{"data":{"skill":{"slug":"browser-act-browser-act-skill-forge","name":"browser-act-skill-forge","icon":"📦","repo":"https://github.com/browser-act/skills/tree/main/browser-act-skill-forge","status":"approved","author":"browser-act","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"7777a1a0-460e-44a6-b53b-84ae15bf8956","skill_id":"9d70f22a-d950-4c57-8b35-68c116e6a35a","version":3,"content_hash":"c3b54473e2113cb43dd3e7120b2e1380","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"No prompt injection or clear credential exfiltration was found in the reviewed files. The skill is dual-use: it intentionally explores website internals, automates authenticated browser workflows, and generates local scripts. Most static hits are markdown examples, but shell command substitution and generated Python execution are real medium-risk surfaces.","remediation":[{"issue":"Generated skills rely on shell command substitution for Python-produced JavaScript.","severity":"medium","suggestion":"Use a safer browser-act execution path, quote parameters strictly, and reject inputs that can alter shell syntax."},{"issue":"The workflow encourages internal endpoint discovery and large-scale extraction from authenticated pages.","severity":"medium","suggestion":"Add explicit authorization checks, rate guidance, and policy reminders before extraction or batch execution."},{"issue":"Operation workflows can capture and reproduce state-changing requests.","severity":"medium","suggestion":"Require dry-run testing, user confirmation before live submission, and logs for POST, PUT, PATCH, or DELETE workflows."},{"issue":"Generated Python scripts are executed locally during verification.","severity":"medium","suggestion":"Constrain scripts to the documented template, disallow imports beyond the template, and review before execution."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"references/exploration_extraction.md","line_end":130,"line_start":130},{"file":"references/exploration_extraction.md","line_end":264,"line_start":264},{"file":"references/exploration_extraction.md","line_end":265,"line_start":265},{"file":"references/exploration_extraction.md","line_end":130,"line_start":130},{"file":"references/output_template.md","line_end":118,"line_start":118},{"file":"SKILL.md","line_end":254,"line_start":254},{"file":"SKILL.md","line_end":7,"line_start":7}]},{"factor":"external_commands","evidence":[{"file":"references/exploration_operation.md","line_end":113,"line_start":110},{"file":"references/output_template.md","line_end":61,"line_start":48},{"file":"references/output_template.md","line_end":75,"line_start":61},{"file":"references/output_template.md","line_end":75,"line_start":75},{"file":"references/output_template.md","line_end":81,"line_start":77},{"file":"references/output_template.md","line_end":88,"line_start":81},{"file":"references/output_template.md","line_end":106,"line_start":98},{"file":"references/output_template.md","line_end":119,"line_start":118},{"file":"references/output_template.md","line_end":120,"line_start":119},{"file":"references/output_template.md","line_end":121,"line_start":120},{"file":"references/output_template.md","line_end":123,"line_start":121},{"file":"references/output_template.md","line_end":128,"line_start":123},{"file":"references/output_template.md","line_end":143,"line_start":142},{"file":"references/output_template.md","line_end":144,"line_start":143},{"file":"references/output_template.md","line_end":146,"line_start":144},{"file":"references/output_template.md","line_end":151,"line_start":146},{"file":"references/output_template.md","line_end":163,"line_start":161},{"file":"references/output_template.md","line_end":166,"line_start":163},{"file":"references/output_template.md","line_end":177,"line_start":174},{"file":"references/output_template.md","line_end":181,"line_start":177},{"file":"references/output_template.md","line_end":183,"line_start":181},{"file":"references/output_template.md","line_end":191,"line_start":183},{"file":"references/output_template.md","line_end":191,"line_start":191},{"file":"references/output_template.md","line_end":198,"line_start":197},{"file":"references/output_template.md","line_end":198,"line_start":198},{"file":"references/output_template.md","line_end":200,"line_start":199},{"file":"references/output_template.md","line_end":200,"line_start":200},{"file":"references/output_template.md","line_end":224,"line_start":217},{"file":"references/output_template.md","line_end":234,"line_start":234},{"file":"references/output_template.md","line_end":235,"line_start":235},{"file":"references/output_template.md","line_end":237,"line_start":236},{"file":"references/output_template.md","line_end":237,"line_start":237},{"file":"references/output_template.md","line_end":241,"line_start":238},{"file":"references/output_template.md","line_end":255,"line_start":253},{"file":"references/output_template.md","line_end":267,"line_start":255},{"file":"references/output_template.md","line_end":267,"line_start":267},{"file":"references/output_template.md","line_end":269,"line_start":269},{"file":"references/output_template.md","line_end":271,"line_start":271},{"file":"references/output_template.md","line_end":273,"line_start":273},{"file":"references/output_template.md","line_end":280,"line_start":277},{"file":"references/output_template.md","line_end":281,"line_start":280},{"file":"references/output_template.md","line_end":282,"line_start":281},{"file":"references/output_template.md","line_end":283,"line_start":282},{"file":"references/output_template.md","line_end":301,"line_start":283},{"file":"references/output_template.md","line_end":306,"line_start":301},{"file":"references/output_template.md","line_end":309,"line_start":306},{"file":"references/output_template.md","line_end":75,"line_start":75},{"file":"references/output_template.md","line_end":81,"line_start":81},{"file":"references/output_template.md","line_end":98,"line_start":98},{"file":"references/output_template.md","line_end":163,"line_start":163},{"file":"references/output_template.md","line_end":174,"line_start":174},{"file":"references/output_template.md","line_end":183,"line_start":183},{"file":"references/output_template.md","line_end":217,"line_start":217},{"file":"references/output_template.md","line_end":234,"line_start":234},{"file":"references/output_template.md","line_end":237,"line_start":237},{"file":"references/output_template.md","line_end":253,"line_start":253},{"file":"references/output_template.md","line_end":255,"line_start":255},{"file":"references/output_template.md","line_end":75,"line_start":75},{"file":"references/output_template.md","line_end":81,"line_start":81},{"file":"references/output_template.md","line_end":98,"line_start":98},{"file":"references/output_template.md","line_end":163,"line_start":163},{"file":"references/output_template.md","line_end":174,"line_start":174},{"file":"references/output_template.md","line_end":183,"line_start":183},{"file":"references/output_template.md","line_end":217,"line_start":217},{"file":"references/output_template.md","line_end":234,"line_start":234},{"file":"references/output_template.md","line_end":237,"line_start":237},{"file":"references/output_template.md","line_end":253,"line_start":253},{"file":"references/output_template.md","line_end":255,"line_start":255},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":36,"line_start":28},{"file":"SKILL.md","line_end":51,"line_start":36},{"file":"SKILL.md","line_end":78,"line_start":51},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":89,"line_start":81},{"file":"SKILL.md","line_end":92,"line_start":89},{"file":"SKILL.md","line_end":99,"line_start":92},{"file":"SKILL.md","line_end":114,"line_start":99},{"file":"SKILL.md","line_end":115,"line_start":114},{"file":"SKILL.md","line_end":134,"line_start":115},{"file":"SKILL.md","line_end":140,"line_start":134},{"file":"SKILL.md","line_end":148,"line_start":140},{"file":"SKILL.md","line_end":148,"line_start":148},{"file":"SKILL.md","line_end":153,"line_start":149},{"file":"SKILL.md","line_end":155,"line_start":153},{"file":"SKILL.md","line_end":156,"line_start":155},{"file":"SKILL.md","line_end":157,"line_start":156},{"file":"SKILL.md","line_end":159,"line_start":157},{"file":"SKILL.md","line_end":163,"line_start":159},{"file":"SKILL.md","line_end":167,"line_start":163},{"file":"SKILL.md","line_end":172,"line_start":167},{"file":"SKILL.md","line_end":181,"line_start":172},{"file":"SKILL.md","line_end":181,"line_start":181},{"file":"SKILL.md","line_end":213,"line_start":197},{"file":"SKILL.md","line_end":248,"line_start":213},{"file":"SKILL.md","line_end":252,"line_start":248},{"file":"SKILL.md","line_end":252,"line_start":252},{"file":"SKILL.md","line_end":254,"line_start":253},{"file":"SKILL.md","line_end":254,"line_start":254},{"file":"SKILL.md","line_end":255,"line_start":255},{"file":"SKILL.md","line_end":261,"line_start":261},{"file":"SKILL.md","line_end":269,"line_start":265},{"file":"SKILL.md","line_end":271,"line_start":269},{"file":"SKILL.md","line_end":277,"line_start":271},{"file":"SKILL.md","line_end":277,"line_start":277},{"file":"SKILL.md","line_end":156,"line_start":156},{"file":"SKILL.md","line_end":156,"line_start":156}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":75,"line_start":75}],"confidence":0.86,"description":"> This