{"data":{"skill":{"slug":"cagdasyurekli-agy-worker","name":"agy-worker","icon":"📦","repo":"https://github.com/cagdasyurekli/codex-agy-worker/tree/3da9a50afaa66492dd77f23f92c6ed4f84be4ada/skills/agy-worker","status":"approved","author":"cagdasyurekli","authorVersion":"0.20.0","skillstoreRevision":7},"audit":{"id":"9d825e56-b434-4504-a8da-d59303dd32a6","skill_id":"466f2750-44a5-4d4f-8709-a2494454b27b","version":7,"content_hash":"v3:7b5f6226ad3dfaed7068a68fb47e33a511a95cb3:6265484dddafa504df20fa1cc2033d6bbd7243ada5189f892ddd42973c8285e4:5ed1e9b7a5b0bbee6ff0542508a6ab17283522e7e176033e7531146657f8bd2c:736b696c6c732f636167646173797572656b6c692f6167792d776f726b6572:2b712c7cff30f18b62689fab595c5377","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"The review confirmed intentional high-impact capabilities: external provider execution, repository-content transmission, verifier command execution, and limited private configuration access. Most static matches are false positives from defensive validation, documentation, compact schemas, or fixed local commands. Default session mode lacks host containment, and 589 lower-priority static matches remain outside the supplied adjudication set. Static review was capped at 400/989 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.","remediation":[{"issue":"Static review capped","severity":"medium","suggestion":"Manually review the omitted 589 static analyzer matches or reduce bundled generated/vendor/reference content before enabling automatic publication."},{"issue":"Session isolation is the default despite retaining normal user filesystem and network authority.","severity":"high","suggestion":"Default to native or equivalent containment where supported. Require a separate prominent confirmation when session mode is selected."},{"issue":"Whole-worktree approval can expose unrelated repository content to the external provider.","severity":"high","suggestion":"Disable whole-worktree dispatch in the marketplace build, or require scoped manifests unless every path receives explicit review."},{"issue":"Legacy shell verification executes caller-selected text through bash.","severity":"high","suggestion":"Remove shell mode from the default workflow. Prefer validated argv verification and require a separate warning for any retained shell mode."},{"issue":"Native mode grants the security helper broader Keychain operations than token lookup requires.","severity":"high","suggestion":"Replace helper access with a least-privilege credential handoff that cannot add, modify, delete, or enumerate unrelated Keychain items."},{"issue":"Static review was capped at 400 of 989 matches.","severity":"high","suggestion":"Complete manual review of the remaining 589 matches before automatic publication or installation is enabled."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"README.md","line_end":56,"line_start":56},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":71,"line_start":71},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":80,"line_start":80},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":81,"line_start":81},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":82,"line_start":82},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":251,"line_start":251},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":252,"line_start":252},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":286,"line_start":286},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":289,"line_start":287},{"file":"runtime/agy-worker.sh","line_end":14,"line_start":14},{"file":"runtime/agy-worker.sh","line_end":15,"line_start":15},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":1262},{"file":"runtime/agy-worker.sh","line_end":1263,"line_start":1263},{"file":"runtime/agy-worker.sh","line_end":1300,"line_start":1300},{"file":"runtime/agy-worker.sh","line_end":25,"line_start":25},{"file":"runtime/agy-worker.sh","line_end":30,"line_start":30},{"file":"runtime/agy-worker.sh","line_end":237,"line_start":237},{"file":"runtime/agy-worker.sh","line_end":464,"line_start":464},{"file":"runtime/agy-worker.sh","line_end":475,"line_start":473},{"file":"runtime/agy-worker.sh","line_end":497,"line_start":497},{"file":"runtime/agy-worker.sh","line_end":498,"line_start":498},{"file":"runtime/agy-worker.sh","line_end":499,"line_start":499},{"file":"runtime/agy-worker.sh","line_end":603,"line_start":603},{"file":"runtime/agy-worker.sh","line_end":604,"line_start":604},{"file":"runtime/agy-worker.sh","line_end":649,"line_start":649},{"file":"runtime/agy-worker.sh","line_end":650,"line_start":650},{"file":"runtime/agy-worker.sh","line_end":651,"line_start":651},{"file":"runtime/agy-worker.sh","line_end":652,"line_start":652},{"file":"runtime/agy-worker.sh","line_end":663,"line_start":663},{"file":"runtime/agy-worker.sh","line_end":685,"line_start":685},{"file":"runtime/agy-worker.sh","line_end":690,"line_start":690},{"file":"runtime/agy-worker.sh","line_end":692,"line_start":692},{"file":"runtime/agy-worker.sh","line_end":696,"line_start":696},{"file":"runtime/agy-worker.sh","line_end":725,"line_start":720},{"file":"runtime/agy-worker.sh","line_end":906,"line_start":901},{"file":"runtime/agy-worker.sh","line_end":980,"line_start":980},{"file":"runtime/agy-worker.sh","line_end":1011,"line_start":1009},{"file":"runtime/agy-worker.sh","line_end":1054,"line_start":1043},{"file":"runtime/agy-worker.sh","line_end":1225,"line_start":1225},{"file":"runtime/agy-worker.sh","line_end":1226,"line_start":1226},{"file":"runtime/agy-worker.sh","line_end":1306,"line_start":1306},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":15},{"file":"runtime/benchmark.sh","line_end":5,"line_start":5},{"file":"runtime/codex-usage-report.sh","line_end":5,"line_start":5},{"file":"runtime/delegation-policy.sh","line_end":5,"line_start":5},{"file":"runtime/doctor.sh","line_end":21,"line_start":21},{"file":"runtime/doctor.sh","line_end":32,"line_start":32},{"file":"runtime/doctor.sh","line_end":38,"line_start":37},{"file":"runtime/doctor.sh","line_end":86,"line_start":85},{"file":"runtime/doctor.sh","line_end":147,"line_start":146}]},{"factor":"network","evidence":[{