{"data":{"skill":{"slug":"cagdasyurekli-agy-worker","name":"agy-worker","icon":"📦","repo":"https://github.com/cagdasyurekli/codex-agy-worker/tree/3da9a50afaa66492dd77f23f92c6ed4f84be4ada/skills/agy-worker","status":"approved","author":"cagdasyurekli","authorVersion":"0.17.0","skillstoreRevision":5},"audit":{"id":"98e566d2-2e3c-4b37-8de4-b2c3a6d231ed","skill_id":"466f2750-44a5-4d4f-8709-a2494454b27b","version":5,"content_hash":"v3:e5464e662405de6361fdde6b984f9ea865635f64:3d138378c67980113003cc9307c51d1b54cf24091ed95b0b2ee7d88174247bee:ae8aee1e8340badcb3d529ebcf1a879dc8cebb6f4145f9acdf9a97d4ce8fab83:736b696c6c732f636167646173797572656b6c692f6167792d776f726b6572:62a79c7608d1f13565f15b5e2679599b","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 400 presented static findings were adjudicated individually. Most matches are benign validation, documentation, schema, or bounded orchestration patterns, but account configuration access and legacy shell verification are confirmed risks. The skill also explicitly allows provider execution with normal filesystem and network authority in session mode, so operators must treat it as a delegation tool rather than a sandbox. Static review was capped at 400/962 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.","remediation":[{"issue":"Static review capped","severity":"medium","suggestion":"Manually review the omitted 562 static analyzer matches or reduce bundled generated/vendor/reference content before enabling automatic publication."},{"issue":"Default session mode retains normal user filesystem and network authority for the provider.","severity":"critical","suggestion":"Prefer scoped transmission and native containment where supported, and require explicit approval that names the provider, execution mode, readable content, and destination."},{"issue":"Approved worktree content can include secrets, credentials, private keys, or unrelated private files.","severity":"high","suggestion":"Run a secret and private-path scan before every launch, exclude sensitive entries from the approved scope, and fail closed when the scan is inconclusive."},{"issue":"Legacy verifier mode executes caller-supplied text through /bin/bash -c.","severity":"high","suggestion":"Disable legacy shell verification by default and require a separate high-risk acknowledgement, or accept only canonical argv records with an executable allowlist."},{"issue":"Compatibility manifests reference external CLI distribution URLs.","severity":"high","suggestion":"Pin each download to an immutable digest, verify signatures or checksums before execution, and review manifest changes as supply-chain updates."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"README.md","line_end":56,"line_start":56},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":39,"line_start":39},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":48,"line_start":48},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":49,"line_start":49},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":50,"line_start":50},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":212,"line_start":212},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":213,"line_start":213},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":244,"line_start":244},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":247,"line_start":245},{"file":"runtime/agy-worker.sh","line_end":14,"line_start":14},{"file":"runtime/agy-worker.sh","line_end":15,"line_start":15},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":1262},{"file":"runtime/agy-worker.sh","line_end":1263,"line_start":1263},{"file":"runtime/agy-worker.sh","line_end":1300,"line_start":1300},{"file":"runtime/agy-worker.sh","line_end":25,"line_start":25},{"file":"runtime/agy-worker.sh","line_end":30,"line_start":30},{"file":"runtime/agy-worker.sh","line_end":237,"line_start":237},{"file":"runtime/agy-worker.sh","line_end":464,"line_start":464},{"file":"runtime/agy-worker.sh","line_end":475,"line_start":473},{"file":"runtime/agy-worker.sh","line_end":497,"line_start":497},{"file":"runtime/agy-worker.sh","line_end":498,"line_start":498},{"file":"runtime/agy-worker.sh","line_end":499,"line_start":499},{"file":"runtime/agy-worker.sh","line_end":603,"line_start":603},{"file":"runtime/agy-worker.sh","line_end":604,"line_start":604},{"file":"runtime/agy-worker.sh","line_end":649,"line_start":649},{"file":"runtime/agy-worker.sh","line_end":650,"line_start":650},{"file":"runtime/agy-worker.sh","line_end":651,"line_start":651},{"file":"runtime/agy-worker.sh","line_end":652,"line_start":652},{"file":"runtime/agy-worker.sh","line_end":663,"line_start":663},{"file":"runtime/agy-worker.sh","line_end":685,"line_start":685},{"file":"runtime/agy-worker.sh","line_end":690,"line_start":690},{"file":"runtime/agy-worker.sh","line_end":692,"line_start":692},{"file":"runtime/agy-worker.sh","line_end":696,"line_start":696},{"file":"runtime/agy-worker.sh","line_end":725,"line_start":720},{"file":"runtime/agy-worker.sh","line_end":906,"line_start":901},{"file":"runtime/agy-worker.sh","line_end":980,"line_start":980},{"file":"runtime/agy-worker.sh","line_end":1011,"line_start":1009},{"file":"runtime/agy-worker.sh","line_end":1054,"line_start":1043},{"file":"runtime/agy-worker.sh","line_end":1225,"line_start":1225},{"file":"runtime/agy-worker.sh","line_end":1226,"line_start":1226},{"file":"runtime/agy-worker.sh","line_end":1306,"line_start":1306},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":15},{"file":"runtime/benchmark.sh","line_end":5,"line_start":5},{"file":"runtime/codex-usage-report.sh","line_end":5,"line_start":5},{"file":"runtime/delegation-policy.sh","line_end":5,"line_start":5},{"file":"runtime/doctor.sh","line_end":21,"line_start":21},{"file":"runtime/doctor.sh","line_end":32,"line_start":32},{"file":"runtime/doctor.sh","line_end":38,"line_start":37},{"file":"runtime/doctor.sh","line_end":86,"line_start":85},{"file":"runtime/doctor.sh","line_end":147,"line_start":146}]},{"factor":"filesystem","evidence":[{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":49,"line_start":49},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":50,"line_start":50},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":212,"line_start":212},{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":177,"line_start":177},{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":42,"line_start":42},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":1262},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":1262},{"file":"runtime/agy-worker.sh","line_end":237,"line_start":237},{"file":"runtime/agy-worker.sh","line_end":663,"line_start":663},{"file":"runtime/agy-worker.sh","line_end":673,"line_start":673},{"file":"runtime/agy-worker.sh","line_end":685,"line_start":685},{"file":"runtime/agy-worker.sh","line_end":897,"line_start":897},{"file":"runtime/agy-worker.sh","line_end":1011,"line_start":1011},{"file":"runtime/agy-worker.sh","line_end":1030,"line_start":1030},{"file":"runtime/agy-worker.sh","line_end":1200,"line_start":1200},{"file":"runtime/agy-worker.sh","line_end":1201,"line_start":1201},{"file":"runtime/agy-worker.sh","line_end":939,"line_start":939},{"file":"runtime/doctor.sh","line_end":21,"line_start":21},{"file":"runtime/doctor.sh","line_end":24,"line_start":24},{"file":"runtime/doctor.sh","line_end":32,"line_start":32},{"file":"runtime/doctor.sh","line_end":38,"line_start":38},{"file":"runtime/doctor.sh","line_end":86,"line_start":86},{"file":"runtime/doctor.sh","line_end":147,"line_start":147},{"file":"runtime/doctor.sh","line_end":156,"line_start":156},{"file":"runtime/doctor.sh","line_end":157,"line_start":157},{"file":"runtime/doctor.sh","line_end":172,"line_start":172},{"file":"runtime/doctor.sh","line_end":198,"line_start":198},{"file":"runtime/doctor.sh","line_end":199,"line_start":199},{"file":"runtime/doctor.sh","line_end":225,"line_start":225},{"file":"runtime/doctor.sh","line_end":230,"line_start":230},{"file":"runtime/doctor.sh","line_end":231,"line_start":231},{"file":"runtime/doctor.sh","line_end":237,"line_start":237},{"file":"runtime/doctor.sh","line_end":252,"line_start":252},{"file":"runtime/doctor.sh","line_end":253,"line_start":253},{"file":"runtime/doctor.sh","line_end":301,"line_start":301},{"file":"runtime/doctor.sh","line_end":302,"line_start":302},{"file":"runtime/doctor.sh","line_end":304,"line_start":304},{"file":"runtime/doctor.sh","line_end":315,"line_start":315},{"file":"runtime/doctor.sh","line_end":322,"line_start":322},{"file":"runtime/doctor.sh","line_end":468,"line_start":468},{"file":"runtime/doctor.sh","line_end":470,"line_start":470},{"file":"runtime/doctor.sh","line_end":478,"line_start":478},{"file":"runtime/doctor.sh","line_end":479,"line_start":479},{"file":"runtime/doctor.sh","line_end":493,"line_start":493},{"file":"runtime/doctor.sh","line_end":506,"line_start":506},{"file":"runtime/doctor.sh","line_end":527,"line_start":527},{"file":"runtime/doctor.sh","line_end":543,"line_start":543},{"file":"runtime/doctor.sh","line_end":563,"line_start":563},{"file":"runtime/doctor.sh","line_end":579,"line_start":579},{"file":"runtime/doctor.sh","line_end":224,"line_start":224}]},{"factor":"scripts","evidence":[{"file":"runtime/agy-worker.sh","line_end":1430,"line_start":1430},{"file":"runtime/agy-worker.sh","line_end":1431,"line_start":1431},{"file":"runtime/agy-worker.sh","line_end":1443,"line_start":1443},{"file":"runtime/agy-worker.sh","line_end":1446,"line_start":1446},{"file":"runtime/agy-worker.sh","line_end":1457,"line_start":1457},{"file":"runtime/agy-worker.sh","line_end":1478,"line_start":1478},{"file":"runtime/scripts/agy_dispatch_containment.py","line_end":378,"line_start":377},{"file":"runtime/scripts/agy_dispatch_worktree.py","line_end":674,"line_start":674},{"file":"runtime/scripts/agy_dispatch_worktree.py","line_end":4215,"line_start":4215},{"file":"runtime/scripts/agy_dispatch.py","line_end":2887,"line_start":2887},{"file":"runtime/scripts/agy_dispatch.py","line_end":46,"line_start":46},{"file":"runtime/scripts/agy_dispatch.py","line_end":3157,"line_start":3157},{"file":"runtime/scripts/benchmark.py","line_end":96,"line_start":88},{"file":"runtime/scripts/benchmark.py","line_end":100,"line_start":97},{"file":"runtime/scripts/evidence_receipt.py","line_end":37,"line_start":29},{"file":"runtime/scripts/evidence_receipt.py","line_end":41,"line_start":38},{"file":"runtime/scripts/evidence_report.py","line_end":34,"line_start":25},{"file":"runtime/scripts/evidence_report.py","line_end":38,"line_start":35},{"file":"runtime/scripts/job_lifecycle.py","line_end":38,"line_start":35},{"file":"runtime/scripts/job_lifecycle.py","line_end":44,"line_start":39},{"file":"runtime/scripts/job_lifecycle.py","line_end":54,"line_start":45},{"file":"runtime/scripts/model-recommendation.py","line_end":18,"line_start":12}]},{"factor":"network","evidence":[{"file":"runtime/compat/agy-version-manifest.json","line_end":20,"line_start":20},{"file":"runtime/compat/agy-version-manifest.json","line_end":65,"line_start":65},{"file":"runtime/compat/agy-version-manifest.json","line_end":85,"line_start":85},{"file":"runtime/compat/agy-version-manifest.json","line_end":111,"line_start":111},{"file":"runtime/compat/agy-version-manifest.json","line_end":159,"line_start":159},{"file":"runtime/compat/model-effort-matrix.schema.json","line_end":2,"line_start":2},{"file":"runtime/compat/model-effort-matrix.schema.json","line_end":3,"line_start":3},{"file":"runtime/compat/version-manifest.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/benchmark-plan.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/benchmark-result.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/delegation-policy.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/evidence-receipt.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/job-state.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-advisory-preview.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-advisory-summary.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-aggregate.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-evaluation.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-plan.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-record.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-record.schema.json","line_end":156,"line_start":156},{"file":"runtime/schemas/model-intelligence-advisory.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-intelligence-evidence.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-intelligence-evidence.schema.json","line_end":85,"line_start":85},{"file":"runtime/schemas/model-recommendation.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-selection.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/swebench-workflow-study-advisory.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/swebench-workflow-study-report.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/worker-result.provider.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/worker-result.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/workflow-state.schema.json","line_end":2,"line_start":2},{"file":"runtime/scripts/codex_usage_report.py","line_end":726,"line_start":726},{"file":"runtime/scripts/compatibility.py","line_end":245,"line_start":245},{"file":"runtime/scripts/compatibility.py","line_end":246,"line_start":246},{"file":"runtime/scripts/feedback-triage.py","line_end":31,"line_start":31},{"file":"runtime/scripts/model_evidence_campaign.py","line_end":28,"line_start":28},{"file":"runtime/scripts/model_intelligence.py","line_end":26,"line_start":26}]},{"factor":"env_access","evidence":[{"file":"runtime/qa-gate.sh","line_end":120,"line_start":120},{"file":"runtime/scripts/agy_dispatch_verification.py","line_end":151,"line_start":151},{"file":"runtime/scripts/agy_dispatch_worktree.py","line_end":1379,"line_start":1379},{"file":"runtime/scripts/evidence_receipt.py","line_end":1115,"line_start":1115},{"file":"runtime/scripts/evidence_receipt.py","line_end":1117,"line_start":1117},{"file":"runtime/scripts/evidence_receipt.py","line_end":1521,"line_start":1521},{"file":"runtime/scripts/evidence_receipt.py","line_end":955,"line_start":955},{"file":"runtime/scripts/feedback-triage.py","line_end":360,"line_start":360},{"file":"runtime/scripts/model_selection.py","line_end":98,"line_start":98},{"file":"runtime/scripts/workflow.py","line_end":711,"line_start":711},{"file":"runtime/scripts/workflow.py","line_end":718,"line_start":718},{"file":"runtime/scripts/workflow.py","line_end":750,"line_start":750},{"file":"runtime/scripts/workflow.py","line_end":1115,"line_start":1115},{"file":"runtime/scripts/workflow.py","line_end":1186,"line_start":1186},{"file":"runtime/scripts/workflow.py","line_end":1598,"line_start":1598}]}],"critical_findings":[],"high_findings":[{"title":"Hidden file in home directory","locations":[{"file":"runtime/ground-truth.sh","line_end":63,"line_start":63}],"confidence":0.94,"description":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The account phase reads ~/.gemini/antigravity-cli/settings.json and reports its permission configuration. This is an intentional account inspection, but it accesses user-owned configuration outside the worktree."},{"title":"Hidden file access","locations":[{"file":"runtime/ground-truth.sh","line_end":63,"line_start":63}],"confidence":0.94,"description":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The account phase reads ~/.gemini/antigravity-cli/settings.json and reports its permission configuration. This is an intentional account inspection, but it accesses user-owned configuration outside the worktree."},{"title":"Unix shell invocation","locations":[{"file":"runtime/qa-gate.sh","line_end":623,"line_start":623}],"confidence":0.98,"description":"/bin/bash -c \"${verify_specs[$i]}\"","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The legacy shell verifier executes verify_specs through /bin/bash -c. An untrusted verifier specification can therefore run arbitrary commands, even though this mode is explicitly selected by the driver."},{"title":"Unix shell invocation","locations":[{"file":"runtime/qa-gate.sh","line_end":639,"line_start":639}],"confidence":0.98,"description":"/bin/bash -c \"${verify_specs[$i]}\"","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The legacy shell verifier executes verify_specs through /bin/bash -c. An untrusted verifier specification can therefore run arbitrary commands, even though this mode is explicitly selected by the driver."},{"title":"Unconfined Provider Execution","locations":[{"file":"SKILL.md","line_end":51,"line_start":49}],"confidence":0.99,"description":"The skill states that whole-worktree content may be transmitted to Google or Gemini and that session mode gives AGY normal user filesystem and network authority. A provider task can therefore affect or disclose resources beyond the intended worktree unless the operator uses scoped content and stronger containment.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The documented execution boundary explicitly says the entire worktree may be readable and transmissible, while session mode has no AGY sandbox or native host containment."