Skill's operational boundary = what the user can manually do in their browser. It only reads ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":88,"line_start":81}],"confidence":0.86,"description":"`eval \"$(python scripts/{capability-name}.py '{param1}' --param2 {param2})\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":106,"line_start":98}],"confidence":0.86,"description":"`eval \"$(python scripts/{capability-name}.py '{param1}' --field1 '{value1}' --field2 '{value2}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":166,"line_start":163}],"confidence":0.86,"description":"Extract: `eval \"$(python scripts/{extraction-capability-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":177,"line_start":174}],"confidence":0.86,"description":"Pagination: `eval \"$(python scripts/{pagination-capability-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":191,"line_start":183}],"confidence":0.86,"description":"Fill and submit: `eval \"$(python scripts/{operation-capability-name}.py '{param1}' --field '{value}'","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":224,"line_start":217}],"confidence":0.86,"description":"`eval \"$(python scripts/{composite-capability-name}.py '{param1}' --param2 {param2})\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":234,"line_start":234}],"confidence":0.86,"description":"1. `navigate {page-A URL}` → `wait stable` → `eval \"$(python scripts/{capability-A}.py '{param}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":237,"line_start":237}],"confidence":0.86,"description":"a. `navigate {page-B URL pattern}` → `eval \"$(python scripts/{capability-B}.py '{item}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":255,"line_start":253}],"confidence":0.86,"description":"[API] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/output_template.md","line_end":267,"line_start":255}],"confidence":0.86,"description":"[DOM] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":75,"line_start":75}],"confidence":0.86,"description":"> This Skill's operational boundary = what the user can manually do in their browser. It only reads ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":81,"line_start":81}],"confidence":0.86,"description":"`eval \"$(python scripts/{capability-name}.py '{param1}' --param2 {param2})\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":98,"line_start":98}],"confidence":0.86,"description":"`eval \"$(python scripts/{capability-name}.py '{param1}' --field1 '{value1}' --field2 '{value2}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":163,"line_start":163}],"confidence":0.86,"description":"Extract: `eval \"$(python scripts/{extraction-capability-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":174,"line_start":174}],"confidence":0.86,"description":"Pagination: `eval \"$(python scripts/{pagination-capability-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":183,"line_start":183}],"confidence":0.86,"description":"Fill and submit: `eval \"$(python scripts/{operation-capability-name}.py '{param1}' --field '{value}'","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":217,"line_start":217}],"confidence":0.86,"description":"`eval \"$(python scripts/{composite-capability-name}.py '{param1}' --param2 {param2})\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":234,"line_start":234}],"confidence":0.86,"description":"1. `navigate {page-A URL}` → `wait stable` → `eval \"$(python scripts/{capability-A}.py '{param}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":237,"line_start":237}],"confidence":0.86,"description":"a. `navigate {page-B URL pattern}` → `eval \"$(python scripts/{capability-B}.py '{item}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":253,"line_start":253}],"confidence":0.86,"description":"[API] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"references/output_template.md","line_end":255,"line_start":255}],"confidence":0.86,"description":"[DOM] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":75,"line_start":75}],"confidence":0.86,"description":"> This Skill's operational boundary = what the user can manually do in their browser. It only reads ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":81,"line_start":81}],"confidence":0.86,"description":"`eval \"$(python scripts/{capability-name}.py '{param1}' --param2 {param2})\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":98,"line_start":98}],"confidence":0.86,"description":"`eval \"$(python scripts/{capability-name}.py '{param1}' --field1 '{value1}' --field2 '{value2}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":163,"line_start":163}],"confidence":0.86,"description":"Extract: `eval \"$(python scripts/{extraction-capability-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":174,"line_start":174}],"confidence":0.86,"description":"Pagination: `eval \"$(python scripts/{pagination-capability-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":183,"line_start":183}],"confidence":0.86,"description":"Fill and submit: `eval \"$(python scripts/{operation-capability-name}.py '{param1}' --field '{value}'","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":217,"line_start":217}],"confidence":0.86,"description":"`eval \"$(python scripts/{composite-capability-name}.py '{param1}' --param2 {param2})\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":234,"line_start":234}],"confidence":0.86,"description":"1. `navigate {page-A URL}` → `wait stable` → `eval \"$(python scripts/{capability-A}.py '{param}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":237,"line_start":237}],"confidence":0.86,"description":"a. `navigate {page-B URL pattern}` → `eval \"$(python scripts/{capability-B}.py '{item}')\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":253,"line_start":253}],"confidence":0.86,"description":"[API] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"references/output_template.md","line_end":255,"line_start":255}],"confidence":0.86,"description":"[DOM] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":156,"line_start":155}],"confidence":0.86,"description":"1. `python scripts/{feature-name}.py {test-params}` — confirm output is valid JS string","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":157,"line_start":156}],"confidence":0.86,"description":"2. `eval \"$(python scripts/{feature-name}.py {test-params})\"` — confirm browser execution result mat","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Shell command substitution","locations":[{"file":"SKILL.md","line_end":156,"line_start":156}],"confidence":0.86,"description":"2. `eval \"$(python scripts/{feature-name}.py {test-params})\"` — confirm browser execution result mat","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"Template literal with command substitution","locations":[{"file":"SKILL.md","line_end":156,"line_start":156}],"confidence":0.86,"description":"2. `eval \"$(python scripts/{feature-name}.py {test-params})\"` — confirm browser execution result mat","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe."},{"title":"System reconnaissance","locations":[{"file":"SKILL.md","line_end":155,"line_start":155}],"confidence":0.82,"description":"1. `python scripts/{feature-name}.py {test-params}` — confirm output is valid JS string","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line requires executing generated local Python wrappers during verification. Generated local code execution is a real risk when templates or parameters are unsafe."},{"title":"Authenticated Internal Endpoint Automation","locations":[{"file":"SKILL.md","line_end":18,"line_start":12},{"file":"SKILL.md","line_end":277,"line_start":273},{"file":"references/exploration_extraction.md","line_end":59,"line_start":43}],"confidence":0.9,"description":"The skill guides agents to explore frontend internal endpoints and automate extraction through a logged-in browser session. This is useful for authorized work, but it can enable large-scale scraping of third-party sites.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The stated purpose includes endpoint discovery, reusable extraction, and direct use of frontend internal endpoints in the user session."},{"title":"Generated Local Script Execution Surface","locations":[{"file":"SKILL.md","line_end":156,"line_start":142},{"file":"references/output_template.md","line_end":366,"line_start":315}],"confidence":0.86,"description":"The workflow creates Python wrappers that output browser JavaScript and then verifies them by running local commands. Unsafe generated code or unsanitized parameters could execute unexpected local or browser-side behavior.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The files explicitly describe generating scripts and executing them during verification, even though the intended scripts only print JavaScript."},{"title":"State-Changing Browser Operation Automation","locations":[{"file":"references/exploration_operation.md","line_end":63,"line_start":49},{"file":"references/exploration_operation.md","line_end":100,"line_start":77}],"confidence":0.88,"description":"The operation workflow captures form submission requests and can package direct API or DOM submission methods. This can automate authenticated state changes, so misuse could affect accounts or data.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The operation guide covers POST-like request capture, API submission strategy, and DOM submission fallback within authenticated workflows."}],"low_findings":[{"title":"Fetch API call","locations":[{"file":"references/exploration_extraction.md","line_end":130,"line_start":130}],"confidence":0.78,"description":"const res = await fetch('https://example.com/api/v1/items?page=1&limit=20');","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The documentation instructs agents to reproduce discovered target-site endpoints with browser-side fetch calls. This is intended network automation rather than credential exfiltration, but it is a real network capability."},{"title":"Fetch API call","locations":[{"file":"references/exploration_extraction.md","line_end":264,"line_start":264}],"confidence":0.78,"description":"const r1 = await (await fetch('{endpoint page 1}')).json();","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The documentation instructs agents to reproduce discovered target-site endpoints with browser-side fetch calls. This is intended network automation rather than credential exfiltration, but it is a real network capability."},{"title":"Fetch API call","locations":[{"file":"references/exploration_extraction.md","line_end":265,"line_start":265}],"confidence":0.78,"description":"const r2 = await (await fetch('{endpoint page 2}')).json();","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The documentation instructs agents to reproduce discovered target-site endpoints with browser-side fetch calls. This is intended network automation rather than credential exfiltration, but it is a real network capability."},{"title":"System reconnaissance","locations":[{"file":"references/exploration_extraction.md","line_end":321,"line_start":321}],"confidence":0.72,"description":"4. **Independent invocation not feasible** → Record as hybrid method: which prerequisites need to be","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"Network reconnaissance","locations":[{"file":"references/exploration_extraction.md","line_end":69,"line_start":68}],"confidence":0.72,"description":"- Parameter names are clear and parameterizable → Transparent, proceed to evaluate parameter complet","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"System reconnaissance","locations":[{"file":"references/exploration_operation.md","line_end":155,"line_start":155}],"confidence":0.72,"description":"> **Verification failure fallback**: HAR did not capture the expected request (framework not respond","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"System reconnaissance","locations":[{"file":"references/exploration_operation.md","line_end":196,"line_start":196}],"confidence":0.72,"description":"4. **Independent invocation not feasible** → Record as hybrid approach: what prerequisite dependenci","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"System reconnaissance","locations":[{"file":"SKILL.md","line_end":269,"line_start":269}],"confidence":0.72,"description":"**Control scan** (during enum collection): use one eval to return complete mapping of all target con","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."}],"dangerous_patterns":[{"title":"System reconnaissance","locations":[{"file":"references/exploration_extraction.md","line_end":321,"line_start":321}],"confidence":0.72,"description":"4. **Independent invocation not feasible** → Record as hybrid method: which prerequisites need to be","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"Network reconnaissance","locations":[{"file":"references/exploration_extraction.md","line_end":69,"line_start":68}],"confidence":0.72,"description":"- Parameter names are clear and parameterizable → Transparent, proceed to evaluate parameter complet","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"System reconnaissance","locations":[{"file":"references/exploration_operation.md","line_end":155,"line_start":155}],"confidence":0.72,"description":"> **Verification failure fallback**: HAR did not capture the expected request (framework not respond","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"System reconnaissance","locations":[{"file":"references/exploration_operation.md","line_end":196,"line_start":196}],"confidence":0.72,"description":"4. **Independent invocation not feasible** → Record as hybrid approach: what prerequisite dependenci","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."},{"title":"System reconnaissance","locations":[{"file":"SKILL.md","line_end":155,"line_start":155}],"confidence":0.82,"description":"1. `python scripts/{feature-name}.py {test-params}` — confirm output is valid JS string","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line requires executing generated local Python wrappers during verification. Generated local code execution is a real risk when templates or parameters are unsafe."},{"title":"System reconnaissance","locations":[{"file":"SKILL.md","line_end":269,"line_start":269}],"confidence":0.72,"description":"**Control scan** (during enum collection): use one eval to return complete mapping of all target con","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning."}],"files_scanned":4,"total_lines":1219,"audit_model":"codex","audited_at":"2026-07-05T04:12:41.621+00:00","created_at":"2026-07-05T05:47:57.04867+00:00","static_findings":[{"id":"network:references/exploration_extraction.md:130:fetch-api-call","file":"references/exploration_extraction.md","pattern":"Fetch API call","snippet":"const res = await fetch('https://example.com/api/v1/items?page=1&limit=20');","category":"network","line_end":130,"severity":"low","line_start":130},{"id":"network:references/exploration_extraction.md:264:fetch-api-call","file":"references/exploration_extraction.md","pattern":"Fetch API call","snippet":"const r1 = await (await fetch('{endpoint page 1}')).json();","category":"network","line_end":264,"severity":"low","line_start":264},{"id":"network:references/exploration_extraction.md:265:fetch-api-call","file":"references/exploration_extraction.md","pattern":"Fetch API call","snippet":"const r2 = await (await fetch('{endpoint page 2}')).json();","category":"network","line_end":265,"severity":"low","line_start":265},{"id":"network:references/exploration_extraction.md:130:hardcoded-url","file":"references/exploration_extraction.md","pattern":"Hardcoded URL","snippet":"const res = await fetch('https://example.com/api/v1/items?page=1&limit=20');","category":"network","line_end":130,"severity":"low","line_start":130},{"id":"blocker:references/exploration_extraction.md:321:system-reconnaissance","file":"references/exploration_extraction.md","pattern":"System reconnaissance","snippet":"4. **Independent invocation not feasible** → Record as hybrid method: which prerequisites need to be","category":"blocker","line_end":321,"severity":"low","line_start":321},{"id":"blocker:references/exploration_extraction.md:68:network-reconnaissance","file":"references/exploration_extraction.md","pattern":"Network reconnaissance","snippet":"- Parameter names are clear and parameterizable → Transparent, proceed to evaluate parameter complet","category":"blocker","line_end":69,"severity":"low","line_start":68},{"id":"external_commands:references/exploration_operation.md:110:ruby-shell-backtick-execution","file":"references/exploration_operation.md","pattern":"Ruby/shell backtick execution","snippet":"const el = document.querySelector(`[name=\"${f}\"], [id=\"${f}\"]`);","category":"external_commands","line_end":113,"severity":"medium","line_start":110},{"id":"blocker:references/exploration_operation.md:155:system-reconnaissance","file":"references/exploration_operation.md","pattern":"System reconnaissance","snippet":"> **Verification failure fallback**: HAR did not capture the expected request (framework not respond","category":"blocker","line_end":155,"severity":"low","line_start":155},{"id":"blocker:references/exploration_operation.md:196:system-reconnaissance","file":"references/exploration_operation.md","pattern":"System reconnaissance","snippet":"4. **Independent invocation not feasible** → Record as hybrid approach: what prerequisite dependenci","category":"blocker","line_end":196,"severity":"low","line_start":196},{"id":"external_commands:references/output_template.md:48:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"- Target page is already open in the browser: `{full URL of the target page}`","category":"external_commands","line_end":61,"severity":"medium","line_start":48},{"id":"external_commands:references/output_template.md:61:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Invoke `browser-act` via Skill tool to load usage. If installation or configuration issues arise, fo","category":"external_commands","line_end":75,"severity":"medium","line_start":61},{"id":"external_commands:references/output_template.md:75:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"> This Skill's operational boundary = what the user can manually do in their browser. It only reads ","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:references/output_template.md:77:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Below are all atomic capabilities discovered and verified during the exploration phase, listed by co","category":"external_commands","line_end":81,"severity":"medium","line_start":77},{"id":"external_commands:references/output_template.md:81:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"`eval \"$(python scripts/{capability-name}.py '{param1}' --param2 {param2})\"`","category":"external_commands","line_end":88,"severity":"medium","line_start":81},{"id":"external_commands:references/output_template.md:98:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"`eval \"$(python scripts/{capability-name}.py '{param1}' --field1 '{value1}' --field2 '{value2}')\"`","category":"external_commands","line_end":106,"severity":"medium","line_start":98},{"id":"external_commands:references/output_template.md:118:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"1. `navigate {URL pattern, e.g., https://example.com/search?q={keyword}&page={page}}`","category":"external_commands","line_end":119,"severity":"medium","line_start":118},{"id":"external_commands:references/output_template.md:119:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"2. `wait stable`","category":"external_commands","line_end":120,"severity":"medium","line_start":119},{"id":"external_commands:references/output_template.md:120:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"3. `network requests --type xhr,fetch --filter {endpoint keyword}`","category":"external_commands","line_end":121,"severity":"medium","line_start":120},{"id":"external_commands:references/output_template.md:121:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"4. `network request <id>`","category":"external_commands","line_end":123,"severity":"medium","line_start":121},{"id":"external_commands:references/output_template.md:123:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Endpoint characteristic: URL contains `{characteristic path, e.g., /api/search}`","category":"external_commands","line_end":128,"severity":"medium","line_start":123},{"id":"external_commands:references/output_template.md:142:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"3. `wait stable`","category":"external_commands","line_end":143,"severity":"medium","line_start":142},{"id":"external_commands:references/output_template.md:143:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"4. `network requests --type xhr,fetch --filter {endpoint keyword}`","category":"external_commands","line_end":144,"severity":"medium","line_start":143},{"id":"external_commands:references/output_template.md:144:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"5. `network request <id>`","category":"external_commands","line_end":146,"severity":"medium","line_start":144},{"id":"external_commands:references/output_template.md:146:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Endpoint characteristic: URL contains `{characteristic path}`","category":"external_commands","line_end":151,"severity":"medium","line_start":146},{"id":"external_commands:references/output_template.md:161:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"<!-- Assembly guidance: If the target data is asynchronously injected (browser extensions, lazy load","category":"external_commands","line_end":163,"severity":"medium","line_start":161},{"id":"external_commands:references/output_template.md:163:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Extract: `eval \"$(python scripts/{extraction-capability-name}.py)\"`","category":"external_commands","line_end":166,"severity":"medium","line_start":163},{"id":"external_commands:references/output_template.md:174:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Pagination: `eval \"$(python scripts/{pagination-capability-name}.py)\"`","category":"external_commands","line_end":177,"severity":"medium","line_start":174},{"id":"external_commands:references/output_template.md:177:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"`screenshot` confirm page change → re-run extraction script","category":"external_commands","line_end":181,"severity":"medium","line_start":177},{"id":"external_commands:references/output_template.md:181:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"<!