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":25,"line_start":25},{"file":"runtime/compat/agy-version-manifest.json","line_end":20,"line_start":20},{"file":"runtime/compat/agy-version-manifest.json","line_end":64,"line_start":64},{"file":"runtime/compat/agy-version-manifest.json","line_end":111,"line_start":111},{"file":"runtime/compat/agy-version-manifest.json","line_end":163,"line_start":163},{"file":"runtime/compat/agy-version-manifest.json","line_end":212,"line_start":212},{"file":"runtime/compat/agy-version-manifest.json","line_end":257,"line_start":257},{"file":"runtime/compat/agy-version-manifest.json","line_end":277,"line_start":277},{"file":"runtime/compat/agy-version-manifest.json","line_end":303,"line_start":303},{"file":"runtime/compat/agy-version-manifest.json","line_end":347,"line_start":347},{"file":"runtime/compat/model-effort-matrix.schema.json","line_end":2,"line_start":2},{"file":"runtime/compat/model-effort-matrix.schema.json","line_end":3,"line_start":3},{"file":"runtime/compat/version-manifest.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/benchmark-plan.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/benchmark-result.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/delegation-policy.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/evidence-receipt.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/job-state.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-advisory-preview.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-advisory-summary.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-aggregate.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-evaluation.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-plan.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-record.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-evidence-campaign-record.schema.json","line_end":156,"line_start":156},{"file":"runtime/schemas/model-intelligence-advisory.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-intelligence-evidence.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-intelligence-evidence.schema.json","line_end":85,"line_start":85},{"file":"runtime/schemas/model-recommendation.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/model-selection.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/swebench-workflow-study-advisory.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/swebench-workflow-study-report.schema.json","line_end":1,"line_start":1},{"file":"runtime/schemas/worker-result.provider.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/worker-result.schema.json","line_end":2,"line_start":2},{"file":"runtime/schemas/workflow-state.schema.json","line_end":2,"line_start":2},{"file":"runtime/scripts/codex_usage_report.py","line_end":726,"line_start":726},{"file":"runtime/scripts/compatibility.py","line_end":245,"line_start":245},{"file":"runtime/scripts/compatibility.py","line_end":246,"line_start":246},{"file":"runtime/scripts/feedback-triage.py","line_end":31,"line_start":31},{"file":"runtime/scripts/model_evidence_campaign.py","line_end":28,"line_start":28},{"file":"runtime/scripts/model_intelligence.py","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":36,"line_start":36}]},{"factor":"filesystem","evidence":[{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":81,"line_start":81},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":82,"line_start":82},{"file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","line_end":251,"line_start":251},{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":204,"line_start":204},{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":42,"line_start":42},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":1262},{"file":"runtime/agy-worker.sh","line_end":1262,"line_start":1262},{"file":"runtime/agy-worker.sh","line_end":237,"line_start":237},{"file":"runtime/agy-worker.sh","line_end":663,"line_start":663},{"file":"runtime/agy-worker.sh","line_end":673,"line_start":673},{"file":"runtime/agy-worker.sh","line_end":685,"line_start":685},{"file":"runtime/agy-worker.sh","line_end":897,"line_start":897},{"file":"runtime/agy-worker.sh","line_end":1011,"line_start":1011},{"file":"runtime/agy-worker.sh","line_end":1030,"line_start":1030},{"file":"runtime/agy-worker.sh","line_end":1200,"line_start":1200},{"file":"runtime/agy-worker.sh","line_end":1201,"line_start":1201},{"file":"runtime/agy-worker.sh","line_end":939,"line_start":939},{"file":"runtime/doctor.sh","line_end":21,"line_start":21},{"file":"runtime/doctor.sh","line_end":24,"line_start":24},{"file":"runtime/doctor.sh","line_end":32,"line_start":32},{"file":"runtime/doctor.sh","line_end":38,"line_start":38},{"file":"runtime/doctor.sh","line_end":86,"line_start":86},{"file":"runtime/doctor.sh","line_end":147,"line_start":147},{"file":"runtime/doctor.sh","line_end":156,"line_start":156},{"file":"runtime/doctor.sh","line_end":157,"line_start":157},{"file":"runtime/doctor.sh","line_end":172,"line_start":172},{"file":"runtime/doctor.sh","line_end":198,"line_start":198},{"file":"runtime/doctor.sh","line_end":199,"line_start":199},{"file":"runtime/doctor.sh","line_end":225,"line_start":225},{"file":"runtime/doctor.sh","line_end":230,"line_start":230},{"file":"runtime/doctor.sh","line_end":231,"line_start":231},{"file":"runtime/doctor.sh","line_end":237,"line_start":237},{"file":"runtime/doctor.sh","line_end":252,"line_start":252},{"file":"runtime/doctor.sh","line_end":253,"line_start":253},{"file":"runtime/doctor.sh","line_end":301,"line_start":301},{"file":"runtime/doctor.sh","line_end":302,"line_start":302},{"file":"runtime/doctor.sh","line_end":304,"line_start":304},{"file":"runtime/doctor.sh","line_end":315,"line_start":315},{"file":"runtime/doctor.sh","line_end":322,"line_start":322},{"file":"runtime/doctor.sh","line_end":468,"line_start":468},{"file":"runtime/doctor.sh","line_end":470,"line_start":470},{"file":"runtime/doctor.sh","line_end":478,"line_start":478},{"file":"runtime/doctor.sh","line_end":479,"line_start":479},{"file":"runtime/doctor.sh","line_end":493,"line_start":493},{"file":"runtime/doctor.sh","line_end":506,"line_start":506},{"file":"runtime/doctor.sh","