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":92,"total_lines":37454,"audit_model":"codex","audited_at":"2026-09-06T12:11:18.935+00:00","created_at":"2026-09-08T15:01:53.045852+00:00","static_findings":[{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2581:certificate-key-files","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Certificate/key files","snippet":"if set(value.keys()) != {\"schema_version\", \"kind\", \"read\", \"write\"}:","category":"sensitive","line_end":2581,"severity":"high","line_start":2581},{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2597:certificate-key-files","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Certificate/key files","snippet":"if set(entry.keys()) != {\"path\", \"kind\"}:","category":"sensitive","line_end":2597,"severity":"high","line_start":2597},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:430:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(plan.keys()) != allowed_keys:","category":"sensitive","line_end":430,"severity":"high","line_start":430},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:457:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(anchors, dict) or set(anchors.keys()) != {","category":"sensitive","line_end":457,"severity":"high","line_start":457},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:470:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(trigger, dict) or set(trigger.keys()) != {","category":"sensitive","line_end":470,"severity":"high","line_start":470},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:489:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(obj, dict) or set(obj.keys()) != {\"id\", \"version\"}:","category":"sensitive","line_end":489,"severity":"high","line_start":489},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:501:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(mw, dict) or set(mw.keys()) != {\"start_date\", \"end_date\"}:","category":"sensitive","line_end":501,"severity":"high","line_start":501},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:510:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(ar, dict) or not {\"min_sample_size\", \"min_coverage\", \"max_error_rate\", \"uncertaint","category":"sensitive","line_end":510,"severity":"high","line_start":510},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:512:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(ar.keys()) - {\"min_sample_size\", \"min_coverage\", \"max_error_rate\", \"min_quality_score\", \"unce","category":"sensitive","line_end":512,"severity":"high","line_start":512},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:524:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(ur, dict) or set(ur.keys()) != {\"max_uncertainty\"}:","category":"sensitive","line_end":524,"severity":"high","line_start":524},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:530:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(budget, dict) or set(budget.keys()) != {\"sample_budget\", \"invocation_budget\"}:","category":"sensitive","line_end":530,"severity":"high","line_start":530},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:539:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(dt, dict) or set(dt.keys()) != {\"max_drift_fraction\"}:","category":"sensitive","line_end":539,"severity":"high","line_start":539},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:546:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(rt, dict) or set(rt.keys()) != {\"bindings\", \"min_coverage\"}:","category":"sensitive","line_end":546,"severity":"high","line_start":546},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:587:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(record.keys()) != allowed_keys:","category":"sensitive","line_end":587,"severity":"high","line_start":587},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:607:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"for k in record.keys():","category":"sensitive","line_end":607,"severity":"high","line_start":607},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:613:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(mid, dict) or set(mid.keys()) != {\"requested_model\", \"observed_model\", \"substitute","category":"sensitive","line_end":613,"severity":"high","line_start":613},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:628:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(obj, dict) or set(obj.keys()) != {\"id\", \"version\"}:","category":"sensitive","line_end":628,"severity":"high","line_start":628},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:667:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(mw, dict) or set(mw.keys()) != {\"start_date\", \"end_date\"}:","category":"sensitive","line_end":667,"severity":"high","line_start":667},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:695:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(telem.keys()) != allowed_telem_keys:","category":"sensitive","line_end":695,"severity":"high","line_start":695},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:729:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(metrics.keys()) - allowed_metric_keys:","category":"sensitive","line_end":729,"severity":"high","line_start":729},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:784:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(eval_dict.keys()) != allowed_keys:","category":"sensitive","line_end":784,"severity":"high","line_start":784},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:832:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(facts.keys()) != allowed_facts:","category":"sensitive","line_end":832,"severity":"high","line_start":832},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:930:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(agg.keys()) != expected_keys:","category":"sensitive","line_end":930,"severity":"high","line_start":930},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:939:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(by_lane, dict) or set(by_lane.keys()) != {\"vendor_declared\", \"measured\", \"observat","category":"sensitive","line_end":939,"severity":"high","line_start":939},{"id":"sensitive:references/SECURITY_AND_COMPATIBILITY.md:26:crypto-seed-private-key-mention","file":"references/SECURITY_AND_COMPATIBILITY.md","pattern":"Crypto seed/private key mention","snippet":"boundary before launch. Credentials, private keys, user-denied paths, unrelated private files,","category":"sensitive","line_end":26,"severity":"high","line_start":26},{"id":"sensitive:SKILL.md:53:crypto-seed-private-key-mention","file":"SKILL.md","pattern":"Crypto seed/private key mention","snippet":"Before each launch, ensure secrets, credentials, private keys, user-denied paths, and unrelated priv","category":"sensitive","line_end":53,"severity":"high","line_start":53},{"id":"obfuscation:runtime/benchmarks/v1/portable-source.json:1:heuristic-extremely-long-line-2076-chars-likely-","file":"runtime/benchmarks/v1/portable-source.json","pattern":"[HEURISTIC] Extremely long line (2076 chars) - likely obfuscated","snippet":"{\"files\":[{\"mode\":\"100755\",\"path\":\"benchmark.sh\",\"sha256\":\"7e0033f6bf3eec1e6007752ef67e8e33db8f39c71","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-advisory.schema.json:1:heuristic-extremely-long-line-2424-chars-likely-","file":"runtime/schemas/swebench-workflow-study-advisory.schema.json","pattern":"[HEURISTIC] Extremely long line (2424 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"app","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-plan.schema.json:1:heuristic-extremely-long-line-2929-chars-likely-","file":"runtime/schemas/swebench-workflow-study-plan.schema.json","pattern":"[HEURISTIC] Extremely long line (2929 chars) - likely obfuscated","snippet":"{\"additionalProperties\":false,\"properties\":{\"aggregation\":{\"enum\":[\"input-plus-output-no-overlap-v1\"","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/benchmark-result.schema.json:1:heuristic-extremely-long-line-3160-chars-likely-","file":"runtime/schemas/benchmark-result.schema.json","pattern":"[HEURISTIC] Extremely long line (3160 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"com","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-report.schema.json:1:heuristic-extremely-long-line-6721-chars-likely-","file":"runtime/schemas/swebench-workflow-study-report.schema.json","pattern":"[HEURISTIC] Extremely long line (6721 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"den","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/benchmark-plan.schema.json:1:heuristic-extremely-long-line-7848-chars-likely-","file":"runtime/schemas/benchmark-plan.schema.json","pattern":"[HEURISTIC] Extremely long line (7848 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"exp","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:1:heuristic-multiple-bracket-chains-20-jsfuck-obfu","file":"runtime/schemas/model-evidence-campaign-advisory-summary.schema.json","pattern":"[HEURISTIC] Multiple bracket chains (20) - JSFuck/obfuscation pattern","snippet":"}}}]}, }}}]}, }}}]}","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/model-selection.schema.json:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","file":"runtime/schemas/model-selection.schema.json","pattern":"[HEURISTIC] Multiple bracket chains (6) - JSFuck/obfuscation pattern","snippet":"]}}}}, ]}}}}, ]}]}","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"[HEURISTIC] Multiple bracket chains (6) - JSFuck/obfuscation pattern","snippet":")))), ())), ()))","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/scripts/evidence_report.py:131:heuristic-very-high-entropy-string-6-02-bits-lik","file":"runtime/scripts/evidence_report.py","pattern":"[HEURISTIC] Very high entropy string (6.02 bits) - likely encoded/encrypted payload","snippet":"abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789._-","category":"obfuscation","line_end":131,"severity":"high","line_start":131},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2563:hex-encoded-characters","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Hex-encoded characters","snippet":"if \"\\x00\" in text:","category":"obfuscation","line_end":2563,"severity":"high","line_start":2563},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2605:hex-encoded-characters","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Hex-encoded characters","snippet":"if \"\\x00\" in path or \"\\r\" in path or \"\\n\" in path:","category":"obfuscation","line_end":2605,"severity":"high","line_start":2605},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:723:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"not isinstance(item, str) or \"\\x00\" in item for item in value[\"argv\"]","category":"obfuscation","line_end":723,"severity":"high","line_start":723},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:1361:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"or any(ch in summary for ch in \"\\x00\\r\\n\")","category":"obfuscation","line_end":1361,"severity":"high","line_start":1361},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2581:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"if not isinstance(reported, str) or not reported or \"\\x00\" in reported:","category":"obfuscation","line_end":2581,"severity":"high","line_start":2581},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2702:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"item in summary for item in (\"\\x00\", \"\\r\", \"\\n\")","category":"obfuscation","line_end":2702,"severity":"high","line_start":2702},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2709:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"or any(control in item for control in (\"\\x00\", \"\\r\", \"\\n\"))","category":"obfuscation","line_end":2709,"severity":"high","line_start":2709},{"id":"obfuscation:runtime/scripts/compatibility.py:174:hex-encoded-characters","file":"runtime/scripts/compatibility.py","pattern":"Hex-encoded characters","snippet":"if not raw or \"\\x00\" in raw:","category":"obfuscation","line_end":174,"severity":"high","line_start":174},{"id":"obfuscation:runtime/scripts/evidence_report.py:145:hex-encoded-characters","file":"runtime/scripts/evidence_report.py","pattern":"Hex-encoded characters","snippet":"if \"\\r\" in text or \"\\x00\" in text or text.startswith(\"::\") or \"\\n::\" in text:","category":"obfuscation","line_end":145,"severity":"high","line_start":145},{"id":"obfuscation:runtime/scripts/job_lifecycle.py:392:hex-encoded-characters","file":"runtime/scripts/job_lifecycle.py","pattern":"Hex-encoded characters","snippet":"if not isinstance(value[key], str) or not value[key] or \"\\x00\" in value[key]:","category":"obfuscation","line_end":392,"severity":"high","line_start":392},{"id":"obfuscation:runtime/scripts/model_selection.py:625:hex-encoded-characters","file":"runtime/scripts/model_selection.py","pattern":"Hex-encoded characters","snippet":"if not raw.endswith(b\"\\n\") or raw.count(b\"\\n\") != 1 or b\"\\x00\" in raw:","category":"obfuscation","line_end":625,"severity":"high","line_start":625},{"id":"obfuscation:runtime/scripts/model_selection.py:640:hex-encoded-characters","file":"runtime/scripts/model_selection.py","pattern":"Hex-encoded characters","snippet":"if b\"\\x00\" in raw:","category":"obfuscation","line_end":640,"severity":"high","line_start":640},{"id":"obfuscation:runtime/scripts/swebench_workflow_study.py:58:hex-encoded-characters","file":"runtime/scripts/swebench_workflow_study.py","pattern":"Hex-encoded characters","snippet":"r\"Users/|/home/|\\\\|[\\r\\n\\x00-\\x1f])\"","category":"obfuscation","line_end":58,"severity":"high","line_start":58},{"id":"env_access:runtime/qa-gate.sh:120:database-connection-strings","file":"runtime/qa-gate.sh","pattern":"Database connection strings","snippet":"|| \"$1\" == GH_PAT || \"$1\" == DATABASE_URL \\","category":"env_access","line_end":120,"severity":"high","line_start":120},{"id":"env_access:runtime/scripts/evidence_receipt.py:955:database-connection-strings","file":"runtime/scripts/evidence_receipt.py","pattern":"Database connection strings","snippet":"{\"DATABASE_URL\", \"GH_PAT\", \"MYSQL_PWD\", \"PGPASSWORD\"}","category":"env_access","line_end":955,"severity":"high","line_start":955},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-in-home-directory","file":"runtime/agy-worker.sh","pattern":"Hidden file in home directory","snippet":"`~/.gemini`, parent directories, or other user directories.","category":"filesystem","line_end":1262,"severity":"high","line_start":1262},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-in-home-directory","file":"runtime/ground-truth.sh","pattern":"Hidden file in home directory","snippet":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","category":"filesystem","line_end":63,"severity":"high","line_start":63},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2559:hidden-file-in-home-directory","file":"runtime/scripts/agy_dispatch.py","pattern":"Hidden file in home directory","snippet":"\"`~/.gemini`, or any other directory. Do not call shell or terminal tools.\\n\"","category":"filesystem","line_end":2559,"severity":"high","line_start":2559},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:416:non-standard-device-file-access","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Non-standard device file access","snippet":"(subpath \"/dev/fd\"))","category":"filesystem","line_end":416,"severity":"high","line_start":416},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:177:path-traversal-sequence","file":"references/SECURITY_AND_COMPATIBILITY.md","pattern":"Path traversal sequence","snippet":"The package-owned [README](../README.md), [skill router](../SKILL.md), and references","category":"filesystem","line_end":177,"severity":"high","line_start":177},{"id":"filesystem:runtime/qa-gate.sh:472:path-traversal-sequence","file":"runtime/qa-gate.sh","pattern":"Path traversal sequence","snippet":"if path in (\"\", \".\", \"..\") or path.startswith(\"../\") or posixpath.isabs(path):","category":"filesystem","line_end":472,"severity":"high","line_start":472},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:2610:path-traversal-sequence","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Path traversal sequence","snippet":"if norm != path or norm in (\"\", \".\", \"..\") or norm.startswith(\"../\") or posixpath.isabs(norm):","category":"filesystem","line_end":2610,"severity":"high","line_start":2610},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3490:path-traversal-sequence","file":"runtime/scripts/agy_dispatch.py","pattern":"Path traversal sequence","snippet":"# example ``../source/target``).  Rebase every contained link from its","category":"filesystem","line_end":3490,"severity":"high","line_start":3490},{"id":"filesystem:scripts/resolve-pipeline.sh:169:path-traversal-sequence","file":"scripts/resolve-pipeline.sh","pattern":"Path traversal sequence","snippet":"PLUGIN_ROOT=\"$(CDPATH= cd -- \"$SKILL_DIR/../..\" 2>/dev/null && pwd -P)\" || PLUGIN_ROOT=\"\"","category":"filesystem","line_end":169,"severity":"high","line_start":169},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:377:process-exec","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Process exec","snippet":"(allow process-exec","category":"external_commands","line_end":378,"severity":"high","line_start":377},{"id":"external_commands:runtime/scripts/agy_dispatch.py:2887:process-exec","file":"runtime/scripts/agy_dispatch.py","pattern":"Process exec","snippet":"exec(","category":"external_commands","line_end":2888,"severity":"high","line_start":2887},{"id":"external_commands:runtime/scripts/agy_dispatch.py:5617:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"def spawn(","category":"external_commands","line_end":5617,"severity":"high","line_start":5617},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6100:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(","category":"external_commands","line_end":6100,"severity":"high","line_start":6100},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6254:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(job, \"initial\", resume=False, foreground=True)","category":"external_commands","line_end":6254,"severity":"high","line_start":6254},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6256:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(job, \"initial\", resume=False, foreground=False)","category":"external_commands","line_end":6256,"severity":"high","line_start":6256},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6260:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(","category":"external_commands","line_end":6260,"severity":"high","line_start":6260},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6266:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(","category":"external_commands","line_end":6266,"severity":"high","line_start":6266},{"id":"scripts:runtime/agy-worker.sh:1430:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"if (not __import__(\"stat\").S_ISREG(before.st_mode) or before.st_uid != os.geteuid()","category":"scripts","line_end":1430,"severity":"high","line_start":1430},{"id":"scripts:runtime/agy-worker.sh:1431:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"or __import__(\"stat\").S_IMODE(before.st_mode) != 0o600 or before.st_nlink != 1):","category":"scripts","line_end":1431,"severity":"high","line_start":1431},{"id":"scripts:runtime/agy-worker.sh:1443:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"identity = lambda info: (info.st_dev, info.st_ino, info.st_uid, info.st_gid, __import__(\"stat\").S_IM","category":"scripts","line_end":1443,"severity":"high","line_start":1443},{"id":"scripts:runtime/agy-worker.sh:1446:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"value[\"selection_sha256\"] = __import__(\"hashlib\").sha256(selection).hexdigest()","category":"scripts","line_end":1446,"severity":"high","line_start":1446},{"id":"scripts:runtime/agy-worker.sh:1457:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"value[\"provider_scope_sha256\"] = __import__(\"hashlib\").sha256(sc_data).hexdigest()","category":"scripts","line_end":1457,"severity":"high","line_start":1457},{"id":"scripts:runtime/agy-worker.sh:1478:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"value[\"self_verification_manifest_sha256\"] = __import__(\"hashlib\").sha256(manifest_data).hexdigest()","category":"scripts","line_end":1478,"severity":"high","line_start":1478},{"id":"scripts:runtime/scripts/agy_dispatch_containment.py:377:python-exec-function","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Python exec() function","snippet":"(allow process-exec","category":"scripts","line_end":378,"severity":"high","line_start":377},{"id":"scripts:runtime/scripts/agy_dispatch.py:2887:python-exec-function","file":"runtime/scripts/agy_dispatch.py","pattern":"Python exec() function","snippet":"exec(","category":"scripts","line_end":2887,"severity":"high","line_start":2887},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:674:python-globals-manipulation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python globals() manipulation","snippet":"globals()[key] = value","category":"scripts","line_end":674,"severity":"high","line_start":674},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:4215:python-globals-manipulation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python globals() manipulation","snippet":"name: globals()[name] for name in _IMPLEMENTATION_FUNCTIONS","category":"scripts","line_end":4215,"severity":"high","line_start":4215},{"id":"scripts:runtime/scripts/agy_dispatch.py:46:python-globals-manipulation","file":"runtime/scripts/agy_dispatch.py","pattern":"Python globals() manipulation","snippet":"return globals()[name]","category":"scripts","line_end":46,"severity":"high","line_start":46},{"id":"scripts:runtime/scripts/agy_dispatch.py:3157:python-globals-manipulation","file":"runtime/scripts/agy_dispatch.py","pattern":"Python globals() manipulation","snippet":"name: globals()[name] for name in _WORKTREE_HELPER._IMPLEMENTATION_FUNCTIONS","category":"scripts","line_end":3157,"severity":"high","line_start":3157},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1521:python-os-exec-variants","file":"runtime/scripts/evidence_receipt.py","pattern":"Python os.exec variants","snippet":"os.execvpe(command[0], command, dict(os.environ))","category":"external_commands","line_end":1521,"severity":"high","line_start":1521},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:94:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_verification.