-- Assembly guidance: If form controls are asynchronously rendered (component libraries, extension","category":"external_commands","line_end":183,"severity":"medium","line_start":181},{"id":"external_commands:references/output_template.md:183:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Fill and submit: `eval \"$(python scripts/{operation-capability-name}.py '{param1}' --field '{value}'","category":"external_commands","line_end":191,"severity":"medium","line_start":183},{"id":"external_commands:references/output_template.md:191:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"→ `state` get element index then `click <index>`","category":"external_commands","line_end":191,"severity":"medium","line_start":191},{"id":"external_commands:references/output_template.md:197:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"1. `navigate {url}` → page loaded, title is \"{expected-title}\"","category":"external_commands","line_end":198,"severity":"medium","line_start":197},{"id":"external_commands:references/output_template.md:198:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"2. `state` locate {visual description, e.g., \"product card area with price labels in the middle of t","category":"external_commands","line_end":198,"severity":"medium","line_start":198},{"id":"external_commands:references/output_template.md:199:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"3. `scroll down` → wait for more products to load (checkpoint: new products appear)","category":"external_commands","line_end":200,"severity":"medium","line_start":199},{"id":"external_commands:references/output_template.md:200:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"4. `get markdown` extract `{field-list}` from returned content","category":"external_commands","line_end":200,"severity":"medium","line_start":200},{"id":"external_commands:references/output_template.md:217:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"`eval \"$(python scripts/{composite-capability-name}.py '{param1}' --param2 {param2})\"`","category":"external_commands","line_end":224,"severity":"medium","line_start":217},{"id":"external_commands:references/output_template.md:234:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"1. `navigate {page-A URL}` → `wait stable` → `eval \"$(python scripts/{capability-A}.py '{param}')\"`","category":"external_commands","line_end":234,"severity":"medium","line_start":234},{"id":"external_commands:references/output_template.md:235:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"2. `network requests --filter {keyword}` → `network request <id>`","category":"external_commands","line_end":235,"severity":"medium","line_start":235},{"id":"external_commands:references/output_template.md:236:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"3. For each `{item}` from step 1/2:","category":"external_commands","line_end":237,"severity":"medium","line_start":236},{"id":"external_commands:references/output_template.md:237:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"a. `navigate {page-B URL pattern}` → `eval \"$(python scripts/{capability-B}.py '{item}')\"`","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:references/output_template.md:238:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"4. Merge: associate by `{association-field}`","category":"external_commands","line_end":241,"severity":"medium","line_start":238},{"id":"external_commands:references/output_template.md:253:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"[API] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","category":"external_commands","line_end":255,"severity":"medium","line_start":253},{"id":"external_commands:references/output_template.md:255:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"[DOM] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","category":"external_commands","line_end":267,"severity":"medium","line_start":255},{"id":"external_commands:references/output_template.md:267:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"**API Pagination**: `{pagination-param-name}`, type: `{page-number / cursor}`, start value: `{start-","category":"external_commands","line_end":267,"severity":"medium","line_start":267},{"id":"external_commands:references/output_template.md:269:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"**URL Pagination**: URL pattern `{URL pattern}`, next page link selector: `{selector}`. Termination:","category":"external_commands","line_end":269,"severity":"medium","line_start":269},{"id":"external_commands:references/output_template.md:271:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"**DOM Pagination**: Click \"{control description}\" (`{selector}`), wait for loading then re-extract. ","category":"external_commands","line_end":271,"severity":"medium","line_start":271},{"id":"external_commands:references/output_template.md:273:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"**AI Pagination**: Pagination driven by Agent visual operations. Each page: `screenshot` judge statu","category":"external_commands","line_end":273,"severity":"medium","line_start":273},{"id":"external_commands:references/output_template.md:277:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"`{quantifiable condition expression; purely descriptive criteria are prohibited}`","category":"external_commands","line_end":280,"severity":"medium","line_start":277},{"id":"external_commands:references/output_template.md:280:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"- Data count: `result count >= 1`","category":"external_commands","line_end":281,"severity":"medium","line_start":280},{"id":"external_commands:references/output_template.md:281:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"- Field completeness: `core field non-null rate = 100%`","category":"external_commands","line_end":282,"severity":"medium","line_start":281},{"id":"external_commands:references/output_template.md:282:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"- Data consistency: `matches the first N items displayed on the page`","category":"external_commands","line_end":283,"severity":"medium","line_start":282},{"id":"external_commands:references/output_template.md:283:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"- Operation result: `response status 200 with no error field`","category":"external_commands","line_end":301,"severity":"medium","line_start":283},{"id":"external_commands:references/output_template.md:301:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"Path: `{working-directory}/browser-act-skill-forge-memories/{skill-name}-{site-slug}-{capability-slu","category":"external_commands","line_end":306,"severity":"medium","line_start":301},{"id":"external_commands:references/output_template.md:306:ruby-shell-backtick-execution","file":"references/output_template.md","pattern":"Ruby/shell backtick execution","snippet":"`{YYYY-MM-DD}: {what happened} → {conclusion}`","category":"external_commands","line_end":309,"severity":"medium","line_start":306},{"id":"external_commands:references/output_template.md:75:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"> This Skill's operational boundary = what the user can manually do in their browser. It only reads ","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:references/output_template.md:81:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"`eval \"$(python scripts/{capability-name}.py '{param1}' --param2 {param2})\"`","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:references/output_template.md:98:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"`eval \"$(python scripts/{capability-name}.py '{param1}' --field1 '{value1}' --field2 '{value2}')\"`","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:references/output_template.md:163:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"Extract: `eval \"$(python scripts/{extraction-capability-name}.py)\"`","category":"external_commands","line_end":163,"severity":"medium","line_start":163},{"id":"external_commands:references/output_template.md:174:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"Pagination: `eval \"$(python scripts/{pagination-capability-name}.py)\"`","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:references/output_template.md:183:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"Fill and submit: `eval \"$(python scripts/{operation-capability-name}.py '{param1}' --field '{value}'","category":"external_commands","line_end":183,"severity":"medium","line_start":183},{"id":"external_commands:references/output_template.md:217:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"`eval \"$(python scripts/{composite-capability-name}.py '{param1}' --param2 {param2})\"`","category":"external_commands","line_end":217,"severity":"medium","line_start":217},{"id":"external_commands:references/output_template.md:234:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"1. `navigate {page-A URL}` → `wait stable` → `eval \"$(python scripts/{capability-A}.py '{param}')\"`","category":"external_commands","line_end":234,"severity":"medium","line_start":234},{"id":"external_commands:references/output_template.md:237:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"a. `navigate {page-B URL pattern}` → `eval \"$(python scripts/{capability-B}.py '{item}')\"`","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:references/output_template.md:253:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"[API] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","category":"external_commands","line_end":253,"severity":"medium","line_start":253},{"id":"external_commands:references/output_template.md:255:shell-command-substitution","file":"references/output_template.md","pattern":"Shell command substitution","snippet":"[DOM] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","category":"external_commands","line_end":255,"severity":"medium","line_start":255},{"id":"external_commands:references/output_template.md:75:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"> This Skill's operational boundary = what the user can manually do in their browser. It only reads ","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:references/output_template.md:81:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"`eval \"$(python scripts/{capability-name}.py '{param1}' --param2 {param2})\"`","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:references/output_template.md:98:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"`eval \"$(python scripts/{capability-name}.py '{param1}' --field1 '{value1}' --field2 '{value2}')\"`","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:references/output_template.md:163:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"Extract: `eval \"$(python scripts/{extraction-capability-name}.py)\"`","category":"external_commands","line_end":163,"severity":"medium","line_start":163},{"id":"external_commands:references/output_template.md:174:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"Pagination: `eval \"$(python scripts/{pagination-capability-name}.py)\"`","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:references/output_template.md:183:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"Fill and submit: `eval \"$(python scripts/{operation-capability-name}.py '{param1}' --field '{value}'","category":"external_commands","line_end":183,"severity":"medium","line_start":183},{"id":"external_commands:references/output_template.md:217:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"`eval \"$(python scripts/{composite-capability-name}.py '{param1}' --param2 {param2})\"`","category":"external_commands","line_end":217,"severity":"medium","line_start":217},{"id":"external_commands:references/output_template.md:234:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"1. `navigate {page-A URL}` → `wait stable` → `eval \"$(python scripts/{capability-A}.py '{param}')\"`","category":"external_commands","line_end":234,"severity":"medium","line_start":234},{"id":"external_commands:references/output_template.md:237:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"a. `navigate {page-B URL pattern}` → `eval \"$(python scripts/{capability-B}.py '{item}')\"`","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:references/output_template.md:253:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"[API] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","category":"external_commands","line_end":253,"severity":"medium","line_start":253},{"id":"external_commands:references/output_template.md:255:template-literal-with-command-substitution","file":"references/output_template.md","pattern":"Template literal with command substitution","snippet":"[DOM] {param-name} — `eval \"$(python scripts/enum_{param-name}.py)\"`","category":"external_commands","line_end":255,"severity":"medium","line_start":255},{"id":"network:references/output_template.md:118:hardcoded-url","file":"references/output_template.md","pattern":"Hardcoded URL","snippet":"1. `navigate {URL pattern, e.g., https://example.com/search?q={keyword}&page={page}}`","category":"network","line_end":118,"severity":"low","line_start":118},{"id":"blocker:references/output_template.md:294:system-reconnaissance","file":"references/output_template.md","pattern":"System reconnaissance","snippet":"- **Reduce redundant pre-operations**: When multiple steps depend on the same prerequisite state, co","category":"blocker","line_end":294,"severity":"low","line_start":294},{"id":"blocker:references/output_template.md:354:system-reconnaissance","file":"references/output_template.md","pattern":"System reconnaissance","snippet":"2. **Code must be runnable**: JS strings in `scripts/*.py` must be executable directly in the browse","category":"blocker","line_end":354,"severity":"low","line_start":354},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":36,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Invoke `browser-act` via Skill tool to load usage. If installation or configuration issues arise dur","category":"external_commands","line_end":51,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Output directory**: defaults to `output/` under current working directory, overridden if user sp","category":"external_commands","line_end":78,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Set `skill-name` and capability directory names (lowercase English, hyphen-separated), create dir","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":89,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":92,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":99,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":114,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Extraction** → `references/exploration_extraction.md`","category":"external_commands","line_end":115,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Operation** → `references/exploration_operation.md`","category":"external_commands","line_end":134,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Don't touch experience notes**: experience notes (`browser-act-skill-forge-memories/`) are for gen","category":"external_commands","line_end":140,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read `references/output_template.md` for file format specification.","category":"external_commands","line_end":148,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Escape JS curly braces as `{{` `}}` (f-string syntax requirement, otherwise Python errors)","category":"external_commands","line_end":148,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Write to `scripts/{feature-name}.py`","category":"external_commands","line_end":153,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run end-to-end verification for each `.py` file:","category":"external_commands","line_end":155,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `python scripts/{feature-name}.py {test-params}` — confirm output is valid JS string","category":"external_commands","line_end":156,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `eval \"$(python scripts/{feature-name}.py {test-params})\"` — confirm browser execution result mat","category":"external_commands","line_end":157,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Simulate error scenarios (e.g., non-existent ID, navigating to wrong page), confirm returns `{\"er","category":"external_commands","line_end":159,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Verification failure → fix `.py` file and retry, never skip.","category":"external_commands","line_end":163,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create SKILL.md per template, capability component section references `scripts/*.py` invocation comm","category":"external_commands","line_end":167,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":172,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":181,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Output**: Read generated `scripts/*.py` and `SKILL.md`, check against the Filling Specification","category":"external_commands","line_end":181,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":213,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":248,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All intermediate artifacts (HAR files, temp records, debug output) go in the `tmp/` directory. Creat","category":"external_commands","line_end":252,"severity":"medium","line_start":248},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Wait for network stability before reading traffic**: whether triggered by page navigation or UI ","category":"external_commands","line_end":252,"severity":"medium","line_start":252},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Wait for elements before operating on async DOM**: for async-injected content (browser extension","category":"external_commands","line_end":254,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **No JS-level network interception**: never override `XMLHttpRequest.prototype`, `window.fetch`, e","category":"external_commands","line_end":254,"severity":"medium","line_start":254},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`network clear` only before navigation/reload**: clearing traffic loses all observed request rec","category":"external_commands","line_end":255,"severity":"medium","line_start":255},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Selector priority**: `data-testid > id > name > aria-label > structural path`. Avoid pure position","category":"external_commands","line_end":261,"severity":"medium","line_start":261},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Shadow DOM**: when target element is inside a Shadow Root, access via `element.shadowRoot.querySel","category":"external_commands","line_end":269,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Control scan** (during enum collection): use one eval to return complete mapping of all target con","category":"external_commands","line_end":271,"severity":"medium","line_start":269},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**state index dynamic allocation**: `state` returns element indexes that are dynamically allocated p","category":"external_commands","line_end":277,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Framework internal state fast-fail**: when attempting to access page data or element info through ","category":"external_commands","line_end":277,"severity":"medium","line_start":277},{"id":"external_commands:SKILL.md:156:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"2. `eval \"$(python scripts/{feature-name}.py {test-params})\"` — confirm browser execution result mat","category":"external_commands","line_end":156,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:156:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"2. `eval \"$(python scripts/{feature-name}.py {test-params})\"` — confirm browser execution result mat","category":"external_commands","line_end":156,"severity":"medium","line_start":156},{"id":"network:SKILL.md:254:xmlhttprequest","file":"SKILL.md","pattern":"XMLHttpRequest","snippet":"- **No JS-level network interception**: never override `XMLHttpRequest.prototype`, `window.fetch`, e","category":"network","line_end":254,"severity":"low","line_start":254},{"id":"network:SKILL.md:7:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://www.browseract.com\"","category":"network","line_end":7,"severity":"low","line_start":7},{"id":"blocker:SKILL.md:155:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"1. `python scripts/{feature-name}.py {test-params}` — confirm output is valid JS string","category":"blocker","line_end":155,"severity":"low","line_start":155},{"id":"blocker:SKILL.md:261:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Selector priority**: `data-testid > id > name > aria-label > structural path`. Avoid pure position","category":"blocker","line_end":261,"severity":"low","line_start":261},{"id":"blocker:SKILL.md:269:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Control scan** (during enum collection): use one eval to return complete mapping of all target con","category":"blocker","line_end":269,"severity":"low","line_start":269},{"id":"blocker:SKILL.md:285:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Account permission limits ≠ technical solution failure. Paid features, membership tiers, etc. equall","category":"blocker","line_end":285,"severity":"low","line_start":285},{"id":"blocker:SKILL.md:297:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| **Output volume control** | Extract key fields (count, total, sample) from large responses inside ","category":"blocker","line_end":297,"severity":"low","line_start":297},{"id":"blocker:SKILL.md:300:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| **Fetch once, analyze many** | Fetch data from same source only once, save then analyze multiple t","category":"blocker","line_end":300,"severity":"low","line_start":300}],"finding_verdicts":[{"id":"network:references/exploration_extraction.md:130:fetch-api-call","reason":"The documentation instructs agents to reproduce discovered target-site endpoints with browser-side fetch calls. This is intended network automation rather than credential exfiltration, but it is a real network capability.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:references/exploration_extraction.md:264:fetch-api-call","reason":"The documentation instructs agents to reproduce discovered target-site endpoints with browser-side fetch calls. This is intended network automation rather than credential exfiltration, but it is a real network capability.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:references/exploration_extraction.md:265:fetch-api-call","reason":"The documentation instructs agents to reproduce discovered target-site endpoints with browser-side fetch calls. This is intended network automation rather than credential exfiltration, but it is a real network capability.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:references/exploration_extraction.md:130:hardcoded-url","reason":"The URL is either project metadata or an example placeholder in documentation. It is not an exfiltration endpoint or executable request target.","verdict":"false_positive","confidence":0.93},{"id":"blocker:references/exploration_extraction.md:321:system-reconnaissance","reason":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning.","verdict":"confirmed","severity":"low","confidence":0.72},{"id":"blocker:references/exploration_extraction.md:68:network-reconnaissance","reason":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning.","verdict":"confirmed","severity":"low","confidence":0.72},{"id":"external_commands:references/exploration_operation.md:110:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"blocker:references/exploration_operation.md:155:system-reconnaissance","reason":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning.","verdict":"confirmed","severity":"low","confidence":0.72},{"id":"blocker:references/exploration_operation.md:196:system-reconnaissance","reason":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning.","verdict":"confirmed","severity":"low","confidence":0.72},{"id":"external_commands:references/output_template.md:48:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:61:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:75:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:77:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:81:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:98:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:118:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:119:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:120:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:121:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:123:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:142:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:143:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:144:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:146:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:161:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:163:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:174:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:177:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:181:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:183:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:191:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:197:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