line_end":527,"line_start":527},{"file":"runtime/doctor.sh","line_end":543,"line_start":543},{"file":"runtime/doctor.sh","line_end":563,"line_start":563},{"file":"runtime/doctor.sh","line_end":579,"line_start":579},{"file":"runtime/doctor.sh","line_end":224,"line_start":224}]},{"factor":"scripts","evidence":[{"file":"runtime/agy-worker.sh","line_end":1430,"line_start":1430},{"file":"runtime/agy-worker.sh","line_end":1431,"line_start":1431},{"file":"runtime/agy-worker.sh","line_end":1443,"line_start":1443},{"file":"runtime/agy-worker.sh","line_end":1446,"line_start":1446},{"file":"runtime/agy-worker.sh","line_end":1457,"line_start":1457},{"file":"runtime/agy-worker.sh","line_end":1478,"line_start":1478},{"file":"runtime/scripts/agy_dispatch_containment.py","line_end":778,"line_start":777},{"file":"runtime/scripts/agy_dispatch_worktree.py","line_end":674,"line_start":674},{"file":"runtime/scripts/agy_dispatch_worktree.py","line_end":4215,"line_start":4215},{"file":"runtime/scripts/agy_dispatch.py","line_end":2937,"line_start":2937},{"file":"runtime/scripts/agy_dispatch.py","line_end":46,"line_start":46},{"file":"runtime/scripts/agy_dispatch.py","line_end":3207,"line_start":3207},{"file":"runtime/scripts/benchmark.py","line_end":96,"line_start":88},{"file":"runtime/scripts/benchmark.py","line_end":100,"line_start":97},{"file":"runtime/scripts/evidence_receipt.py","line_end":37,"line_start":29},{"file":"runtime/scripts/evidence_receipt.py","line_end":41,"line_start":38},{"file":"runtime/scripts/evidence_report.py","line_end":34,"line_start":25},{"file":"runtime/scripts/evidence_report.py","line_end":38,"line_start":35},{"file":"runtime/scripts/job_lifecycle.py","line_end":38,"line_start":35},{"file":"runtime/scripts/job_lifecycle.py","line_end":44,"line_start":39},{"file":"runtime/scripts/job_lifecycle.py","line_end":54,"line_start":45},{"file":"runtime/scripts/model-recommendation.py","line_end":18,"line_start":12}]},{"factor":"env_access","evidence":[{"file":"runtime/qa-gate.sh","line_end":120,"line_start":120},{"file":"runtime/scripts/agy_dispatch_verification.py","line_end":151,"line_start":151},{"file":"runtime/scripts/agy_dispatch_worktree.py","line_end":1379,"line_start":1379},{"file":"runtime/scripts/evidence_receipt.py","line_end":1115,"line_start":1115},{"file":"runtime/scripts/evidence_receipt.py","line_end":1117,"line_start":1117},{"file":"runtime/scripts/evidence_receipt.py","line_end":1521,"line_start":1521},{"file":"runtime/scripts/evidence_receipt.py","line_end":955,"line_start":955},{"file":"runtime/scripts/feedback-triage.py","line_end":360,"line_start":360},{"file":"runtime/scripts/model_selection.py","line_end":98,"line_start":98},{"file":"runtime/scripts/workflow.py","line_end":711,"line_start":711},{"file":"runtime/scripts/workflow.py","line_end":718,"line_start":718},{"file":"runtime/scripts/workflow.py","line_end":750,"line_start":750},{"file":"runtime/scripts/workflow.py","line_end":1115,"line_start":1115},{"file":"runtime/scripts/workflow.py","line_end":1186,"line_start":1186},{"file":"runtime/scripts/workflow.py","line_end":1598,"line_start":1598}]}],"critical_findings":[],"high_findings":[{"title":"Hidden file in home directory","locations":[{"file":"runtime/ground-truth.sh","line_end":63,"line_start":63}],"confidence":0.97,"description":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The optional account phase reads ~/.gemini/antigravity-cli/settings.json from the user's home directory. The action is documented and explicit, but it accesses private tool configuration."},{"title":"Process exec","locations":[{"file":"runtime/scripts/agy_dispatch_containment.py","line_end":778,"line_start":777}],"confidence":0.94,"description":"(allow process-exec","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"The native sandbox profile explicitly allows the provider process to execute the bound target and tools from staged and system paths. This is required functionality, but it grants meaningful command-execution authority."},{"title":"Python os.exec variants","locations":[{"file":"runtime/scripts/evidence_receipt.py","line_end":1521,"line_start":1521}],"confidence":0.98,"description":"os.execvpe(command[0], command, dict(os.environ))","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"The no-shell verifier replaces the process with a caller-selected, validated argv command. Validation limits parsing attacks, but the feature intentionally executes external project tooling."},{"title":"Python subprocess.Popen","locations":[{"file":"runtime/scripts/agy_dispatch_verification.py","line_end":94,"line_start":94}],"confidence":0.96,"description":"process = subprocess.Popen(","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This Popen launches the selected verification command inside the prepared containment profile. Verification can execute repository code, so the documented approval and isolation controls remain security-critical."},{"title":"Python subprocess.Popen","locations":[{"file":"runtime/scripts/agy_dispatch.py","line_end":4949,"line_start":4949}],"confidence":0.99,"description":"process = subprocess.Popen(","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This Popen is the live Antigravity provider launch and gives the external worker access to approved repository content. The executable and environment are bound, but provider execution remains a high-impact trust boundary."},{"title":"Approved repository content is transmitted to an external provider","locations":[{"file":"SKILL.md","line_end":50,"line_start":45}],"confidence":0.99,"description":"Scoped files or an entire approved worktree can be readable and transmissible to Google or Gemini. Digest approval reduces accidental scope changes but does not eliminate third-party disclosure.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The skill explicitly documents provider-readable content, whole-worktree transmission, and the need to remove secrets before launch."},{"title":"Default session isolation retains ambient user authority","locations":[{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":91,"line_start":85}],"confidence":0.99,"description":"The default session mode gives AGY normal user filesystem and network authority outside the staged workspace. Scope reconciliation cannot prevent unobserved reads or network activity.