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":94,"severity":"high","line_start":94},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:205:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"def _stop_preview_child(child: subprocess.Popen[bytes]) -> None:","category":"external_commands","line_end":205,"severity":"high","line_start":205},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:238:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"child: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":238,"severity":"high","line_start":238},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:244:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"child = subprocess.Popen(","category":"external_commands","line_end":244,"severity":"high","line_start":244},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1396:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":1396,"severity":"high","line_start":1396},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1414:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":1414,"severity":"high","line_start":1414},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3914:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"def _terminate(process: subprocess.Popen[bytes]) -> int:","category":"external_commands","line_end":3914,"severity":"high","line_start":3914},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3978:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes],","category":"external_commands","line_end":3978,"severity":"high","line_start":3978},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4234:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":4234,"severity":"high","line_start":4234},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4608:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":4608,"severity":"high","line_start":4608},{"id":"external_commands:runtime/scripts/agy_dispatch.py:5635:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"controller_process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":5635,"severity":"high","line_start":5635},{"id":"external_commands:runtime/scripts/agy_dispatch.py:5652:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"controller_process = subprocess.Popen(","category":"external_commands","line_end":5652,"severity":"high","line_start":5652},{"id":"external_commands:runtime/scripts/benchmark.py:135:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"b'process = subprocess.Popen(': 2,","category":"external_commands","line_end":135,"severity":"high","line_start":135},{"id":"external_commands:runtime/scripts/benchmark.py:581:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"def _close_group(process: subprocess.Popen[bytes]) -> int:","category":"external_commands","line_end":581,"severity":"high","line_start":581},{"id":"external_commands:runtime/scripts/benchmark.py:594:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"def _leader_exited_unreaped(process: subprocess.Popen[bytes]) -> bool:","category":"external_commands","line_end":594,"severity":"high","line_start":594},{"id":"external_commands:runtime/scripts/benchmark.py:606:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":606,"severity":"high","line_start":606},{"id":"external_commands:runtime/scripts/benchmark.py:615:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(argv, cwd=cwd, env=git_env(), stdin=subprocess.DEVNULL, stdout=subprocess","category":"external_commands","line_end":615,"severity":"high","line_start":615},{"id":"external_commands:runtime/scripts/codex_usage_report.py:115:python-subprocess-popen","file":"runtime/scripts/codex_usage_report.py","pattern":"Python subprocess.Popen","snippet":"def _close_process_group(process: subprocess.Popen[bytes], pgid: int) -> None:","category":"external_commands","line_end":115,"severity":"high","line_start":115},{"id":"external_commands:runtime/scripts/codex_usage_report.py:157:python-subprocess-popen","file":"runtime/scripts/codex_usage_report.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":157,"severity":"high","line_start":157},{"id":"external_commands:runtime/scripts/codex_usage_report.py:647:python-subprocess-popen","file":"runtime/scripts/codex_usage_report.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":647,"severity":"high","line_start":647},{"id":"external_commands:runtime/scripts/doctor-metadata.py:92:python-subprocess-popen","file":"runtime/scripts/doctor-metadata.py","pattern":"Python subprocess.Popen","snippet":"def terminate_group(process: subprocess.Popen[bytes], signum: int) -> None:","category":"external_commands","line_end":92,"severity":"high","line_start":92},{"id":"external_commands:runtime/scripts/doctor-metadata.py:129:python-subprocess-popen","file":"runtime/scripts/doctor-metadata.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":129,"severity":"high","line_start":129},{"id":"external_commands:runtime/scripts/doctor-metadata.py:142:python-subprocess-popen","file":"runtime/scripts/doctor-metadata.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":142,"severity":"high","line_start":142},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1132:python-subprocess-popen","file":"runtime/scripts/evidence_receipt.py","pattern":"Python subprocess.Popen","snippet":"child: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":1132,"severity":"high","line_start":1132},{"id":"external_commands:runtime/qa-gate.sh:447:python-subprocess-run","file":"runtime/qa-gate.sh","pattern":"Python subprocess.run","snippet":"return subprocess.run(","category":"external_commands","line_end":447,"severity":"high","line_start":447},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3358:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"subprocess.run(","category":"external_commands","line_end":3358,"severity":"high","line_start":3358},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3636:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"subprocess.run(","category":"external_commands","line_end":3636,"severity":"high","line_start":3636},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4209:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"provider_checked = subprocess.run(","category":"external_commands","line_end":4209,"severity":"high","line_start":4209},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4214:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"canonical_checked = subprocess.run(","category":"external_commands","line_end":4214,"severity":"high","line_start":4214},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6046:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"subprocess.run(","category":"external_commands","line_end":6046,"severity":"high","line_start":6046},{"id":"external_commands:runtime/scripts/benchmark.py:347:python-subprocess-run","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.run","snippet":"result = subprocess.run(command, cwd=cwd, env=git_env(), stdin=subprocess.DEVNULL, stdout=subprocess","category":"external_commands","line_end":347,"severity":"high","line_start":347},{"id":"external_commands:runtime/scripts/candidate_state.py:30:python-subprocess-run","file":"runtime/scripts/candidate_state.py","pattern":"Python subprocess.run","snippet":"completed = subprocess.run(","category":"external_commands","line_end":30,"severity":"high","line_start":30},{"id":"external_commands:runtime/scripts/evidence_receipt.py:468:python-subprocess-run","file":"runtime/scripts/evidence_receipt.py","pattern":"Python subprocess.run","snippet":"completed = subprocess.run(","category":"external_commands","line_end":468,"severity":"high","line_start":468},{"id":"external_commands:runtime/scripts/workflow.py:493:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":493,"severity":"high","line_start":493},{"id":"external_commands:runtime/scripts/workflow.py:544:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":544,"severity":"high","line_start":544},{"id":"external_commands:runtime/scripts/workflow.py:576:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":576,"severity":"high","line_start":576},{"id":"external_commands:runtime/scripts/workflow.py:762:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":762,"severity":"high","line_start":762},{"id":"external_commands:runtime/scripts/workflow.py:784:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"return subprocess.run(","category":"external_commands","line_end":784,"severity":"high","line_start":784},{"id":"external_commands:runtime/scripts/workflow.py:1121:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":1121,"severity":"high","line_start":1121},{"id":"external_commands:runtime/scripts/workflow.py:1800:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(verify_cmd, check=False)","category":"external_commands","line_end":1800,"severity":"high","line_start":1800},{"id":"external_commands:runtime/scripts/workflow.py:1854:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"fin_proc = subprocess.run(","category":"external_commands","line_end":1854,"severity":"high","line_start":1854},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3504:symlink-creation","file":"runtime/scripts/agy_dispatch.py","pattern":"Symlink creation","snippet":"os.symlink(target_text, target)","category":"filesystem","line_end":3504,"severity":"high","line_start":3504},{"id":"scripts:runtime/scripts/benchmark.py:88:dynamic-import-expression","file":"runtime/scripts/benchmark.py","pattern":"Dynamic import() expression","snippet":"from evidence_receipt import (  # noqa: E402","category":"scripts","line_end":96,"severity":"medium","line_start":88},{"id":"scripts:runtime/scripts/benchmark.py:97:dynamic-import-expression","file":"runtime/scripts/benchmark.py","pattern":"Dynamic import() expression","snippet":"from model_selection import (  # noqa: E402","category":"scripts","line_end":100,"severity":"medium","line_start":97},{"id":"scripts:runtime/scripts/evidence_receipt.py:29:dynamic-import-expression","file":"runtime/scripts/evidence_receipt.py","pattern":"Dynamic import() expression","snippet":"from model_selection import (  # noqa: E402","category":"scripts","line_end":37,"severity":"medium","line_start":29},{"id":"scripts:runtime/scripts/evidence_receipt.py:38:dynamic-import-expression","file":"runtime/scripts/evidence_receipt.py","pattern":"Dynamic import() expression","snippet":"from recommendation_record import (  # noqa: E402","category":"scripts","line_end":41,"severity":"medium","line_start":38},{"id":"scripts:runtime/scripts/evidence_report.py:25:dynamic-import-expression","file":"runtime/scripts/evidence_report.py","pattern":"Dynamic import() expression","snippet":"from evidence_receipt import (  # noqa: E402","category":"scripts","line_end":34,"severity":"medium","line_start":25},{"id":"scripts:runtime/scripts/evidence_report.py:35:dynamic-import-expression","file":"runtime/scripts/evidence_report.py","pattern":"Dynamic import() expression","snippet":"from recommendation_record import (  # noqa: E402","category":"scripts","line_end":38,"severity":"medium","line_start":35},{"id":"scripts:runtime/scripts/job_lifecycle.py:35:dynamic-import-expression","file":"runtime/scripts/job_lifecycle.py","pattern":"Dynamic import() expression","snippet":"from candidate_state import (  # noqa: E402","category":"scripts","line_end":38,"severity":"medium","line_start":35},{"id":"scripts:runtime/scripts/job_lifecycle.py:39:dynamic-import-expression","file":"runtime/scripts/job_lifecycle.py","pattern":"Dynamic import() expression","snippet":"from evidence_receipt import (  # noqa: E402","category":"scripts","line_end":44,"severity":"medium","line_start":39},{"id":"scripts:runtime/scripts/job_lifecycle.py:45:dynamic-import-expression","file":"runtime/scripts/job_lifecycle.py","pattern":"Dynamic import() expression","snippet":"from agy_dispatch import (  # noqa: E402","category":"scripts","line_end":54,"severity":"medium","line_start":45},{"id":"scripts:runtime/scripts/model-recommendation.py:12:dynamic-import-expression","file":"runtime/scripts/model-recommendation.py","pattern":"Dynamic import() expression","snippet":"from recommendation_record import (","category":"scripts","line_end":18,"severity":"medium","line_start":12},{"id":"filesystem:runtime/scripts/benchmark.py:420:hard-link-creation","file":"runtime/scripts/benchmark.py","pattern":"Hard link creation","snippet":"os.link(temp, name, src_dir_fd=fd, dst_dir_fd=fd, follow_symlinks=False)","category":"filesystem","line_end":420,"severity":"medium","line_start":420},{"id":"filesystem:runtime/scripts/evidence_receipt.py:882:hard-link-creation","file":"runtime/scripts/evidence_receipt.py","pattern":"Hard link creation","snippet":"os.link(temporary, target, follow_symlinks=False)","category":"filesystem","line_end":882,"severity":"medium","line_start":882},{"id":"filesystem:runtime/scripts/evidence_report.py:341:hard-link-creation","file":"runtime/scripts/evidence_report.py","pattern":"Hard link creation","snippet":"os.link(","category":"filesystem","line_end":341,"severity":"medium","line_start":341},{"id":"filesystem:runtime/scripts/model_evidence_campaign.py:355:hard-link-creation","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Hard link creation","snippet":"os.link(","category":"filesystem","line_end":355,"severity":"medium","line_start":355},{"id":"filesystem:runtime/scripts/swebench_workflow_study.py:277:hard-link-creation","file":"runtime/scripts/swebench_workflow_study.py","pattern":"Hard link creation","snippet":"os.link(temp,name,src_dir_fd=root_fd,dst_dir_fd=root_fd,follow_symlinks=False); linked=True","category":"filesystem","line_end":277,"severity":"medium","line_start":277},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-access","file":"runtime/agy-worker.sh","pattern":"Hidden file access","snippet":"`~/.gemini`, parent directories, or other user directories.","category":"filesystem","line_end":1262,"severity":"medium","line_start":1262},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-access","file":"runtime/ground-truth.sh","pattern":"Hidden file access","snippet":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","category":"filesystem","line_end":63,"severity":"medium","line_start":63},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2559:hidden-file-access","file":"runtime/scripts/agy_dispatch.py","pattern":"Hidden file access","snippet":"\"`~/.gemini`, or any other directory. Do not call shell or terminal tools.