{"data":{"skill":{"slug":"caffeinelabs-extension-authorization","name":"extension-authorization","icon":"📦","repo":"https://github.com/caffeinelabs/skills/tree/main/skills/extension-authorization/","status":"approved","author":"caffeinelabs","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"396efc5d-a15b-442c-a25a-c46e6289fd42","skill_id":"f09db2a3-896d-40fc-bd42-9a3de479e946","version":1,"content_hash":"v2:48c90b0b69b40692aeeed7f047470c7ead884454:8b7395d7a2a1adecc774de9e58bd8b23fea40276bd2bef9c9dc8bd7b6d0f3c13:c43699c3b03fc1ffeb3ee5c6d46f27da437cec0725aa0e3221095cb0bea992eb:56e104f18457abb0f290bb019e2a95bc","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"The static findings are false positives caused by Markdown formatting, documentation links, relative imports, and identity terminology. Semantic review found a high-risk first-admin bootstrap pattern because the first authenticated user becomes admin without a token or preconfigured owner. No prompt injection attempt was found.","remediation":[{"issue":"First authenticated user becomes administrator without proof of ownership.","severity":"high","suggestion":"Require a deployer-controlled owner principal, one-time setup secret, or explicit setup step before assigning the first admin role."},{"issue":"Public access before admin bootstrap can create an account takeover window.","severity":"medium","suggestion":"Document a safe deployment sequence and block privileged endpoints until the intended owner completes setup."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"migration/v0.x.y-to-v1.x.y.md","line_end":5,"line_start":5},{"file":"migration/v0.x.y-to-v1.x.y.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":95,"line_start":95}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":44,"line_start":28},{"file":"SKILL.md","line_end":46,"line_start":44},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":74,"line_start":58},{"file":"SKILL.md","line_end":78,"line_start":74},{"file":"SKILL.md","line_end":84,"line_start":78},{"file":"SKILL.md","line_end":88,"line_start":84},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":122,"line_start":90},{"file":"SKILL.md","line_end":128,"line_start":122},{"file":"SKILL.md","line_end":140,"line_start":128},{"file":"SKILL.md","line_end":145,"line_start":140},{"file":"SKILL.md","line_end":146,"line_start":145},{"file":"SKILL.md","line_end":147,"line_start":146},{"file":"SKILL.md","line_end":149,"line_start":147},{"file":"SKILL.md","line_end":153,"line_start":149},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":155,"line_start":155},{"file":"SKILL.md","line_end":160,"line_start":157},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":165,"line_start":163},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":194,"line_start":169},{"file":"SKILL.md","line_end":196,"line_start":194},{"file":"SKILL.md","line_end":196,"line_start":196},{"file":"SKILL.md","line_end":208,"line_start":202},{"file":"SKILL.md","line_end":219,"line_start":208},{"file":"SKILL.md","line_end":219,"line_start":219},{"file":"SKILL.md","line_end":221,"line_start":220},{"file":"SKILL.md","line_end":231,"line_start":221},{"file":"SKILL.md","line_end":251,"line_start":231},{"file":"SKILL.md","line_end":254,"line_start":251},{"file":"SKILL.md","line_end":256,"line_start":254},{"file":"SKILL.md","line_end":260,"line_start":256},{"file":"SKILL.md","line_end":262,"line_start":260},{"file":"SKILL.md","line_end":262,"line_start":262},{"file":"SKILL.md","line_end":264,"line_start":264},{"file":"SKILL.md","line_end":265,"line_start":265},{"file":"SKILL.md","line_end":266,"line_start":266},{"file":"SKILL.md","line_end":267,"line_start":267},{"file":"SKILL.md","line_end":268,"line_start":268},{"file":"SKILL.md","line_end":269,"line_start":269},{"file":"SKILL.md","line_end":271,"line_start":271},{"file":"SKILL.md","line_end":274,"line_start":274},{"file":"SKILL.md","line_end":279,"line_start":275},{"file":"SKILL.md","line_end":300,"line_start":279},{"file":"SKILL.md","line_end":310,"line_start":304},{"file":"SKILL.md","line_end":312,"line_start":310},{"file":"SKILL.md","line_end":312,"line_start":312},{"file":"SKILL.md","line_end":315,"line_start":314},{"file":"SKILL.md","line_end":321,"line_start":315},{"file":"SKILL.md","line_end":325,"line_start":321},{"file":"SKILL.md","line_end":335,"line_start":325},{"file":"SKILL.md","line_end":343,"line_start":335},{"file":"SKILL.md","line_end":345,"line_start":343}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":14,"line_start":14}]}],"critical_findings":[],"high_findings":[{"title":"Unauthenticated First-Admin Bootstrap","locations":[{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":345,"line_start":345}],"confidence":0.88,"description":"The skill states that the first authenticated user automatically becomes admin and no token or secret is required. A public deployment could be taken over by any early user before the intended owner logs in.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The same bootstrap behavior is documented twice with no secret, token, or fixed owner principal. The risk depends on deployment timing, but the takeover path is clear."