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"Both the primary instructions and security guide state that session mode has no host containment and cannot observe access outside the stage."},{"title":"Native mode grants broad Keychain helper and listener authority","locations":[{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":142,"line_start":119}],"confidence":0.99,"description":"Native mode can expose wildcard listeners and broader same-user Keychain operations through the security helper. Approval does not technically limit helper operations to one AGY token.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The security guide explicitly states that wildcard binds are possible and Keychain reads, additions, changes, and deletions may be allowed."}],"medium_findings":[{"title":"Hidden file access","locations":[{"file":"runtime/ground-truth.sh","line_end":63,"line_start":63}],"confidence":0.97,"description":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The optional account phase opens ~/.gemini/antigravity-cli/settings.json to display permission settings. This is intentional diagnostics, but it is genuine hidden-file access."},{"title":"Unix shell invocation","locations":[{"file":"runtime/qa-gate.sh","line_end":623,"line_start":623}],"confidence":0.99,"description":"/bin/bash -c \"${verify_specs[$i]}\"","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Shell verification passes the selected verification specification to /bin/bash -c. This intentionally supports arbitrary shell commands and therefore carries command-injection and project-code execution risk."},{"title":"Unix shell invocation","locations":[{"file":"runtime/qa-gate.sh","line_end":639,"line_start":639}],"confidence":0.99,"description":"/bin/bash -c \"${verify_specs[$i]}\"","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The alternate gate branch also executes the selected verification specification through /bin/bash -c. The clean environment reduces exposure but does not remove arbitrary shell execution."}],"low_findings":[{"title":"Python environment access","locations":[{"file":"runtime/scripts/evidence_receipt.py","line_end":1115,"line_start":1115}],"confidence":0.94,"description":"if name in os.environ:","review_kind":"capability","source_category":"env_access","source_severity":"low","confidence_reasoning":"The verifier reads explicitly named values from the caller environment. The opt-in and private-pipe design reduce risk, but approved names may contain credentials."},{"title":"Python environment access","locations":[{"file":"runtime/scripts/evidence_receipt.py","line_end":1117,"line_start":1117}],"confidence":0.94,"description":"(os.fsencode(name), b\"\\0\", os.fsencode(os.environ[name]), b\"\\0\")","review_kind":"capability","source_category":"env_access","source_severity":"low","confidence_reasoning":"This line serializes approved environment values into the private verifier payload. Credential acknowledgements are enforced, but sensitive values still cross into executed verification code."},{"title":"Python environment access","locations":[{"file":"runtime/scripts/evidence_receipt.py","line_end":1521,"line_start":1521}],"confidence":0.92,"description":"os.execvpe(command[0], command, dict(os.environ))","review_kind":"capability","source_category":"env_access","source_severity":"low","confidence_reasoning":"The validated verifier receives the gate's environment through execvpe. The environment is sanitized and opt-in, but any approved secret becomes accessible to project tooling."},{"title":"Python environment access","locations":[{"file":"runtime/scripts/feedback-triage.py","line_end":360,"line_start":360}],"confidence":0.9,"description":"environment = os.environ.copy()","review_kind":"capability","source_category":"env_access","source_severity":"low","confidence_reasoning":"Feedback triage copies the ambient environment before invoking an authenticated GitHub CLI request. Fixed GitHub routing limits misuse, but the child can receive ambient GitHub credentials."}],"dangerous_patterns":[],"files_scanned":92,"total_lines":38537,"audit_model":"codex","audited_at":"2026-09-19T10:47:19.914+00:00","created_at":"2026-09-19T11:03:27.435235+00:00","static_findings":[{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1002:certificate-key-files","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Certificate/key files","snippet":"if prepared.keychain is None or prepared.keychain_preferences is None:","category":"sensitive","line_end":1002,"severity":"high","line_start":1002},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1004:certificate-key-files","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Certificate/key files","snippet":"if _bind_keychain(prepared.keychain.path) != prepared.keychain:","category":"sensitive","line_end":1004,"severity":"high","line_start":1004},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1007:certificate-key-files","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Certificate/key files","snippet":"prepared.keychain_preferences.path, modes={0o600}, limit=MAX_PROFILE_BYTES,","category":"sensitive","line_end":1007,"severity":"high","line_start":1007},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1008:certificate-key-files","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Certificate/key files","snippet":") != prepared.keychain_preferences:","category":"sensitive","line_end":1008,"severity":"high","line_start":1008},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1018:certificate-key-files","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Certificate/key files","snippet":"prepared.keychain is not None or prepared.keychain_preferences is not None","category":"sensitive","line_end":1018,"severity":"high","line_start":1018},{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2581:certificate-key-files","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Certificate/key files","snippet":"if