\\n\"","category":"filesystem","line_end":2559,"severity":"medium","line_start":2559},{"id":"filesystem:scripts/resolve-pipeline.sh:171:hidden-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Hidden file access","snippet":"&& [[ -f \"$PLUGIN_ROOT/.codex-plugin/plugin.json\" ]] \\","category":"filesystem","line_end":171,"severity":"medium","line_start":171},{"id":"filesystem:scripts/resolve-pipeline.sh:177:hidden-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Hidden file access","snippet":"MARKER=\"$SKILL_DIR/.pipeline-root\"","category":"filesystem","line_end":177,"severity":"medium","line_start":177},{"id":"filesystem:runtime/scripts/model_selection.py:1270:python-file-write-append","file":"runtime/scripts/model_selection.py","pattern":"Python file write/append","snippet":"with os.fdopen(descriptor, \"wb\") as handle:","category":"filesystem","line_end":1270,"severity":"medium","line_start":1270},{"id":"filesystem:runtime/agy-worker.sh:939:python-os-file-operations","file":"runtime/agy-worker.sh","pattern":"Python os file operations","snippet":"os.rmdir(path)","category":"filesystem","line_end":939,"severity":"medium","line_start":939},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:268:python-os-file-operations","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Python os file operations","snippet":"os.chmod(path, 0o700, follow_symlinks=False)","category":"filesystem","line_end":268,"severity":"medium","line_start":268},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3479:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(name, dir_fd=recovery_fd)","category":"filesystem","line_end":3479,"severity":"medium","line_start":3479},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3481:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(\"reconciliation-backups\", dir_fd=job_fd)","category":"filesystem","line_end":3481,"severity":"medium","line_start":3481},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3482:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(\"reconciliation-in-progress.json\", dir_fd=job_fd)","category":"filesystem","line_end":3482,"severity":"medium","line_start":3482},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3517:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(parts[-1], dir_fd=parent)","category":"filesystem","line_end":3517,"severity":"medium","line_start":3517},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3519:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(parts[-1], dir_fd=parent)","category":"filesystem","line_end":3519,"severity":"medium","line_start":3519},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4055:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(parts[-1], dir_fd=curr_src)","category":"filesystem","line_end":4055,"severity":"medium","line_start":4055},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4067:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(parts[-1], dir_fd=curr_src)","category":"filesystem","line_end":4067,"severity":"medium","line_start":4067},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4169:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(name_str, dir_fd=parent_fd)","category":"filesystem","line_end":4169,"severity":"medium","line_start":4169},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4171:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(name_str, dir_fd=parent_fd)","category":"filesystem","line_end":4171,"severity":"medium","line_start":4171},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4177:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(stg_str)","category":"filesystem","line_end":4177,"severity":"medium","line_start":4177},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3440:python-os-file-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python os file operations","snippet":"os.chmod(current, 0o700)","category":"filesystem","line_end":3440,"severity":"medium","line_start":3440},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3551:python-os-file-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python os file operations","snippet":"os.chmod(destination, 0o700)","category":"filesystem","line_end":3551,"severity":"medium","line_start":3551},{"id":"filesystem:runtime/scripts/benchmark.py:427:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.unlink(temp, dir_fd=fd)","category":"filesystem","line_end":427,"severity":"medium","line_start":427},{"id":"filesystem:runtime/scripts/benchmark.py:441:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.unlink(target, dir_fd=fd)","category":"filesystem","line_end":441,"severity":"medium","line_start":441},{"id":"filesystem:runtime/scripts/benchmark.py:465:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.unlink(name, dir_fd=fd); os.fsync(fd)","category":"filesystem","line_end":465,"severity":"medium","line_start":465},{"id":"filesystem:runtime/scripts/benchmark.py:757:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.chmod(work, 0o700)","category":"filesystem","line_end":757,"severity":"medium","line_start":757},{"id":"filesystem:runtime/scripts/benchmark.py:770:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"selection_path.write_bytes(canonical_bytes(variant[\"selection\"])); os.chmod(selection_path, 0o600)","category":"filesystem","line_end":770,"severity":"medium","line_start":770},{"id":"filesystem:runtime/scripts/codex_usage_report.py:223:python-os-file-operations","file":"runtime/scripts/codex_usage_report.py","pattern":"Python os file operations","snippet":"os.chmod(str(temp_path), 0o700)","category":"filesystem","line_end":223,"severity":"medium","line_start":223},{"id":"filesystem:runtime/scripts/evidence_report.py:263:python-os-file-operations","file":"runtime/scripts/evidence_report.py","pattern":"Python os file operations","snippet":"os.unlink(name, dir_fd=parent_fd)","category":"filesystem","line_end":263,"severity":"medium","line_start":263},{"id":"filesystem:runtime/scripts/evidence_report.py:353:python-os-file-operations","file":"runtime/scripts/evidence_report.py","pattern":"Python os file operations","snippet":"os.unlink(temporary, dir_fd=parent_fd)","category":"filesystem","line_end":353,"severity":"medium","line_start":353},{"id":"filesystem:runtime/scripts/job_lifecycle.py:690:python-os-file-operations","file":"runtime/scripts/job_lifecycle.py","pattern":"Python os file operations","snippet":"os.unlink(temporary, dir_fd=self.parent_fd)","category":"filesystem","line_end":690,"severity":"medium","line_start":690},{"id":"filesystem:runtime/scripts/job_lifecycle.py:839:python-os-file-operations","file":"runtime/scripts/job_lifecycle.py","pattern":"Python os file operations","snippet":"os.chmod(directory, 0o700)","category":"filesystem","line_end":839,"severity":"medium","line_start":839},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3447:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.rmtree(destination)","category":"filesystem","line_end":3447,"severity":"medium","line_start":3447},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3505:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.copystat(source, target, follow_symlinks=False)","category":"filesystem","line_end":3505,"severity":"medium","line_start":3505},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3511:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.copy2(source, target, follow_symlinks=False)","category":"filesystem","line_end":3511,"severity":"medium","line_start":3511},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3545:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.copystat(source, target, follow_symlinks=False)","category":"filesystem","line_end":3545,"severity":"medium","line_start":3545},{"id":"filesystem:runtime/scripts/benchmark.py:740:python-shutil-operations","file":"runtime/scripts/benchmark.py","pattern":"Python shutil operations","snippet":"shutil.rmtree(path)","category":"filesystem","line_end":740,"severity":"medium","line_start":740},{"id":"filesystem:runtime/scripts/job_lifecycle.py:851:python-shutil-operations","file":"runtime/scripts/job_lifecycle.py","pattern":"Python shutil operations","snippet":"shutil.rmtree(directory, ignore_errors=True)","category":"filesystem","line_end":851,"severity":"medium","line_start":851},{"id":"external_commands:runtime/agy-worker.sh:14:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"#   * Under --sandbox, SHELL commands need an `unsandboxed(<target>)` allow-rule; a","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:runtime/agy-worker.sh:15:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"#     `command(<name>)` rule alone is NOT enough. But a worker editing files via its","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:runtime/agy-worker.sh:1262:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"`~/.gemini`, parent directories, or other user directories.","category":"external_commands","line_end":1262,"severity":"medium","line_start":1262},{"id":"external_commands:runtime/agy-worker.sh:1263:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"- Never call shell or terminal tools, including `pwd`, `ls`, `find`, or `git`.","category":"external_commands","line_end":1263,"severity":"medium","line_start":1263},{"id":"external_commands:runtime/agy-worker.sh:1300:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"# the `tools:` list is meaningless here — tool access is governed by agy's own","category":"external_commands","line_end":1300,"severity":"medium","line_start":1300},{"id":"external_commands:runtime/ground-truth.sh:5:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# When agy was asked to research its own CLI, it confidently invented `agy run`,","category":"external_commands","line_end":5,"severity":"medium","line_start":5},{"id":"external_commands:runtime/ground-truth.sh:6:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# `--headless`, `--slim`, `--no-prompt`, `--workspace` and an `agy auth status --json`","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:runtime/ground-truth.sh:8:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# `agy --help` got it right. Conclusion: a model's memory of its own tooling is","category":"external_commands","line_end":8,"severity":"medium","line_start":8},{"id":"external_commands:runtime/ground-truth.sh:13:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# account review: it invokes only `agy --version` and `agy --help`. The optional","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:runtime/ground-truth.sh:14:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# account phase is a separate explicit action because `models`, `agents`, plugin","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:runtime/ground-truth.sh:74:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- The prompt is `--print`'s ARGUMENT VALUE. agy ignores stdin in print mode. With","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:runtime/ground-truth.sh:75:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"`--print` placed before other flags, agy reads the NEXT FLAG as the message.","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:runtime/ground-truth.sh:76:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"Therefore `--print` must always be built LAST.","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:runtime/ground-truth.sh:80:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- Under `--sandbox`, running a shell command needs an `unsandboxed(<target>)`","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:runtime/ground-truth.sh:81:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"allow-rule. A `command(<name>)` rule alone is NOT sufficient.","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:runtime/ground-truth.sh:85:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- `stream-json` event shape: {\"event\":\"...\",\"init\":...}, then repeated","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:runtime/ground-truth.sh:92:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- The observed unsupported examples `agy run`, `agy exec`, and `agy auth` print","category":"external_commands","line_end":92,"severity":"medium","line_start":92},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:9:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"``sandbox-exec`` is a deprecated macOS interface.  The implementation therefore","category":"external_commands","line_end":9,"severity":"medium","line_start":9},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:11:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"caller must re-run :func:`confirm_contained_launch` immediately before ``Popen``.","category":"external_commands","line_end":11,"severity":"medium","line_start":11},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:308:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Render the fixed default-deny profile; dynamic paths use ``-D`` params.\"\"\"","category":"external_commands","line_end":308,"severity":"medium","line_start":308},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:534:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Revalidate every native authority immediately before caller ``Popen``.\"\"\"","category":"external_commands","line_end":534,"severity":"medium","line_start":534},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:616:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Bind the session leader created by ``Popen(start_new_session=True)``.\"\"\"","category":"external_commands","line_end":616,"severity":"medium","line_start":616},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:690:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Signal only members of the exact new session rooted at ``root``.","category":"external_commands","line_end":690,"severity":"medium","line_start":690},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:692:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"Direct ``setsid`` and ``setpgid`` syscalls are denied, but posix_spawn","category":"external_commands","line_end":692,"severity":"medium","line_start":692},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"project work through `agy`. The worker discovers ordinary structure and proposes or","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":22,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`ready` covers offline prerequisites only. It does not prove authentication, provider","category":"external_commands","line_end":48,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Prefer `--provider-scope FILE --approve-transmission-sha SHA256` for bounded jobs. It binds exact re","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Whole-worktree dispatch remains an explicit exception. Treat the entire disposable worktree passed a","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Neither `workflow.sh run` nor the advanced `agy-worker.sh` initial dispatch has an implicit transmis","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"New jobs default to `--provider-isolation session`, which uses the existing AGY session without AGY ","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Explore, understand, review, or plan | `explore` | 2 | Spot-check material claims and state covera","category":"external_commands","line_end":76,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Implement a feature, refactor, tests, or a bounded repair | `task` | 2 | Inspect the diff and run ","category":"external_commands","line_end":77,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Build a project or perform broad audit-and-fix work | `project` | 5 | Review repo-wide changes and","category":"external_commands","line_end":79,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`explore` and `task` accept `1..2` cycles; `project` accepts `1..5`. Personas","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The advanced raw dispatcher also offers an opt-in `--boost` profile for one bounded","category":"external_commands","line_end":84,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`task` cycle. Boost may invoke provider-side subagents and protected tools, so it","category":"external_commands","line_end":85,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"requires the exact job-bound `--approve-boost-risk-sha` printed by the rejected","category":"external_commands","line_end":87,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"scope. Boost is restricted to `accept-edits`, one cycle, no persona, and default slash","category":"external_commands","line_end":89,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"both `agent=Boost` and `permission_mode=request-review`. A Boost job cannot resume,","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Explicit delegation-first requires running the `delegation-policy.sh` evaluator before substantive r","category":"external_commands","line_end":109,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Prefer the portable `workflow.sh` facade for `run --preview`, approved `run`,","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"read-only `status`, and `verify-finalize`. For ordinary use, supply only an absolute","category":"external_commands","line_end":110,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"repository and job ID; optional `--base` overrides the first-call `HEAD` binding. The","category":"external_commands","line_end":111,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"repository/job ID with `--approve-whole-worktree` and its exact manifest digest, or","category":"external_commands","line_end":115,"severity":"medium","line_start":114},{"id":"external_commands:README.md:56:shell-command-substitution","file":"README.md","pattern":"Shell command substitution","snippet":"PIPELINE=\"$(bash \"$SKILL_ROOT/scripts/resolve-pipeline.sh\")\" || exit $?","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:39:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"PIPELINE=\"$(bash \"$SKILL_ROOT/scripts/resolve-pipeline.sh\")\" || exit $?","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:48:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"BASE=\"$(git -C \"$TARGET\" rev-parse HEAD)\"","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:49:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"STATE_DIR=\"$(mktemp -d -t agyworker-state.XXXXXX)\"","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:50:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"WT=\"$(mktemp -d -t agyworker-worktree.XXXXXX)\"","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:212:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"VERIFY_PARENT=\"$(mktemp -d -t agyworker-verify.XXXXXX)\" || exit $?","category":"external_commands","line_end":212,"severity":"medium","line_start":212},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:213:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"VERIFY_PARENT=\"$(CDPATH= cd -- \"$VERIFY_PARENT\" && pwd -P)\" || exit $?","category":"external_commands","line_end":213,"severity":"medium","line_start":213},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:244:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"STATUS_JSON=\"$(\"$PIPELINE/agy-worker.sh\" status --job-id \"$JOB_ID\" --format json)\"","category":"external_commands","line_end":244,"severity":"medium","line_start":244},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:245:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"STATE_AND_CANDIDATE=\"$(printf '%s\\n' \"$STATUS_JSON\" | python3 -c '","category":"external_commands","line_end":247,"severity":"medium","line_start":245},{"id":"external_commands:runtime/agy-worker.sh:25:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"CALLER_UMASK=\"$(umask)\"","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:runtime/agy-worker.sh:30:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"SCRIPT_DIR=\"$(CDPATH= cd -- \"$SCRIPT_SOURCE_DIR\" && pwd -P)\"","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:runtime/agy-worker.sh:237:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\" || exit 64","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:runtime/agy-worker.sh:464:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"provider_env_occurrences=$((provider_env_occurrences + 1))","category":"external_commands","line_end":464,"severity":"medium","line_start":464},{"id":"external_commands:runtime/agy-worker.sh:473:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"job_id=\"job-$(python3 -I -S -B - <<'PY'","category":"external_commands","line_end":475,"severity":"medium","line_start":473},{"id":"external_commands:runtime/agy-worker.sh:497:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"tier_seen=$((tier_cli_seen + tier_env_seen))","category":"external_commands","line_end":497,"severity":"medium","line_start":497},{"id":"external_commands:runtime/agy-worker.sh:498:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"model_seen=$((model_cli_seen + model_env_seen))","category":"external_commands","line_end":498,"severity":"medium","line_start":498},{"id":"external_commands:runtime/agy-worker.sh:499:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"effort_seen=$((effort_cli_seen + effort_env_seen))","category":"external_commands","line_end":499,"severity":"medium","line_start":499},{"id":"external_commands:runtime/agy-worker.sh:603:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"boost_policy_sha=\"$(printf '%s' \"$boost_policy_text\" | shasum -a 256 | awk '{print $1}')\"","category":"external_commands","line_end":603,"severity":"medium","line_start":603},{"id":"external_commands:runtime/agy-worker.sh:604:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"expected_boost_risk_sha=\"$(printf '%s\\n%s\\n' \"$boost_policy_sha\" \"$job_id\" | shasum -a 256 | awk '{p","category":"external_commands","line_end":604,"severity":"medium","line_start":604},{"id":"external_commands:runtime/agy-worker.sh:649:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"idle_seconds=\"$(duration_seconds \"$idle_timeout\")\" || { echo \"agy-worker.sh: invalid idle timeout\" >","category":"external_commands","line_end":649,"severity":"medium","line_start":649},{"id":"external_commands:runtime/agy-worker.sh:650:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"hard_seconds=\"$(duration_seconds \"$hard_timeout\")\" || { echo \"agy-worker.sh: invalid hard timeout\" >","category":"external_commands","line_end":650,"severity":"medium","line_start":650},{"id":"external_commands:runtime/agy-worker.sh:651:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"max_seconds=\"$(duration_seconds \"$max_runtime\")\" || { echo \"agy-worker.sh: invalid max runtime\" >&2;","category":"external_commands","line_end":651,"severity":"medium","line_start":651},{"id":"external_commands:runtime/agy-worker.sh:652:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"notice_seconds=\"$(duration_seconds \"$notice_interval\")\" || { echo \"agy-worker.sh: invalid notice int","category":"external_commands","line_end":652,"severity":"medium","line_start":652},{"id":"external_commands:runtime/agy-worker.sh:663:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"prospective_workdir=\"$(CDPATH= cd -- \"$workdir\" 2>/dev/null && pwd -P)\" || {","category":"external_commands","line_end":663,"severity":"medium","line_start":663},{"id":"external_commands:runtime/agy-worker.sh:685:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"if ! LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\"; then","category":"external_commands","line_end":685,"severity":"medium","line_start":685},{"id":"external_commands:runtime/agy-worker.sh:690:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"SCHEMA=\"$(cd \"$(dirname \"$SCHEMA\")\" && pwd)/$(basename \"$SCHEMA\")\"","category":"external_commands","line_end":690,"severity":"medium","line_start":690},{"id":"external_commands:runtime/agy-worker.sh:692:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"workdir=\"$(cd \"$workdir\" && pwd -P)\"","category":"external_commands","line_end":692,"severity":"medium","line_start":692},{"id":"external_commands:runtime/agy-worker.sh:696:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"resolved_dir=\"$(cd \"$d\" && pwd -P)\"","category":"external_commands","line_end":696,"severity":"medium","line_start":696},{"id":"external_commands:runtime/agy-worker.sh:720:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"current_manifest_sha=\"$(","category":"external_commands","line_end":725,"severity":"medium","line_start":720},{"id":"external_commands:runtime/agy-worker.sh:901:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"job_dir_identity=\"$(python3 -I -S -B - \"$job_dir\" <<'PY'","category":"external_commands","line_end":906,"severity":"medium","line_start":901},{"id":"external_commands:runtime/agy-worker.sh:980:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"model=\"$(python3 -B \"$SCRIPT_DIR/scripts/model_selection.py\" \"${selection_args[@]}\")\"","category":"external_commands","line_end":980,"severity":"medium","line_start":980},{"id":"external_commands:runtime/agy-worker.sh:1009:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"observed_version=\"$(python3 -B \"$SCRIPT_DIR/scripts/model_selection.py\" \\","category":"external_commands","line_end":1011,"severity":"medium","line_start":1009},{"id":"external_commands:runtime/agy-worker.sh:1043:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"if ! self_verification_prompt_block=\"$(","category":"external_commands","line_end":1054,"severity":"medium","line_start":1043},{"id":"external_commands:scripts/resolve-pipeline.sh:6:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"SCRIPT_DIR=\"$(CDPATH= cd -- \"$(dirname -- \"${BASH_SOURCE[0]}\")\" && pwd -P)\"","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:scripts/resolve-pipeline.sh:7:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"SKILL_DIR=\"$(CDPATH= cd -- \"$SCRIPT_DIR/..\" && pwd -P)\"","category":"external_commands","line_end":7,"severity":"medium","line_start":7},{"id":"external_commands:scripts/resolve-pipeline.sh:12:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"pipeline_root=\"$(CDPATH= cd -- \"$1\" 2>/dev/null && pwd -P)\" || return 1","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:scripts/resolve-pipeline.sh:19:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"component_canonical=\"$(CDPATH= cd -- \"$parent_canonical/$component\" \\","category":"external_commands","line_end":20,"severity":"medium","line_start":19},{"id":"external_commands:scripts/resolve-pipeline.sh:40:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"runtime_canonical=\"$(CDPATH= cd -- \"$runtime_root\" 2>/dev/null && pwd -P)\" \\","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:scripts/resolve-pipeline.sh:45:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"parent_canonical=\"$(CDPATH= cd -- \"$runtime_canonical/$parent\" \\","category":"external_commands","line_end":46,"severity":"medium","line_start":45},{"id":"external_commands:scripts/resolve-pipeline.sh:93:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"parent_canonical=\"$(CDPATH= cd -- \"$runtime_canonical/$dependency_parent\" \\","category":"external_commands","line_end":94,"severity":"medium","line_start":93},{"id":"external_commands:scripts/resolve-pipeline.sh:154:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"parent_canonical=\"$(CDPATH= cd -- \"$runtime_canonical/$dependency_parent\" \\","category":"external_commands","line_end":155,"severity":"medium","line_start":154},{"id":"external_commands:scripts/resolve-pipeline.sh:164:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"&& \"$(/usr/bin/stat -f '%Lp' \"$dependency_canonical\" 2>/dev/null \\","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:scripts/resolve-pipeline.sh:169:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"PLUGIN_ROOT=\"$(CDPATH= cd -- \"$SKILL_DIR/../..\" 2>/dev/null && pwd -P)\" || PLUGIN_ROOT=\"\"","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:21:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"PIPELINE=\"$(bash \"$SKILL_ROOT/scripts/resolve-pipeline.sh\")\" || exit $?","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:42:temp-directory-access","file":"references/SECURITY_AND_COMPATIBILITY.md","pattern":"Temp directory access","snippet":"HOME/TMP/XDG with private directories for scoped launches. Version/help probes are","category":"filesystem","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:runtime/agy-worker.sh:15:template-literal-with-command-substitution","file":"runtime/agy-worker.sh","pattern":"Template literal with command substitution","snippet":"#     `command(<name>)` rule alone is NOT enough. But a worker editing files via its","category":"external_commands","line_end":1262,"severity":"medium","line_start":15},{"id":"external_commands:runtime/ground-truth.sh:14:template-literal-with-command-substitution","file":"runtime/ground-truth.sh","pattern":"Template literal with command substitution","snippet":"# account phase is a separate explicit action because `models`, `agents`, plugin","category":"external_commands","line_end":74,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:20:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":22,"severity":"medium","line_start":20},{"id":"external_commands:runtime/qa-gate.sh:623:unix-shell-invocation","file":"runtime/qa-gate.sh","pattern":"Unix shell invocation","snippet":"/bin/bash -c \"${verify_specs[$i]}\"","category":"external_commands","line_end":623,"severity":"medium","line_start":623},{"id":"external_commands:runtime/qa-gate.sh:639:unix-shell-invocation","file":"runtime/qa-gate.sh","pattern":"Unix shell invocation","snippet":"/bin/bash -c \"${verify_specs[$i]}\"","category":"external_commands","line_end":639,"severity":"medium","line_start":639},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:27:unix-shell-invocation","file":"runtime/scripts/agy_dispatch_verification.py","pattern":"Unix shell invocation","snippet":"SCRIPT_SHELLS = frozenset({\"/bin/bash\", \"/bin/sh\"})","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1416:unix-shell-invocation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Unix shell invocation","snippet":"\"/bin/sh\", \"-c\", supervisor, \"bounded-git-supervisor\",","category":"external_commands","line_end":1416,"severity":"medium","line_start":1416},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1146:unix-shell-invocation","file":"runtime/scripts/evidence_receipt.py","pattern":"Unix shell invocation","snippet":"\"/bin/bash\",","category":"external_commands","line_end":1146,"severity":"medium","line_start":1146},{"id":"blocker:runtime/agy-worker.sh:154:network-reconnaissance","file":"runtime/agy-worker.sh","pattern":"Network reconnaissance","snippet":"result emits its bound worker envelope unless --format text. A non-zero run exit means","category":"blocker","line_end":154,"severity":"low","line_start":154},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:63:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"--branch \"$JOB_BRANCH\" --base \"$BASE\" --job-id \"$JOB_ID\" \\","category":"blocker","line_end":63,"severity":"low","line_start":63},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:80:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"--branch \"$JOB_BRANCH\" --base \"$BASE\" --job-id \"$JOB_ID\" \\","category":"blocker","line_end":80,"severity":"low","line_start":80},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:169:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"- A structurally valid provider `ERROR` candidate is retrieved and reviewed before","category":"blocker","line_end":169,"severity":"low","line_start":169},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:171:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"- A structurally valid `CANCELED` or `CANCELLED` candidate is preserved for review","category":"blocker","line_end":171,"severity":"low","line_start":171},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:215:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"\"$PIPELINE/agy-worker.sh\" verification-copy --job-id \"$JOB_ID\" \\","category":"blocker","line_end":215,"severity":"low","line_start":215},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:244:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"STATUS_JSON=\"$(\"$PIPELINE/agy-worker.sh\" status --job-id \"$JOB_ID\" --format json)\"","category":"blocker","line_end":244,"severity":"low","line_start":244},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:279:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"\"$PIPELINE/agy-worker.sh\" continue --job-id \"$JOB_ID\" \\","category":"blocker","line_end":279,"severity":"low","line_start":279},{"id":"blocker:references/TROUBLESHOOTING.md:54:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"failure. A model change cannot repair a permission, missing executable, invalid","category":"blocker","line_end":55,"severity":"low","line_start":54},{"id":"blocker:references/TROUBLESHOOTING.md:65:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"This can be valid CLI behavior. Parse `result.structured_output`; do not treat the","category":"blocker","line_end":65,"severity":"low","line_start":65},{"id":"blocker:references/TROUBLESHOOTING.md:88:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"that same intended job and transmission. An invalid or stale digest, broader workflow,","category":"blocker","line_end":88,"severity":"low","line_start":88},{"id":"blocker:references/TROUBLESHOOTING.md:96:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"A structurally valid `ERROR` candidate is reviewable. Retrieve `result`, inspect the","category":"blocker","line_end":96,"severity":"low","line_start":96},{"id":"blocker:references/TROUBLESHOOTING.md:100:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"A structurally valid `CANCELED` or `CANCELLED` candidate is preserved for review and","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:references/TROUBLESHOOTING.md:139:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"outward/broken/Git-administration symlinks, or an invalid destination boundary. A","category":"blocker","line_end":139,"severity":"low","line_start":139},{"id":"blocker:references/TROUBLESHOOTING.md:141:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"only when its bounded inspection is small enough; otherwise the failure stays an invalid","category":"blocker","line_end":142,"severity":"low","line_start":141},{"id":"blocker:runtime/agents/bulk-test-writer.md:46:system-reconnaissance","file":"runtime/agents/bulk-test-writer.md","pattern":"System reconnaissance","snippet":"invalid state that the public constructor deliberately rejects, first create a valid","category":"blocker","line_end":46,"severity":"low","line_start":46},{"id":"blocker:runtime/agents/diff-reviewer.md:34:system-reconnaissance","file":"runtime/agents/diff-reviewer.md","pattern":"System reconnaissance","snippet":"4. **Secret exposure** — credentials, tokens, internal hostnames added to tracked files.","category":"blocker","line_end":34,"severity":"low","line_start":34},{"id":"blocker:runtime/agents/repo-inventory.md:40:system-reconnaissance","file":"runtime/agents/repo-inventory.md","pattern":"System reconnaissance","snippet":"- Report only what you actually read. If you did not open a file, do not describe","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"blocker:runtime/agy-worker.sh:2:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"# agy-worker.sh — dispatch a bounded job to agy and return a schema-valid result envelope.","category":"blocker","line_end":2,"severity":"low","line_start":2},{"id":"blocker:runtime/agy-worker.sh:79:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"valid = (","category":"blocker","line_end":79,"severity":"low","line_start":79},{"id":"blocker:runtime/agy-worker.sh:82:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"and metadata.st_uid == os.geteuid()","category":"blocker","line_end":82,"severity":"low","line_start":82},{"id":"blocker:runtime/agy-worker.sh:85:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"raise SystemExit(0 if valid else 1)","category":"blocker","line_end":85,"severity":"low","line_start":85},{"id":"blocker:runtime/agy-worker.sh:134:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh status|result --job-id JOB [--format json|text]","category":"blocker","line_end":134,"severity":"low","line_start":134},{"id":"blocker:runtime/agy-worker.sh:135:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh verification-copy --job-id JOB --destination NEW_DIRECTORY_IN_0700_PARENT [--format js","category":"blocker","line_end":135,"severity":"low","line_start":135},{"id":"blocker:runtime/agy-worker.sh:136:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh self-verify --job-id JOB --approve-state-sha SHA [--format json|text]","category":"blocker","line_end":136,"severity":"low","line_start":136},{"id":"blocker:runtime/agy-worker.sh:137:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh resume --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] [--format js","category":"blocker","line_end":137,"severity":"low","line_start":137},{"id":"blocker:runtime/agy-worker.sh:138:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh restart --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] [--format j","category":"blocker","line_end":138,"severity":"low","line_start":138},{"id":"blocker:runtime/agy-worker.sh:139:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh continue --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] [--format ","category":"blocker","line_end":139,"severity":"low","line_start":139},{"id":"blocker:runtime/agy-worker.sh:140:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh continue --job-id JOB --approve-state-sha SHA --use-self-verification [--format json|t","category":"blocker","line_end":140,"severity":"low","line_start":140},{"id":"blocker:runtime/agy-worker.sh:141:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh finalize --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] \\","category":"blocker","line_end":141,"severity":"low","line_start":141},{"id":"blocker:runtime/agy-worker.sh:143:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh wait --job-id JOB --after-state-sha SHA [--timeout 60s] [--format json|text]","category":"blocker","line_end":143,"severity":"low","line_start":143},{"id":"blocker:runtime/agy-worker.sh:144:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh cancel --job-id JOB --approve-state-sha SHA","category":"blocker","line_end":144,"severity":"low","line_start":144},{"id":"blocker:runtime/agy-worker.sh:145:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh extend --job-id JOB --approve-state-sha SHA --by 2h","category":"blocker","line_end":145,"severity":"low","line_start":145},{"id":"blocker:runtime/agy-worker.sh:155:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"stdout is NOT a valid envelope. Artifacts land in $AGY_WORKER_LOG_DIR.","category":"blocker","line_end":155,"severity":"low","line_start":155},{"id":"blocker:runtime/agy-worker.sh:157:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"Exit codes: 0 ok · 2 no prompt · 3 empty output · 4 schema invalid · 5 unclassified agy failure","category":"blocker","line_end":157,"severity":"low","line_start":157},{"id":"blocker:runtime/agy-worker.sh:163:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"64 invalid usage","category":"blocker","line_end":163,"severity":"low","line_start":163},{"id":"blocker:runtime/agy-worker.sh:166:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh resume --job-id JOB --approve-state-sha STATE_SHA","category":"blocker","line_end":166,"severity":"low","line_start":166},{"id":"blocker:runtime/agy-worker.sh:167:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh restart --job-id JOB --approve-state-sha STATE_SHA","category":"blocker","line_end":167,"severity":"low","line_start":167},{"id":"blocker:runtime/agy-worker.sh:221:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"*) echo \"agy-worker.sh: invalid usage; run --help for usage\" >&2; usage ;;","category":"blocker","line_end":221,"severity":"low","line_start":221},{"id":"blocker:scripts/resolve-pipeline.sh:183:system-reconnaissance","file":"scripts/resolve-pipeline.sh","pattern":"System reconnaissance","snippet":"echo \"agy-worker: invalid standalone pipeline marker\" >&2","category":"blocker","line_end":183,"severity":"low","line_start":183},{"id":"env_access:runtime/scripts/agy_dispatch_verification.py:151:configuration-library","file":"runtime/scripts/agy_dispatch_verification.py","pattern":"Configuration library","snippet":"raise VerificationError(\"verification descendants remain unconfirmed\")","category":"env_access","line_end":151,"severity":"low","line_start":151},{"id":"network:runtime/compat/agy-version-manifest.json:20:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.26-555015","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:runtime/compat/agy-version-manifest.json:65:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.12-587761","category":"network","line_end":65,"severity":"low","line_start":65},{"id":"network:runtime/compat/agy-version-manifest.json:85:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.16-660797","category":"network","line_end":85,"severity":"low","line_start":85},{"id":"network:runtime/compat/agy-version-manifest.json:111:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.22-571154","category":"network","line_end":111,"severity":"low","line_start":111},{"id":"network:runtime/compat/agy-version-manifest.json:159:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://github.com/google-antigravity/antigravity-cli/releases/download/1.1.24/","category":"network","line_end":159,"severity":"low","line_start":159},{"id":"network:runtime/compat/model-effort-matrix.schema.json:2:hardcoded-url","file":"runtime/compat/model-effort-matrix.