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:41:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:58:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:509:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:629:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:637:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:629:environment-variant-files","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:code-examples.md:637:environment-variant-files","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"blocker:code-examples.md:632:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"blocker:code-examples.md:640:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"network:github-pages.md:46:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:github-pages.md:215:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:github-pages.md:37:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:github-pages.md:211:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:oauth-setup.md:124:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:oauth-setup.md:224:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"network:oauth-setup.md:39:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:40:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:87:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:88:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:137:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:138:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:145:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:146:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:248:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:277:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:278:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:oauth-setup.md:292:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:oauth-setup.md:114:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:oauth-setup.md:115:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:oauth-setup.md:116:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:oauth-setup.md:133:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:oauth-setup.md:141:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:oauth-setup.md:133:environment-variant-files","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:oauth-setup.md:141:environment-variant-files","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"blocker:oauth-setup.md:136:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"blocker:oauth-setup.md:144:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"blocker:oauth-setup.md:311:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"blocker:oauth-setup.md:321:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"blocker:oauth-setup.md:324:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:quick-start.md:109:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"This is a documented, fixed npm setup command in Markdown guidance. It is not hidden shell execution and does not include user-controlled command construction.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","reason":"This is a documented, fixed npm setup command in Markdown guidance. It is not hidden shell execution and does not include user-controlled command construction.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:388:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:389:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"The match is Markdown inline code, a fenced example, or a TypeScript template literal in documentation. It does not execute shell commands from the skill runtime.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:24:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:47:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:48:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:228:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:357:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:397:hardcoded-url","reason":"The URL is an expected Bodhi OAuth endpoint, localhost callback, GitHub Pages example, or documentation link. It matches the integration purpose and shows no covert exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"blocker:SKILL.md:176:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:troubleshooting.md:413:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:troubleshooting.md:414:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:troubleshooting.md:417:environment-file-access","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:troubleshooting.md:413:environment-variant-files","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:troubleshooting.md:414:environment-variant-files","reason":"The text names example environment variant files with placeholder OAuth client IDs. It is documentation and does not read or exfiltrate secret files.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:troubleshooting.md:458:certificate-key-files","reason":"The snippet lists browser localStorage keys with a Bodhi prefix, not certificate or private key files. Token exposure from nearby auth-state logging is captured separately as a semantic finding.","verdict":"false_positive","confidence":0.88},{"id":"blocker:troubleshooting.md:120:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"blocker:troubleshooting.md:480:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9},{"id":"blocker:troubleshooting.md:482:system-reconnaissance","reason":"The snippet discusses OAuth client IDs, redirect URI errors, or token status for troubleshooting. It does not collect host data or perform system reconnaissance.","verdict":"false_positive","confidence":0.9}],"semantic_findings":[{"title":"OAuth Token Disclosure in Debug Examples","severity":"high","locations":[{"file":"troubleshooting.md","line_end":148,"line_start":137},{"file":"troubleshooting.md","line_end":443,"line_start":437},{"file":"troubleshooting.md","line_end":463,"line_start":454}],"confidence":0.88,"description":"Troubleshooting guidance logs full auth state and reads stored Bodhi auth state from localStorage. The same section shows auth state containing an access token, so shared console output could expose credentials.","confidence_reasoning":"The file explicitly logs the auth object and shows auth state with an accessToken field. Exploitation depends on users sharing logs or console output, so confidence is high but not absolute."}],"subject_marketplace_commit_sha":"5ab1d37e83436c6eef84de88573e142b94f2a4ad","subject_content_hash":"6590cf557f9aba8cec36262dae1acb711caf2a73834007ec03083489665b93c6","subject_tree_hash":"90de8502db0c51f0fd07c0e963a0cc2a69d12905604eb89c77cd19fb79d0d2db","subject_plugin_path":"skills/bodhisearch/bodhi-sdk-react-integration","audit_payload_hash":"678a4a4650576afdafd6eeb4d4d529a5","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"5ab1d37e83436c6eef84de88573e142b94f2a4ad","contentHash":"6590cf557f9aba8cec36262dae1acb711caf2a73834007ec03083489665b93c6","treeHash":"90de8502db0c51f0fd07c0e963a0cc2a69d12905604eb89c77cd19fb79d0d2db","pluginPath":"skills/bodhisearch/bodhi-sdk-react-integration","auditPayloadHash":"678a4a4650576afdafd6eeb4d4d529a5"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}