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":401,"audit_model":"codex","audited_at":"2026-07-07T12:42:53.147+00:00","created_at":"2026-07-07T13:04:38.632682+00:00","static_findings":[{"id":"filesystem:migration/v0.x.y-to-v1.x.y.md:5:path-traversal-sequence","file":"migration/v0.x.y-to-v1.x.y.md","pattern":"Path traversal sequence","snippet":"v1 updates the `caffeineai-authorization` mops package to `1.0.0` and adds support for Internet Iden","category":"filesystem","line_end":5,"severity":"high","line_start":5},{"id":"filesystem:migration/v0.x.y-to-v1.x.y.md:42:path-traversal-sequence","file":"migration/v0.x.y-to-v1.x.y.md","pattern":"Path traversal sequence","snippet":"To capture the verified email at sign-in, pass a callback instead of `null` — see the **Email Attrib","category":"filesystem","line_end":42,"severity":"high","line_start":42},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"This skill adds an authentication and authorization system with role-based access control using the ","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"There is a prefabricated library `mo:caffeineai-authorization/access-control.mo`. It provides core a","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```mo:caffeineai-authorization/access-control.mo","category":"external_commands","line_end":44,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":46,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Initialization is handled internally by `MixinAuthorization` -- do not call `initialize` directly. T","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"IMPORTANT: The `include MixinAuthorization(accessControlState)` line MUST be placed in `main.mo`, no","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the user asks to replace this authorization system with custom authentication (for example userna","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When removing the package, also remove all `mo:caffeineai-authorization/*` imports, the `accessContr","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```motoko filepath=src/backend/main.mo","category":"external_commands","line_end":74,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":78,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```motoko filepath=src/backend/types.mo","category":"external_commands","line_end":84,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":88,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The frontend requires `getCallerUserProfile`, `saveCallerUserProfile`, and `getUserProfile`. Pass `a","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```motoko filepath=src/backend/mixins/Profile.mo","category":"external_commands","line_end":122,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":128,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":140,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":145,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assignRole` includes an admin-only guard internally.","category":"external_commands","line_end":146,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `shared({ caller })` for authenticated endpoints that modify data.","category":"external_commands","line_end":147,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `query({ caller })` for authenticated endpoints that fetch data.","category":"external_commands","line_end":149,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `Runtime.trap` for authorization failures.","category":"external_commands","line_end":153,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`MixinAuthorization` can capture the user's verified Internet Identity attributes (name and email) a","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Do NOT use the `mo:identity-attributes` mixin directly -- always go through `MixinAuthorization`. Th","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":160,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"email : ?Text;  // always the verified address -- sourced from II's `verified_email`, never the unve","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":165,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The field is named `email`, but it only ever holds II's `verified_email` value -- the unverified `em","category":"external_commands","line_end":165,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":194,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":196,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The `trusted_attribute_signers` and `frontend_origins` canister environment variables required for a","category":"external_commands","line_end":196,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":208,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":219,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `getCallerUserProfile(): Promise<UserProfile | null>` -- returns `null` if no profile exists","category":"external_commands","line_end":219,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `saveCallerUserProfile(profile: UserProfile): Promise<void>` -- saves name and profile data","category":"external_commands","line_end":221,"severity":"medium","line_start":220},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `getUserProfile(user: Principal): Promise<UserProfile | null>` -- fetch another user's profile","category":"external_commands","line_end":231,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":251,"severity":"medium","line_start":231},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":254,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":256,"severity":"medium","line_start":254},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":260,"severity":"medium","line_start":256},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The `useInternetIdentity` hook exposes two kinds of state — use the right one:","category":"external_commands","line_end":262,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Scenario | `loginStatus` | `isAuthenticated` |","category":"external_commands","line_end":262,"severity":"medium","line_start":262},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Page load, no stored session | `\"idle\"` | `false` |","category":"external_commands","line_end":264,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Page load, restoring stored session | `\"initializing\"` | `false` → `true` |","category":"external_commands","line_end":265,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Stored session restored after reload | `\"idle\"` | `true` |","category":"external_commands","line_end":266,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Interactive login in progress (popup open) | `\"logging-in\"` | `false` |","category":"external_commands","line_end":267,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Interactive login just completed | `\"success\"` | `true` |","category":"external_commands","line_end":268,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Login popup failed / cancelled | `\"loginError\"` | `false` |","category":"external_commands","line_end":269,"severity":"medium","line_start":269},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**IMPORTANT:** `isLoginSuccess` (`loginStatus === \"success\"`) is only `true` after an interactive lo","category":"external_commands","line_end":271,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `isInitializing` — `AuthClient` is loading from IndexedDB; disable the button to prevent clicks be","category":"external_commands","line_end":274,"severity":"medium","line_start":274},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `isLoggingIn` — the II popup is open; disable the button to prevent duplicate popups.","category":"external_commands","line_end":279,"severity":"medium","line_start":275},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":300,"severity":"medium","line_start":279},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"} disabled:opacity-50`}","category":"external_commands","line_end":310,"severity":"medium","line_start":304},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":312,"severity":"medium","line_start":310},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The `login()` and `clear()` functions are fire-and-forget (they don't return promises that track the","category":"external_commands","line_end":312,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Gate authenticated UI on `isAuthenticated` (covers both fresh login and restored sessions on page re","category":"external_commands","line_end":315,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":321,"severity":"medium","line_start":315},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":325,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":335,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":343,"severity":"medium","line_start":335},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Handle authorization errors from backend `Debug.trap` calls gracefully in the UI with appropriate er","category":"external_commands","line_end":345,"severity":"medium","line_start":343},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Authorization extendsion for [Caffeine AI](https://caffeine.ai?utm_source=caffeine-skill&utm_medium=","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"filesystem:SKILL.md:95:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"import Types \"../types\";","category":"filesystem","line_end":95,"severity":"high","line_start":95},{"id":"blocker:SKILL.md:216:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"When using Internet Identity, the user gets a principal id only after login. Anonymous principals ar","category":"blocker","line_end":216,"severity":"low","line_start":216},{"id":"blocker:SKILL.md:225:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Display the user's profile name instead of the principal id","category":"blocker","line_end":226,"severity":"low","line_start":225},{"id":"blocker:SKILL.md:160:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"email : ?Text;  // always the verified address -- sourced from II's `verified_email`, never the unve","category":"blocker","line_end":160,"severity":"low","line_start":160}],"finding_verdicts":[{"id":"filesystem:migration/v0.x.y-to-v1.x.y.md:5:path-traversal-sequence","reason":"The traversal-like sequence appears only in a Markdown documentation link to another migration or section. It is not executable code and does not access the filesystem.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:migration/v0.x.y-to-v1.x.y.md:42:path-traversal-sequence","reason":"The traversal-like sequence appears only in a Markdown documentation link to another migration or section. It is not executable code and does not access the filesystem.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown inline code, fenced Motoko examples, fenced TypeScript examples, or a TypeScript template literal. They do not invoke Ruby shell backticks or execute commands.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL is a documentation hyperlink to the Caffeine AI website. The skill does not make a runtime network request or transmit data to that URL.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:95:path-traversal-sequence","reason":"The ../types string is a Motoko import inside a documented project example. It is a normal relative module import, not untrusted filesystem traversal.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:216:system-reconnaissance","reason":"The text explains Internet Identity principal handling in application UI. It does not collect host details, enumerate the system, or perform reconnaissance.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:225:system-reconnaissance","reason":"The text explains Internet Identity principal handling in application UI. It does not collect host details, enumerate the system, or perform reconnaissance.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:160:network-reconnaissance","reason":"The text describes a verified email attribute returned by Internet Identity. It does not probe networks, enumerate services, or gather infrastructure data.","verdict":"false_positive","confidence":0.9}],"semantic_findings":[{"title":"Unauthenticated First-Admin Bootstrap","severity":"high","locations":[{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":345,"line_start":345}],"confidence":0.88,"description":"The skill states that the first authenticated user automatically becomes admin and no token or secret is required. A public deployment could be taken over by any early user before the intended owner logs in.","confidence_reasoning":"The same bootstrap behavior is documented twice with no secret, token, or fixed owner principal. The risk depends on deployment timing, but the takeover path is clear."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}