set(value.keys()) != {\"schema_version\", \"kind\", \"read\", \"write\"}:","category":"sensitive","line_end":2581,"severity":"high","line_start":2581},{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2597:certificate-key-files","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Certificate/key files","snippet":"if set(entry.keys()) != {\"path\", \"kind\"}:","category":"sensitive","line_end":2597,"severity":"high","line_start":2597},{"id":"sensitive:runtime/scripts/agy_dispatch.py:4444:certificate-key-files","file":"runtime/scripts/agy_dispatch.py","pattern":"Certificate/key files","snippet":"if set(data.keys()) == {\"short_error\"}:","category":"sensitive","line_end":4444,"severity":"high","line_start":4444},{"id":"sensitive:runtime/scripts/agy_dispatch.py:4465:certificate-key-files","file":"runtime/scripts/agy_dispatch.py","pattern":"Certificate/key files","snippet":"if not set(data.keys()).issubset(AGY_ERROR_PAYLOAD_FIELDS):","category":"sensitive","line_end":4465,"severity":"high","line_start":4465},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:430:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(plan.keys()) != allowed_keys:","category":"sensitive","line_end":430,"severity":"high","line_start":430},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:457:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(anchors, dict) or set(anchors.keys()) != {","category":"sensitive","line_end":457,"severity":"high","line_start":457},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:470:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(trigger, dict) or set(trigger.keys()) != {","category":"sensitive","line_end":470,"severity":"high","line_start":470},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:489:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(obj, dict) or set(obj.keys()) != {\"id\", \"version\"}:","category":"sensitive","line_end":489,"severity":"high","line_start":489},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:501:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(mw, dict) or set(mw.keys()) != {\"start_date\", \"end_date\"}:","category":"sensitive","line_end":501,"severity":"high","line_start":501},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:510:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(ar, dict) or not {\"min_sample_size\", \"min_coverage\", \"max_error_rate\", \"uncertaint","category":"sensitive","line_end":510,"severity":"high","line_start":510},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:512:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(ar.keys()) - {\"min_sample_size\", \"min_coverage\", \"max_error_rate\", \"min_quality_score\", \"unce","category":"sensitive","line_end":512,"severity":"high","line_start":512},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:524:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(ur, dict) or set(ur.keys()) != {\"max_uncertainty\"}:","category":"sensitive","line_end":524,"severity":"high","line_start":524},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:530:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(budget, dict) or set(budget.keys()) != {\"sample_budget\", \"invocation_budget\"}:","category":"sensitive","line_end":530,"severity":"high","line_start":530},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:539:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(dt, dict) or set(dt.keys()) != {\"max_drift_fraction\"}:","category":"sensitive","line_end":539,"severity":"high","line_start":539},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:546:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(rt, dict) or set(rt.keys()) != {\"bindings\", \"min_coverage\"}:","category":"sensitive","line_end":546,"severity":"high","line_start":546},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:587:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if set(record.keys()) != allowed_keys:","category":"sensitive","line_end":587,"severity":"high","line_start":587},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:607:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"for k in record.keys():","category":"sensitive","line_end":607,"severity":"high","line_start":607},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:613:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(mid, dict) or set(mid.keys()) != {\"requested_model\", \"observed_model\", \"substitute","category":"sensitive","line_end":613,"severity":"high","line_start":613},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:628:certificate-key-files","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Certificate/key files","snippet":"if not isinstance(obj, dict) or set(obj.keys()) != {\"id\", \"version\"}:","category":"sensitive","line_end":628,"severity":"high","line_start":628},{"id":"sensitive:references/SECURITY_AND_COMPATIBILITY.md:26:crypto-seed-private-key-mention","file":"references/SECURITY_AND_COMPATIBILITY.md","pattern":"Crypto seed/private key mention","snippet":"boundary before launch. Credentials, private keys, user-denied paths, unrelated private files,","category":"sensitive","line_end":26,"severity":"high","line_start":26},{"id":"sensitive:SKILL.md:50:crypto-seed-private-key-mention","file":"SKILL.md","pattern":"Crypto seed/private key mention","snippet":"Before each launch, ensure secrets, credentials, private keys, user-denied paths, and unrelated priv","category":"sensitive","line_end":50,"severity":"high","line_start":50},{"id":"obfuscation:runtime/benchmarks/v1/portable-source.json:1:heuristic-extremely-long-line-2076-chars-likely-","file":"runtime/benchmarks/v1/portable-source.json","pattern":"[HEURISTIC] Extremely long line (2076 chars) - likely obfuscated","snippet":"{\"files\":[{\"mode\":\"100755\",\"path\":\"benchmark.sh\",\"sha256\":\"7e0033f6bf3eec1e6007752ef67e8e33db8f39c71","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-advisory.schema.json:1:heuristic-extremely-long-line-2424-chars-likely-","file":"runtime/schemas/swebench-workflow-study-advisory.schema.json","pattern":"[HEURISTIC] Extremely long line (2424 