:198:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:199:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:200:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:217:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:234:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:235:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:236:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:237:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:238:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:253:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:255:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:267:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:269:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:271:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:273:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:277:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:280:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:281:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:282:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:283:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:301:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:306:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:references/output_template.md:75:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:81:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:98:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:163:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:174:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:183:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:217:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:234:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:237:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:253:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:255:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:75:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:81:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:98:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:163:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:174:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:183:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:217:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:234:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:237:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:253:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:references/output_template.md:255:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"network:references/output_template.md:118:hardcoded-url","reason":"The URL is either project metadata or an example placeholder in documentation. It is not an exfiltration endpoint or executable request target.","verdict":"false_positive","confidence":0.93},{"id":"blocker:references/output_template.md:294:system-reconnaissance","reason":"The hit describes browser-page analysis, selectors, efficiency guidance, or limitations. It does not scan the host system or bypass access controls.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/output_template.md:354:system-reconnaissance","reason":"The hit describes browser-page analysis, selectors, efficiency guidance, or limitations. It does not scan the host system or bypass access controls.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","reason":"The hit is markdown, a browser-act subcommand example, a file path, or JavaScript syntax. It is not local shell execution at this location.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:156:shell-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"external_commands:SKILL.md:156:template-literal-with-command-substitution","reason":"This line instructs agents to run generated Python scripts through shell command substitution before browser execution. That creates a real local execution surface if generated scripts or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"network:SKILL.md:254:xmlhttprequest","reason":"The line is a safety rule that says not to override XMLHttpRequest or window.fetch. It does not perform interception or make a network request.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:7:hardcoded-url","reason":"The URL is either project metadata or an example placeholder in documentation. It is not an exfiltration endpoint or executable request target.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:155:system-reconnaissance","reason":"The line requires executing generated local Python wrappers during verification. Generated local code execution is a real risk when templates or parameters are unsafe.","verdict":"confirmed","severity":"medium","confidence":0.82},{"id":"blocker:SKILL.md:261:system-reconnaissance","reason":"The hit describes browser-page analysis, selectors, efficiency guidance, or limitations. It does not scan the host system or bypass access controls.","verdict":"false_positive","confidence":0.84},{"id":"blocker:SKILL.md:269:system-reconnaissance","reason":"The line is part of the skill workflow for discovering target-site endpoints, request prerequisites, or browser controls. This is web-application reconnaissance within the user session, not host-system scanning.","verdict":"confirmed","severity":"low","confidence":0.72},{"id":"blocker:SKILL.md:285:system-reconnaissance","reason":"The hit describes browser-page analysis, selectors, efficiency guidance, or limitations. It does not scan the host system or bypass access controls.","verdict":"false_positive","confidence":0.84},{"id":"blocker:SKILL.md:297:system-reconnaissance","reason":"The hit describes browser-page analysis, selectors, efficiency guidance, or limitations. It does not scan the host system or bypass access controls.","verdict":"false_positive","confidence":0.84},{"id":"blocker:SKILL.md:300:system-reconnaissance","reason":"The hit describes browser-page analysis, selectors, efficiency guidance, or limitations. It does not scan the host system or bypass access controls.","verdict":"false_positive","confidence":0.84}],"semantic_findings":[{"title":"Authenticated Internal Endpoint Automation","severity":"medium","locations":[{"file":"SKILL.md","line_end":18,"line_start":12},{"file":"SKILL.md","line_end":277,"line_start":273},{"file":"references/exploration_extraction.md","line_end":59,"line_start":43}],"confidence":0.9,"description":"The skill guides agents to explore frontend internal endpoints and automate extraction through a logged-in browser session. This is useful for authorized work, but it can enable large-scale scraping of third-party sites.","confidence_reasoning":"The stated purpose includes endpoint discovery, reusable extraction, and direct use of frontend internal endpoints in the user session."},{"title":"Generated Local Script Execution Surface","severity":"medium","locations":[{"file":"SKILL.md","line_end":156,"line_start":142},{"file":"references/output_template.md","line_end":366,"line_start":315}],"confidence":0.86,"description":"The workflow creates Python wrappers that output browser JavaScript and then verifies them by running local commands. Unsafe generated code or unsanitized parameters could execute unexpected local or browser-side behavior.","confidence_reasoning":"The files explicitly describe generating scripts and executing them during verification, even though the intended scripts only print JavaScript."},{"title":"State-Changing Browser Operation Automation","severity":"medium","locations":[{"file":"references/exploration_operation.md","line_end":63,"line_start":49},{"file":"references/exploration_operation.md","line_end":100,"line_start":77}],"confidence":0.88,"description":"The operation workflow captures form submission requests and can package direct API or DOM submission methods. This can automate authenticated state changes, so misuse could affect accounts or data.","confidence_reasoning":"The operation guide covers POST-like request capture, API submission strategy, and DOM submission fallback within authenticated workflows."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":9,"capabilityReviewCount":40,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}