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/compat/model-effort-matrix.schema.json:3:hardcoded-url","file":"runtime/compat/model-effort-matrix.schema.json","pattern":"Hardcoded URL","snippet":"\"$id\": \"https://cagdasyurekli.github.io/codex-agy-worker/schemas/model-effort-matrix-v1.json\",","category":"network","line_end":3,"severity":"low","line_start":3},{"id":"network:runtime/compat/version-manifest.schema.json:2:hardcoded-url","file":"runtime/compat/version-manifest.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/benchmark-plan.schema.json:1:hardcoded-url","file":"runtime/schemas/benchmark-plan.schema.json","pattern":"Hardcoded URL","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"exp","category":"network","line_end":1,"severity":"low","line_start":1},{"id":"network:runtime/schemas/benchmark-result.schema.json:1:hardcoded-url","file":"runtime/schemas/benchmark-result.schema.json","pattern":"Hardcoded URL","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"com","category":"network","line_end":1,"severity":"low","line_start":1},{"id":"network:runtime/schemas/delegation-policy.schema.json:2:hardcoded-url","file":"runtime/schemas/delegation-policy.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/evidence-receipt.schema.json:2:hardcoded-url","file":"runtime/schemas/evidence-receipt.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/job-state.schema.json:2:hardcoded-url","file":"runtime/schemas/job-state.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-preview.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-advisory-preview.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-advisory-summary.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-aggregate.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-evaluation.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-evaluation.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-plan.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-plan.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-record.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-record.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-record.schema.json:156:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-record.schema.json","pattern":"Hardcoded URL","snippet":"\"source_uri\": {\"type\": \"string\", \"pattern\": \"^(https://[a-zA-Z0-9_./-]{1,2000}|local://[a-zA-Z0-9_./","category":"network","line_end":156,"severity":"low","line_start":156},{"id":"network:runtime/schemas/model-intelligence-advisory.schema.json:2:hardcoded-url","file":"runtime/schemas/model-intelligence-advisory.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-intelligence-evidence.schema.json:2:hardcoded-url","file":"runtime/schemas/model-intelligence-evidence.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-intelligence-evidence.schema.json:85:hardcoded-url","file":"runtime/schemas/model-intelligence-evidence.schema.json","pattern":"Hardcoded URL","snippet":"\"pattern\": \"^(https://[a-zA-Z0-9_./-]+|local://[a-zA-Z0-9_./-]+)(?![\\\\s\\\\S])\",","category":"network","line_end":85,"severity":"low","line_start":85},{"id":"env_access:runtime/scripts/agy_dispatch_worktree.py:1379:python-environment-access","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python environment access","snippet":"environment = os.environ.copy()","category":"env_access","line_end":1379,"severity":"low","line_start":1379},{"id":"env_access:runtime/scripts/evidence_receipt.py:1115:python-environment-access","file":"runtime/scripts/evidence_receipt.py","pattern":"Python environment access","snippet":"if name in os.environ:","category":"env_access","line_end":1115,"severity":"low","line_start":1115},{"id":"env_access:runtime/scripts/evidence_receipt.py:1117:python-environment-access","file":"runtime/scripts/evidence_receipt.py","pattern":"Python environment access","snippet":"(os.fsencode(name), b\"\\0\", os.fsencode(os.environ[name]), b\"\\0\")","category":"env_access","line_end":1117,"severity":"low","line_start":1117},{"id":"env_access:runtime/scripts/evidence_receipt.py:1521:python-environment-access","file":"runtime/scripts/evidence_receipt.py","pattern":"Python environment access","snippet":"os.execvpe(command[0], command, dict(os.environ))","category":"env_access","line_end":1521,"severity":"low","line_start":1521},{"id":"env_access:runtime/scripts/feedback-triage.py:360:python-environment-access","file":"runtime/scripts/feedback-triage.py","pattern":"Python environment access","snippet":"environment = os.environ.copy()","category":"env_access","line_end":360,"severity":"low","line_start":360},{"id":"env_access:runtime/scripts/model_selection.py:98:python-environment-access","file":"runtime/scripts/model_selection.py","pattern":"Python environment access","snippet":"environment = {name: os.environ[name] for name in allowed if name in os.environ}","category":"env_access","line_end":98,"severity":"low","line_start":98},{"id":"env_access:runtime/scripts/workflow.py:711:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"configured = os.environ.get(\"XDG_STATE_HOME\")","category":"env_access","line_end":711,"severity":"low","line_start":711},{"id":"env_access:runtime/scripts/workflow.py:718:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"home_text = os.environ.get(\"HOME\")","category":"env_access","line_end":718,"severity":"low","line_start":718},{"id":"env_access:runtime/scripts/workflow.py:750:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"environment = dict(os.environ)","category":"env_access","line_end":750,"severity":"low","line_start":750},{"id":"env_access:runtime/scripts/workflow.py:1115:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"env = dict(os.environ)","category":"env_access","line_end":1115,"severity":"low","line_start":1115},{"id":"env_access:runtime/scripts/workflow.py:1186:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"os.environ.get(\"AGY_WORKER_LOG_DIR\") or (state_path.parent / \"logs\")","category":"env_access","line_end":1186,"severity":"low","line_start":1186},{"id":"env_access:runtime/scripts/workflow.py:1598:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"os.environ.get(\"AGY_WORKER_LOG_DIR\") or (SCRIPTS.parent / \"logs\")","category":"env_access","line_end":1598,"severity":"low","line_start":1598},{"id":"filesystem:runtime/qa-gate.sh:434:python-glob-pattern-matching","file":"runtime/qa-gate.sh","pattern":"Python glob/pattern matching","snippet":"import fnmatch","category":"filesystem","line_end":434,"severity":"low","line_start":434},{"id":"filesystem:runtime/qa-gate.sh:513:python-glob-pattern-matching","file":"runtime/qa-gate.sh","pattern":"Python glob/pattern matching","snippet":"if not any(fnmatch.fnmatchcase(path, pattern) for pattern in allow)","category":"filesystem","line_end":513,"severity":"low","line_start":513},{"id":"filesystem:runtime/qa-gate.sh:518:python-glob-pattern-matching","file":"runtime/qa-gate.sh","pattern":"Python glob/pattern matching","snippet":"if only and not any(fnmatch.fnmatchcase(path, pattern) for pattern in only)","category":"filesystem","line_end":518,"severity":"low","line_start":518},{"id":"network:runtime/scripts/codex_usage_report.py:726:python-http-libraries","file":"runtime/scripts/codex_usage_report.py","pattern":"Python HTTP libraries","snippet":"pending_requests.pop(resp_id, None)","category":"network","line_end":726,"severity":"low","line_start":726},{"id":"filesystem:runtime/agy-worker.sh:237:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\" || exit 64","category":"filesystem","line_end":237,"severity":"low","line_start":237},{"id":"filesystem:runtime/agy-worker.sh:663:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"prospective_workdir=\"$(CDPATH= cd -- \"$workdir\" 2>/dev/null && pwd -P)\" || {","category":"filesystem","line_end":663,"severity":"low","line_start":663},{"id":"filesystem:runtime/agy-worker.sh:673:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"mkdir -p \"$LOG_DIR\" 2>/dev/null || {","category":"filesystem","line_end":673,"severity":"low","line_start":673},{"id":"filesystem:runtime/agy-worker.sh:685:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"if ! LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\"; then","category":"filesystem","line_end":685,"severity":"low","line_start":685},{"id":"filesystem:runtime/agy-worker.sh:897:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"if ! mkdir \"$job_dir\" 2>/dev/null; then","category":"filesystem","line_end":897,"severity":"low","line_start":897},{"id":"filesystem:runtime/agy-worker.sh:1011:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"--observe-installed-version 2>/dev/null)\"","category":"filesystem","line_end":1011,"severity":"low","line_start":1011},{"id":"filesystem:runtime/agy-worker.sh:1030:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"--verify-record-executable \"$selection_file\" > /dev/null 2>&1","category":"filesystem","line_end":1030,"severity":"low","line_start":1030},{"id":"filesystem:runtime/agy-worker.sh:1200:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"chmod 0700 \"$staged_dir\" 2>/dev/null || true","category":"filesystem","line_end":1200,"severity":"low","line_start":1200},{"id":"filesystem:runtime/agy-worker.sh:1201:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"[[ ! -f \"$staged_prompt_file\" ]] || chmod 0600 \"$staged_prompt_file\" 2>/dev/null || true","category":"filesystem","line_end":1201,"severity":"low","line_start":1201},{"id":"filesystem:runtime/doctor.sh:21:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"*) source_path=\"$(command -v -- \"$source_path\" 2>/dev/null || true)\" ;;","category":"filesystem","line_end":21,"severity":"low","line_start":21},{"id":"filesystem:runtime/doctor.sh:24:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"CDPATH= cd -- \"${source_path%/*}\" 2>/dev/null && pwd -P","category":"filesystem","line_end":24,"severity":"low","line_start":24},{"id":"filesystem:runtime/doctor.sh:32:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"runtime_canonical=\"$(CDPATH= cd -- \"$runtime_root\" 2>/dev/null && pwd -P)\" \\","category":"filesystem","line_end":32,"severity":"low","line_start":32},{"id":"filesystem:runtime/doctor.sh:38:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":38,"severity":"low","line_start":38},{"id":"filesystem:runtime/doctor.sh:86:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":86,"severity":"low","line_start":86},{"id":"filesystem:runtime/doctor.sh:147:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":147,"severity":"low","line_start":147},{"id":"filesystem:runtime/doctor.sh:156:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"&& \"$(/usr/bin/stat -f '%Lp' \"$dependency_canonical\" 2>/dev/null \\","category":"filesystem","line_end":156,"severity":"low","line_start":156},{"id":"filesystem:runtime/doctor.sh:157:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"|| /usr/bin/stat -c '%a' \"$dependency_canonical\" 2>/dev/null)\" == 644 ]] || return 1","category":"filesystem","line_end":157,"severity":"low","line_start":157},{"id":"filesystem:runtime/doctor.sh:172:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"CDPATH= cd -- \"$1\" 2>/dev/null && pwd -P","category":"filesystem","line_end":172,"severity":"low","line_start":172},{"id":"filesystem:runtime/doctor.sh:198:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null || cleanup_failed=1","category":"filesystem","line_end":198,"severity":"low","line_start":198},{"id":"filesystem:runtime/doctor.sh:199:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"/bin/rmdir \"$workspace\" 2>/dev/null || cleanup_failed=1","category":"filesystem","line_end":199,"severity":"low","line_start":199},{"id":"filesystem:runtime/doctor.sh:225:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"\"$base_dir/agy-worker-doctor.XXXXXX\" 2>/dev/null)\"","category":"filesystem","line_end":225,"severity":"low","line_start":225},{"id":"filesystem:runtime/doctor.sh:230:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"/bin/chmod 700 \"$workspace\" 2>/dev/null || {","category":"filesystem","line_end":230,"severity":"low","line_start":230},{"id":"filesystem:runtime/doctor.sh:231:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"/bin/rmdir \"$workspace\" 2>/dev/null || true","category":"filesystem","line_end":231,"severity":"low","line_start":231},{"id":"filesystem:scripts/resolve-pipeline.sh:12:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"pipeline_root=\"$(CDPATH= cd -- \"$1\" 2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":12,"severity":"low","line_start":12},{"id":"filesystem:scripts/resolve-pipeline.sh:20:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":20,"severity":"low","line_start":20},{"id":"filesystem:scripts/resolve-pipeline.sh:40:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"runtime_canonical=\"$(CDPATH= cd -- \"$runtime_root\" 2>/dev/null && pwd -P)\" \\","category":"filesystem","line_end":40,"severity":"low","line_start":40},{"id":"filesystem:scripts/resolve-pipeline.sh:46:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":46,"severity":"low","line_start":46},{"id":"filesystem:scripts/resolve-pipeline.sh:94:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":94,"severity":"low","line_start":94},{"id":"filesystem:scripts/resolve-pipeline.sh:155:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":155,"severity":"low","line_start":155},{"id":"filesystem:scripts/resolve-pipeline.sh:164:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"&& \"$(/usr/bin/stat -f '%Lp' \"$dependency_canonical\" 2>/dev/null \\","category":"filesystem","line_end":164,"severity":"low","line_start":164},{"id":"filesystem:scripts/resolve-pipeline.sh:165:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"|| /usr/bin/stat -c '%a' \"$dependency_canonical\" 2>/dev/null)\" == 644 ]] || return 1","category":"filesystem","line_end":165,"severity":"low","line_start":165},{"id":"filesystem:scripts/resolve-pipeline.sh:169:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"PLUGIN_ROOT=\"$(CDPATH= cd -- \"$SKILL_DIR/../..\" 2>/dev/null && pwd -P)\" || PLUGIN_ROOT=\"\"","category":"filesystem","line_end":169,"severity":"low","line_start":169},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:49:temp-file-creation","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Temp file creation","snippet":"STATE_DIR=\"$(mktemp -d -t agyworker-state.XXXXXX)\"","category":"filesystem","line_end":49,"severity":"low","line_start":49},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:50:temp-file-creation","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Temp file creation","snippet":"WT=\"$(mktemp -d -t agyworker-worktree.XXXXXX)\"","category":"filesystem","line_end":50,"severity":"low","line_start":50},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:212:temp-file-creation","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Temp file creation","snippet":"VERIFY_PARENT=\"$(mktemp -d -t agyworker-verify.XXXXXX)\" || exit $?","category":"filesystem","line_end":212,"severity":"low","line_start":212},{"id":"filesystem:runtime/doctor.sh:224:temp-file-creation","file":"runtime/doctor.sh","pattern":"Temp file creation","snippet":"workspace=\"$(/usr/bin/mktemp -d \\","category":"filesystem","line_end":224,"severity":"low","line_start":224},{"id":"filesystem:runtime/qa-gate.sh:314:temp-file-creation","file":"runtime/qa-gate.sh","pattern":"Temp file creation","snippet":"workspace=\"$(/usr/bin/mktemp -d \\","category":"filesystem","line_end":314,"severity":"low","line_start":314},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:814:temp-file-creation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Temp file creation","snippet":"# `mktemp` commonly returns /var/... on macOS while","category":"filesystem","line_end":814,"severity":"low","line_start":814},{"id":"filesystem:runtime/scripts/benchmark.py:24:temp-file-creation","file":"runtime/scripts/benchmark.py","pattern":"Temp file creation","snippet":"import tempfile","category":"filesystem","line_end":24,"severity":"low","line_start":24},{"id":"filesystem:runtime/scripts/benchmark.py:756:temp-file-creation","file":"runtime/scripts/benchmark.py","pattern":"Temp file creation","snippet":"work = Path(tempfile.mkdtemp(prefix=\"agy-benchmark.\", dir=str(root)))","category":"filesystem","line_end":756,"severity":"low","line_start":756},{"id":"filesystem:runtime/scripts/codex_usage_report.py:31:temp-file-creation","file":"runtime/scripts/codex_usage_report.py","pattern":"Temp file creation","snippet":"import tempfile","category":"filesystem","line_end":31,"severity":"low","line_start":31},{"id":"filesystem:runtime/scripts/codex_usage_report.py:221:temp-file-creation","file":"runtime/scripts/codex_usage_report.py","pattern":"Temp file creation","snippet":"with tempfile.TemporaryDirectory(prefix=\"agy-codex-schema-\") as temp_dir:","category":"filesystem","line_end":221,"severity":"low","line_start":221},{"id":"filesystem:runtime/scripts/job_lifecycle.py:26:temp-file-creation","file":"runtime/scripts/job_lifecycle.py","pattern":"Temp file creation","snippet":"import tempfile","category":"filesystem","line_end":26,"severity":"low","line_start":26},{"id":"filesystem:runtime/scripts/job_lifecycle.py:837:temp-file-creation","file":"runtime/scripts/job_lifecycle.py","pattern":"Temp file creation","snippet":"directory = Path(tempfile.mkdtemp(prefix=\"agy-worker-empty-hooks.