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"app","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-plan.schema.json:1:heuristic-extremely-long-line-2929-chars-likely-","file":"runtime/schemas/swebench-workflow-study-plan.schema.json","pattern":"[HEURISTIC] Extremely long line (2929 chars) - likely obfuscated","snippet":"{\"additionalProperties\":false,\"properties\":{\"aggregation\":{\"enum\":[\"input-plus-output-no-overlap-v1\"","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/benchmark-result.schema.json:1:heuristic-extremely-long-line-3160-chars-likely-","file":"runtime/schemas/benchmark-result.schema.json","pattern":"[HEURISTIC] Extremely long line (3160 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"com","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-report.schema.json:1:heuristic-extremely-long-line-6721-chars-likely-","file":"runtime/schemas/swebench-workflow-study-report.schema.json","pattern":"[HEURISTIC] Extremely long line (6721 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"den","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/benchmark-plan.schema.json:1:heuristic-extremely-long-line-7848-chars-likely-","file":"runtime/schemas/benchmark-plan.schema.json","pattern":"[HEURISTIC] Extremely long line (7848 chars) - likely obfuscated","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"exp","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:1:heuristic-multiple-bracket-chains-20-jsfuck-obfu","file":"runtime/schemas/model-evidence-campaign-advisory-summary.schema.json","pattern":"[HEURISTIC] Multiple bracket chains (20) - JSFuck/obfuscation pattern","snippet":"}}}]}, }}}]}, }}}]}","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/schemas/model-selection.schema.json:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","file":"runtime/schemas/model-selection.schema.json","pattern":"[HEURISTIC] Multiple bracket chains (6) - JSFuck/obfuscation pattern","snippet":"]}}}}, ]}}}}, ]}]}","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"[HEURISTIC] Multiple bracket chains (6) - JSFuck/obfuscation pattern","snippet":")))), ())), ()))","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/scripts/agy_dispatch_containment.py:1:heuristic-multiple-bracket-chains-9-jsfuck-obfus","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"[HEURISTIC] Multiple bracket chains (9) - JSFuck/obfuscation pattern","snippet":"())), ()[]{}, ()[]{}","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:runtime/scripts/evidence_report.py:131:heuristic-very-high-entropy-string-6-02-bits-lik","file":"runtime/scripts/evidence_report.py","pattern":"[HEURISTIC] Very high entropy string (6.02 bits) - likely encoded/encrypted payload","snippet":"abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789._-","category":"obfuscation","line_end":131,"severity":"high","line_start":131},{"id":"obfuscation:runtime/scripts/agy_dispatch_containment.py:582:hex-encoded-characters","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Hex-encoded characters","snippet":"or \"\\x00\" in path","category":"obfuscation","line_end":582,"severity":"high","line_start":582},{"id":"obfuscation:runtime/scripts/agy_dispatch_containment.py:612:hex-encoded-characters","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Hex-encoded characters","snippet":"or \"\\x00\" in value","category":"obfuscation","line_end":612,"severity":"high","line_start":612},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2563:hex-encoded-characters","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Hex-encoded characters","snippet":"if \"\\x00\" in text:","category":"obfuscation","line_end":2563,"severity":"high","line_start":2563},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2605:hex-encoded-characters","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Hex-encoded characters","snippet":"if \"\\x00\" in path or \"\\r\" in path or \"\\n\" in path:","category":"obfuscation","line_end":2605,"severity":"high","line_start":2605},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:723:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"not isinstance(item, str) or \"\\x00\" in item for item in value[\"argv\"]","category":"obfuscation","line_end":723,"severity":"high","line_start":723},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:1361:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"or any(ch in summary for ch in \"\\x00\\r\\n\")","category":"obfuscation","line_end":1361,"severity":"high","line_start":1361},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2586:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"if not isinstance(reported, str) or not reported or \"\\x00\" in reported:","category":"obfuscation","line_end":2586,"severity":"high","line_start":2586},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2608:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"if not path or \"\\x00\" in path:","category":"obfuscation","line_end":2608,"severity":"high","line_start":2608},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2752:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"item in summary for item in (\"\\x00\", \"\\r\", \"\\n\")","category":"obfuscation","line_end":2752,"severity":"high","line_start":2752},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2759:hex-encoded-characters","file":"runtime/scripts/agy_dispatch.py","pattern":"Hex-encoded characters","snippet":"or any(control in item for control in (\"\\x00\", \"\\r\", \"\\n\"))","category":"obfuscation","line_end":2759,"severity":"high","line_start":2759},{"id":"obfuscation:runtime/scripts/compatibility.py:174:hex-encoded-characters","file":"runtime/scripts/compatibility.py","pattern":"Hex-encoded characters","snippet":"if not raw or \"\\x00\" in raw:","category":"obfuscation","line_end":174,"severity":"high","line_start":174},{"id":"obfuscation:runtime/scripts/evidence_report.py:145:hex-encoded-characters","file":"runtime/scripts/evidence_report.py","pattern":"Hex-encoded characters","snippet":"if \"\\r\" in text or \"\\x00\" in text or text.startswith(\"::\") or \"\\n::\" in text:","category":"obfuscation","line_end":145,"severity":"high","line_start":145},{"id":"obfuscation:runtime/scripts/job_lifecycle.py:392:hex-encoded-characters","file":"runtime/scripts/job_lifecycle.py","pattern":"Hex-encoded