\", dir=\"/tmp\"))","category":"filesystem","line_end":837,"severity":"low","line_start":837}],"finding_verdicts":[{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2581:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2597:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:430:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:457:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:470:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:489:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:501:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:510:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:512:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:524:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:530:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:539:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:546:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:587:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:607:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:613:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:628:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:667:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:695:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:729:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:784:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:832:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:930:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:939:certificate-key-files","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/SECURITY_AND_COMPATIBILITY.md:26:crypto-seed-private-key-mention","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:53:crypto-seed-private-key-mention","reason":"The reported lines compare allowed schema keys and fields; they do not contain certificate or private-key material. No evidence found that these checks read or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/benchmarks/v1/portable-source.json:1:heuristic-extremely-long-line-2076-chars-likely-","reason":"The location is a compact JSON manifest or schema stored on one line. Compact structured data is not evidence of an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-advisory.schema.json:1:heuristic-extremely-long-line-2424-chars-likely-","reason":"The location is a compact JSON manifest or schema stored on one line. Compact structured data is not evidence of an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-plan.schema.json:1:heuristic-extremely-long-line-2929-chars-likely-","reason":"The location is a compact JSON manifest or schema stored on one line. Compact structured data is not evidence of an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/schemas/benchmark-result.schema.json:1:heuristic-extremely-long-line-3160-chars-likely-","reason":"The location is a compact JSON manifest or schema stored on one line. Compact structured data is not evidence of an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-report.schema.json:1:heuristic-extremely-long-line-6721-chars-likely-","reason":"The location is a compact JSON manifest or schema stored on one line. Compact structured data is not evidence of an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/schemas/benchmark-plan.schema.json:1:heuristic-extremely-long-line-7848-chars-likely-","reason":"The location is a compact JSON manifest or schema stored on one line. Compact structured data is not evidence of an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:1:heuristic-multiple-bracket-chains-20-jsfuck-obfu","reason":"The reported brackets are nested JSON schema syntax or ordinary Python grouping. The snippets do not show JSFuck or hidden executable content.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/schemas/model-selection.schema.json:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","reason":"The reported brackets are nested JSON schema syntax or ordinary Python grouping. The snippets do not show JSFuck or hidden executable content.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","reason":"The reported brackets are nested JSON schema syntax or ordinary Python grouping. The snippets do not show JSFuck or hidden executable content.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/evidence_report.py:131:heuristic-very-high-entropy-string-6-02-bits-lik","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2563:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2605:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:723:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:1361:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2581:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2702:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2709:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/compatibility.py:174:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/evidence_report.py:145:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/job_lifecycle.py:392:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/model_selection.py:625:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/model_selection.py:640:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:runtime/scripts/swebench_workflow_study.py:58:hex-encoded-characters","reason":"The high-entropy match is a visible alphanumeric filename-character alphabet. It is a normal validation constant, not an encoded payload.","verdict":"false_positive","confidence":0.98},{"id":"env_access:runtime/qa-gate.sh:120:database-connection-strings","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/evidence_receipt.py:955:database-connection-strings","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-in-home-directory","reason":"The match is documentation or package-marker discovery, not an attempt to search hidden user data. The only actual settings read is separately confirmed at the account inspection line.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-in-home-directory","reason":"The account phase reads ~/.gemini/antigravity-cli/settings.json and reports its permission configuration. This is an intentional account inspection, but it accesses user-owned configuration outside the worktree.","verdict":"confirmed","severity":"high","confidence":0.94},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2559:hidden-file-in-home-directory","reason":"The match is documentation or package-marker discovery, not an attempt to search hidden user data. The only actual settings read is separately confirmed at the account inspection line.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:416:non-standard-device-file-access","reason":"The /dev/fd reference is used for controlled descriptor handling in containment logic. No evidence found of access to an attacker-selected device.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:177:path-traversal-sequence","reason":"The sequence appears in documentation, path validation, or a controlled package-root resolution. The code rejects traversal and absolute paths rather than using them as an escape vector.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:runtime/qa-gate.sh:472:path-traversal-sequence","reason":"The sequence appears in documentation, path validation, or a controlled package-root resolution. The code rejects traversal and absolute paths rather than using them as an escape vector.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:2610:path-traversal-sequence","reason":"The sequence appears in documentation, path validation, or a controlled package-root resolution. The code rejects traversal and absolute paths rather than using them as an escape vector.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3490:path-traversal-sequence","reason":"The sequence appears in documentation, path validation, or a controlled package-root resolution. The code rejects traversal and absolute paths rather than using them as an escape vector.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:scripts/resolve-pipeline.sh:169:path-traversal-sequence","reason":"The sequence appears in documentation, path validation, or a controlled package-root resolution. The code rejects traversal and absolute paths rather than using them as an escape vector.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:377:process-exec","reason":"The match is either a policy string or execution of a path-pinned bundled helper. It is not evidence that arbitrary provider text is evaluated as Python code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:2887:process-exec","reason":"The match is either a policy string or execution of a path-pinned bundled helper. It is not evidence that arbitrary provider text is evaluated as Python code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:5617:process-spawn","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6100:process-spawn","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6254:process-spawn","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6256:process-spawn","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6260:process-spawn","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6266:process-spawn","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"scripts:runtime/agy-worker.sh:1430:python-import-function","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/agy-worker.sh:1431:python-import-function","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/agy-worker.sh:1443:python-import-function","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/agy-worker.sh:1446:python-import-function","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/agy-worker.sh:1457:python-import-function","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/agy-worker.sh:1478:python-import-function","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/agy_dispatch_containment.py:377:python-exec-function","reason":"The match is either a policy string or execution of a path-pinned bundled helper. It is not evidence that arbitrary provider text is evaluated as Python code.","verdict":"false_positive","confidence":0.9},{"id":"scripts:runtime/scripts/agy_dispatch.py:2887:python-exec-function","reason":"The match is either a policy string or execution of a path-pinned bundled helper. It is not evidence that arbitrary provider text is evaluated as Python code.","verdict":"false_positive","confidence":0.9},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:674:python-globals-manipulation","reason":"The globals lookup dispatches names from an internal implementation allowlist. No evidence found that arbitrary caller input selects an unvalidated function.","verdict":"false_positive","confidence":0.92},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:4215:python-globals-manipulation","reason":"The globals lookup dispatches names from an internal implementation allowlist. No evidence found that arbitrary caller input selects an unvalidated function.","verdict":"false_positive","confidence":0.92},{"id":"scripts:runtime/scripts/agy_dispatch.py:46:python-globals-manipulation","reason":"The globals lookup dispatches names from an internal implementation allowlist. No evidence found that arbitrary caller input selects an unvalidated function.","verdict":"false_positive","confidence":0.92},{"id":"scripts:runtime/scripts/agy_dispatch.py:3157:python-globals-manipulation","reason":"The globals lookup dispatches names from an internal implementation allowlist. No evidence found that arbitrary caller input selects an unvalidated function.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1521:python-os-exec-variants","reason":"The process replacement receives an argv record after verifier validation and runs with a sanitized environment. It does not invoke a shell or accept an unvalidated command string.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:94:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:205:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:238:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:244:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1396:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1414:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3914:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3978:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4234:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4608:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:5635:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:5652:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/benchmark.py:135:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/benchmark.py:581:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/benchmark.py:594:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/benchmark.py:606:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/benchmark.py:615:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/codex_usage_report.py:115:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/codex_usage_report.py:157:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/codex_usage_report.py:647:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/doctor-metadata.py:92:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/doctor-metadata.py:129:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/doctor-metadata.py:142:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1132:python-subprocess-popen","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/qa-gate.sh:447:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3358:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3636:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4209:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4214:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6046:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/benchmark.py:347:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/candidate_state.py:30:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/evidence_receipt.py:468:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:493:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:544:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:576:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:762:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:784:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:1121:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:1800:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:runtime/scripts/workflow.py:1854:python-subprocess-run","reason":"The process launch is part of the controller, contained verifier, bounded Git, or schema-validation workflow. Arguments, working directories, and environments are bound or sanitized rather than taken from arbitrary provider output.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3504:symlink-creation","reason":"The symlink is created during controlled candidate reconciliation with no-follow checks and contained paths. The finding does not show an escape from the approved worktree.","verdict":"false_positive","confidence":0.9},{"id":"scripts:runtime/scripts/benchmark.py:88:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/benchmark.py:97:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/evidence_receipt.py:29:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/evidence_receipt.py:38:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/evidence_report.py:25:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/evidence_report.py:35:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/job_lifecycle.py:35:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/job_lifecycle.py:39:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/job_lifecycle.py:45:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"scripts:runtime/scripts/model-recommendation.py:12:dynamic-import-expression","reason":"The reported code uses imports for bundled runtime modules or standard-library helpers. It does not evaluate a caller-controlled module name.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:runtime/scripts/benchmark.py:420:hard-link-creation","reason":"The hard-link operations are part of temporary-file and atomic-copy safeguards, with no-follow and identity checks. They do not expose a credential or bypass the stated worktree boundary.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/evidence_receipt.py:882:hard-link-creation","reason":"The hard-link operations are part of temporary-file and atomic-copy safeguards, with no-follow and identity checks. They do not expose a credential or bypass the stated worktree boundary.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/evidence_report.py:341:hard-link-creation","reason":"The hard-link operations are part of temporary-file and atomic-copy safeguards, with no-follow and identity checks. They do not expose a credential or bypass the stated worktree boundary.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/model_evidence_campaign.py:355:hard-link-creation","reason":"The hard-link operations are part of temporary-file and atomic-copy safeguards, with no-follow and identity checks. They do not expose a credential or bypass the stated worktree boundary.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/swebench_workflow_study.py:277:hard-link-creation","reason":"The hard-link operations are part of temporary-file and atomic-copy safeguards, with no-follow and identity checks. They do not expose a credential or bypass the stated worktree boundary.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-access","reason":"The match is documentation or package-marker discovery, not an attempt to search hidden user data. The only actual settings read is separately confirmed at the account inspection line.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-access","reason":"The account phase reads ~/.gemini/antigravity-cli/settings.json and reports its permission configuration. This is an intentional account inspection, but it accesses user-owned configuration outside the worktree.","verdict":"confirmed","severity":"high","confidence":0.94},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2559:hidden-file-access","reason":"The match is documentation or package-marker discovery, not an attempt to search hidden user data. The only actual settings read is separately confirmed at the account inspection line.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:scripts/resolve-pipeline.sh:171:hidden-file-access","reason":"The match is documentation or package-marker discovery, not an attempt to search hidden user data. The only actual settings read is separately confirmed at the account inspection line.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:scripts/resolve-pipeline.sh:177:hidden-file-access","reason":"The match is documentation or package-marker discovery, not an attempt to search hidden user data. The only actual settings read is separately confirmed at the account inspection line.