characters","snippet":"if not isinstance(value[key], str) or not value[key] or \"\\x00\" in value[key]:","category":"obfuscation","line_end":392,"severity":"high","line_start":392},{"id":"obfuscation:runtime/scripts/model_selection.py:625:hex-encoded-characters","file":"runtime/scripts/model_selection.py","pattern":"Hex-encoded characters","snippet":"if not raw.endswith(b\"\\n\") or raw.count(b\"\\n\") != 1 or b\"\\x00\" in raw:","category":"obfuscation","line_end":625,"severity":"high","line_start":625},{"id":"obfuscation:runtime/scripts/model_selection.py:640:hex-encoded-characters","file":"runtime/scripts/model_selection.py","pattern":"Hex-encoded characters","snippet":"if b\"\\x00\" in raw:","category":"obfuscation","line_end":640,"severity":"high","line_start":640},{"id":"obfuscation:runtime/scripts/swebench_workflow_study.py:58:hex-encoded-characters","file":"runtime/scripts/swebench_workflow_study.py","pattern":"Hex-encoded characters","snippet":"r\"Users/|/home/|\\\\|[\\r\\n\\x00-\\x1f])\"","category":"obfuscation","line_end":58,"severity":"high","line_start":58},{"id":"env_access:runtime/qa-gate.sh:120:database-connection-strings","file":"runtime/qa-gate.sh","pattern":"Database connection strings","snippet":"|| \"$1\" == GH_PAT || \"$1\" == DATABASE_URL \\","category":"env_access","line_end":120,"severity":"high","line_start":120},{"id":"env_access:runtime/scripts/evidence_receipt.py:955:database-connection-strings","file":"runtime/scripts/evidence_receipt.py","pattern":"Database connection strings","snippet":"{\"DATABASE_URL\", \"GH_PAT\", \"MYSQL_PWD\", \"PGPASSWORD\"}","category":"env_access","line_end":955,"severity":"high","line_start":955},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-in-home-directory","file":"runtime/agy-worker.sh","pattern":"Hidden file in home directory","snippet":"`~/.gemini`, parent directories, or other user directories.","category":"filesystem","line_end":1262,"severity":"high","line_start":1262},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-in-home-directory","file":"runtime/ground-truth.sh","pattern":"Hidden file in home directory","snippet":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","category":"filesystem","line_end":63,"severity":"high","line_start":63},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2564:hidden-file-in-home-directory","file":"runtime/scripts/agy_dispatch.py","pattern":"Hidden file in home directory","snippet":"\"`~/.gemini`, or any other directory. Do not call shell or terminal tools.\\n\"","category":"filesystem","line_end":2564,"severity":"high","line_start":2564},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:816:non-standard-device-file-access","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Non-standard device file access","snippet":"(subpath \"/dev/fd\"))","category":"filesystem","line_end":816,"severity":"high","line_start":816},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:204:path-traversal-sequence","file":"references/SECURITY_AND_COMPATIBILITY.md","pattern":"Path traversal sequence","snippet":"The package-owned [README](../README.md), [skill router](../SKILL.md), and references","category":"filesystem","line_end":204,"severity":"high","line_start":204},{"id":"filesystem:runtime/qa-gate.sh:472:path-traversal-sequence","file":"runtime/qa-gate.sh","pattern":"Path traversal sequence","snippet":"if path in (\"\", \".\", \"..\") or path.startswith(\"../\") or posixpath.isabs(path):","category":"filesystem","line_end":472,"severity":"high","line_start":472},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:591:path-traversal-sequence","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Path traversal sequence","snippet":"or normalized.startswith(\"../\")","category":"filesystem","line_end":591,"severity":"high","line_start":591},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:2610:path-traversal-sequence","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Path traversal sequence","snippet":"if norm != path or norm in (\"\", \".\", \"..\") or norm.startswith(\"../\") or posixpath.isabs(norm):","category":"filesystem","line_end":2610,"severity":"high","line_start":2610},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3540:path-traversal-sequence","file":"runtime/scripts/agy_dispatch.py","pattern":"Path traversal sequence","snippet":"# example ``../source/target``).  Rebase every contained link from its","category":"filesystem","line_end":3540,"severity":"high","line_start":3540},{"id":"filesystem:scripts/resolve-pipeline.sh:169:path-traversal-sequence","file":"scripts/resolve-pipeline.sh","pattern":"Path traversal sequence","snippet":"PLUGIN_ROOT=\"$(CDPATH= cd -- \"$SKILL_DIR/../..\" 2>/dev/null && pwd -P)\" || PLUGIN_ROOT=\"\"","category":"filesystem","line_end":169,"severity":"high","line_start":169},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:777:process-exec","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Process exec","snippet":"(allow process-exec","category":"external_commands","line_end":778,"severity":"high","line_start":777},{"id":"external_commands:runtime/scripts/agy_dispatch.py:2937:process-exec","file":"runtime/scripts/agy_dispatch.py","pattern":"Process exec","snippet":"exec(","category":"external_commands","line_end":2938,"severity":"high","line_start":2937},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6003:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"def spawn(","category":"external_commands","line_end":6003,"severity":"high","line_start":6003},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6486:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(","category":"external_commands","line_end":6486,"severity":"high","line_start":6486},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6640:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(job, \"initial\", resume=False, foreground=True)","category":"external_commands","line_end":6640,"severity":"high","line_start":6640},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6642:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(job, \"initial\", resume=False, foreground=False)","category":"external_commands","line_end":6642,"severity":"high","line_start":6642},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6646:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(","category":"external_commands","line_end":6646,"severity":"high","line_start":6646},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6652:process-spawn","file":"runtime/scripts/agy_dispatch.py","pattern":"Process