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:runtime/scripts/model_selection.py:1270:python-file-write-append","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:939:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:268:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3479:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3481:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3482:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3517:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3519:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4055:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4067:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4169:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4171:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4177:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3440:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3551:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:427:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:441:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:465:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:757:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:770:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/codex_usage_report.py:223:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/evidence_report.py:263:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/evidence_report.py:353:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/job_lifecycle.py:690:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/job_lifecycle.py:839:python-os-file-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3447:python-shutil-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3505:python-shutil-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3511:python-shutil-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3545:python-shutil-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:740:python-shutil-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/job_lifecycle.py:851:python-shutil-operations","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/agy-worker.sh:14:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:15:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:1262:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:1263:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:1300:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:5:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:6:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:8:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:13:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:14:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:74:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:75:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:76:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:80:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:81:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:85:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:92:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:9:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:11:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:308:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:534:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:616:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:690:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:692:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:README.md:56:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:39:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:48:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:49:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:50:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:212:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:213:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:244:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:245:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:25:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:30:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:237:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:464:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:473:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:497:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:498:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:499:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:603:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:604:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:649:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:650:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:651:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:652:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:663:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:685:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:690:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:692:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:696:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:720:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:901:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:980:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:1009:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/agy-worker.sh:1043:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:6:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:7:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:12:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:19:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:40:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:45:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:93:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:154:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:164:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/resolve-pipeline.sh:169:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:21:shell-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:42:temp-directory-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/agy-worker.sh:15:template-literal-with-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/ground-truth.sh:14:template-literal-with-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:20:template-literal-with-command-substitution","reason":"The match is a documented shell command example or comment in the skill package. It is not an executed payload in the reported location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:runtime/qa-gate.sh:623:unix-shell-invocation","reason":"The legacy shell verifier executes verify_specs through /bin/bash -c. An untrusted verifier specification can therefore run arbitrary commands, even though this mode is explicitly selected by the driver.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:runtime/qa-gate.sh:639:unix-shell-invocation","reason":"The legacy shell verifier executes verify_specs through /bin/bash -c. An untrusted verifier specification can therefore run arbitrary commands, even though this mode is explicitly selected by the driver.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:27:unix-shell-invocation","reason":"This shell reference is a fixed supervisor, verifier allowlist, or script launch outside the two confirmed legacy verifier execution sites. The surrounding code binds the executable and environment.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1416:unix-shell-invocation","reason":"This shell reference is a fixed supervisor, verifier allowlist, or script launch outside the two confirmed legacy verifier execution sites. The surrounding code binds the executable and environment.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1146:unix-shell-invocation","reason":"This shell reference is a fixed supervisor, verifier allowlist, or script launch outside the two confirmed legacy verifier execution sites. The surrounding code binds the executable and environment.","verdict":"false_positive","confidence":0.84},{"id":"blocker:runtime/agy-worker.sh:154:network-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:63:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:80:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:169:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:171:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:215:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:244:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:279:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/TROUBLESHOOTING.md:54:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/TROUBLESHOOTING.md:65:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/TROUBLESHOOTING.md:88:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/TROUBLESHOOTING.md:96:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/TROUBLESHOOTING.md:100:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/TROUBLESHOOTING.md:139:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/TROUBLESHOOTING.md:141:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agents/bulk-test-writer.md:46:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agents/diff-reviewer.md:34:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agents/repo-inventory.md:40:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:2:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:79:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:82:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:85:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:134:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:135:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:136:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:137:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:138:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:139:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:140:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:141:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:143:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:144:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:145:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:155:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:157:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:163:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:166:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:167:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:runtime/agy-worker.sh:221:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"blocker:scripts/resolve-pipeline.sh:183:system-reconnaissance","reason":"The match occurs in operational documentation or status text describing repository and job handling. It is not an implemented reconnaissance action.","verdict":"false_positive","confidence":0.98},{"id":"env_access:runtime/scripts/agy_dispatch_verification.py:151:configuration-library","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"network:runtime/compat/agy-version-manifest.json:20:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/compat/agy-version-manifest.json:65:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/compat/agy-version-manifest.json:85:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/compat/agy-version-manifest.json:111:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/compat/agy-version-manifest.json:159:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/compat/model-effort-matrix.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/compat/model-effort-matrix.schema.json:3:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/compat/version-manifest.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/benchmark-plan.schema.json:1:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/benchmark-result.schema.json:1:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/delegation-policy.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/evidence-receipt.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/job-state.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-preview.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-evaluation.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-plan.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-record.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-evidence-campaign-record.schema.json:156:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-intelligence-advisory.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-intelligence-evidence.schema.json:2:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/schemas/model-intelligence-evidence.schema.json:85:hardcoded-url","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/agy_dispatch_worktree.py:1379:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/evidence_receipt.py:1115:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/evidence_receipt.py:1117:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/evidence_receipt.py:1521:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/feedback-triage.py:360:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/model_selection.py:98:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/workflow.py:711:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/workflow.py:718:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/workflow.py:750:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/workflow.py:1115:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/workflow.py:1186:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"env_access:runtime/scripts/workflow.py:1598:python-environment-access","reason":"The snippet handles a documented allowlist of environment names or copies a filtered environment for a child process. No evidence found that it harvests arbitrary secrets.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:runtime/qa-gate.sh:434:python-glob-pattern-matching","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/qa-gate.sh:513:python-glob-pattern-matching","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/qa-gate.sh:518:python-glob-pattern-matching","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"network:runtime/scripts/codex_usage_report.py:726:python-http-libraries","reason":"The URL or HTTP match is a documented schema, GitHub release, Google distribution endpoint, or status integration. No evidence found of a covert destination or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:237:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:663:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:673:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:685:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:897:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:1011:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:1030:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:1200:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/agy-worker.sh:1201:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:21:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:24:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:32:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:38:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:86:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:147:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:156:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:157:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:172:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:198:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:199:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:225:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:230:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:231:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:12:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:20:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:40:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:46:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:94:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:155:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:164:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:165:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:scripts/resolve-pipeline.sh:169:standard-device-file-access","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:49:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:50:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:212:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/doctor.sh:224:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/qa-gate.sh:314:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:814:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:24:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/benchmark.py:756:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/codex_usage_report.py:31:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/codex_usage_report.py:221:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/job_lifecycle.py:26:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/job_lifecycle.py:837:temp-file-creation","reason":"The operation supports private temporary state, bounded copying, cleanup, or path matching in the worker lifecycle. The surrounding design uses owner-private directories and containment checks.","verdict":"false_positive","confidence":0.9}],"semantic_findings":[{"title":"Unconfined Provider Execution","severity":"high","locations":[{"file":"SKILL.md","line_end":51,"line_start":49}],"confidence":0.99,"description":"The skill states that whole-worktree content may be transmitted to Google or Gemini and that session mode gives AGY normal user filesystem and network authority. A provider task can therefore affect or disclose resources beyond the intended worktree unless the operator uses scoped content and stronger containment.","confidence_reasoning":"The documented execution boundary explicitly says the entire worktree may be readable and transmissible, while session mode has no AGY sandbox or native host containment."}],"subject_marketplace_commit_sha":"e5464e662405de6361fdde6b984f9ea865635f64","subject_content_hash":"3d138378c67980113003cc9307c51d1b54cf24091ed95b0b2ee7d88174247bee","subject_tree_hash":"ae8aee1e8340badcb3d529ebcf1a879dc8cebb6f4145f9acdf9a97d4ce8fab83","subject_plugin_path":"skills/cagdasyurekli/agy-worker","audit_payload_hash":"62a79c7608d1f13565f15b5e2679599b","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"e5464e662405de6361fdde6b984f9ea865635f64","contentHash":"3d138378c67980113003cc9307c51d1b54cf24091ed95b0b2ee7d88174247bee","treeHash":"ae8aee1e8340badcb3d529ebcf1a879dc8cebb6f4145f9acdf9a97d4ce8fab83","pluginPath":"skills/cagdasyurekli/agy-worker","auditPayloadHash":"62a79c7608d1f13565f15b5e2679599b"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/cagdasyurekli-agy-worker/audits/5/attestation","status":"superseded"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":4,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"superseded","verificationState":"not_verified"},"isLatest":false}}