spawn","snippet":"return spawn(","category":"external_commands","line_end":6652,"severity":"high","line_start":6652},{"id":"scripts:runtime/agy-worker.sh:1430:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"if (not __import__(\"stat\").S_ISREG(before.st_mode) or before.st_uid != os.geteuid()","category":"scripts","line_end":1430,"severity":"high","line_start":1430},{"id":"scripts:runtime/agy-worker.sh:1431:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"or __import__(\"stat\").S_IMODE(before.st_mode) != 0o600 or before.st_nlink != 1):","category":"scripts","line_end":1431,"severity":"high","line_start":1431},{"id":"scripts:runtime/agy-worker.sh:1443:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"identity = lambda info: (info.st_dev, info.st_ino, info.st_uid, info.st_gid, __import__(\"stat\").S_IM","category":"scripts","line_end":1443,"severity":"high","line_start":1443},{"id":"scripts:runtime/agy-worker.sh:1446:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"value[\"selection_sha256\"] = __import__(\"hashlib\").sha256(selection).hexdigest()","category":"scripts","line_end":1446,"severity":"high","line_start":1446},{"id":"scripts:runtime/agy-worker.sh:1457:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"value[\"provider_scope_sha256\"] = __import__(\"hashlib\").sha256(sc_data).hexdigest()","category":"scripts","line_end":1457,"severity":"high","line_start":1457},{"id":"scripts:runtime/agy-worker.sh:1478:python-import-function","file":"runtime/agy-worker.sh","pattern":"Python __import__ function","snippet":"value[\"self_verification_manifest_sha256\"] = __import__(\"hashlib\").sha256(manifest_data).hexdigest()","category":"scripts","line_end":1478,"severity":"high","line_start":1478},{"id":"scripts:runtime/scripts/agy_dispatch_containment.py:777:python-exec-function","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Python exec() function","snippet":"(allow process-exec","category":"scripts","line_end":778,"severity":"high","line_start":777},{"id":"scripts:runtime/scripts/agy_dispatch.py:2937:python-exec-function","file":"runtime/scripts/agy_dispatch.py","pattern":"Python exec() function","snippet":"exec(","category":"scripts","line_end":2937,"severity":"high","line_start":2937},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:674:python-globals-manipulation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python globals() manipulation","snippet":"globals()[key] = value","category":"scripts","line_end":674,"severity":"high","line_start":674},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:4215:python-globals-manipulation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python globals() manipulation","snippet":"name: globals()[name] for name in _IMPLEMENTATION_FUNCTIONS","category":"scripts","line_end":4215,"severity":"high","line_start":4215},{"id":"scripts:runtime/scripts/agy_dispatch.py:46:python-globals-manipulation","file":"runtime/scripts/agy_dispatch.py","pattern":"Python globals() manipulation","snippet":"return globals()[name]","category":"scripts","line_end":46,"severity":"high","line_start":46},{"id":"scripts:runtime/scripts/agy_dispatch.py:3207:python-globals-manipulation","file":"runtime/scripts/agy_dispatch.py","pattern":"Python globals() manipulation","snippet":"name: globals()[name] for name in _WORKTREE_HELPER._IMPLEMENTATION_FUNCTIONS","category":"scripts","line_end":3207,"severity":"high","line_start":3207},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1521:python-os-exec-variants","file":"runtime/scripts/evidence_receipt.py","pattern":"Python os.exec variants","snippet":"os.execvpe(command[0], command, dict(os.environ))","category":"external_commands","line_end":1521,"severity":"high","line_start":1521},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:278:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes], root: ProcessIdentity,","category":"external_commands","line_end":278,"severity":"high","line_start":278},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:308:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":308,"severity":"high","line_start":308},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:94:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_verification.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":94,"severity":"high","line_start":94},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:205:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"def _stop_preview_child(child: subprocess.Popen[bytes]) -> None:","category":"external_commands","line_end":205,"severity":"high","line_start":205},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:238:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"child: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":238,"severity":"high","line_start":238},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:244:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"child = subprocess.Popen(","category":"external_commands","line_end":244,"severity":"high","line_start":244},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1396:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":1396,"severity":"high","line_start":1396},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1414:python-subprocess-popen","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":1414,"severity":"high","line_start":1414},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3964:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"def _terminate(process: subprocess.Popen[bytes]) -> int:","category":"external_commands","line_end":3964,"severity":"high","line_start":3964},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4028:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes],","category":"external_commands","line_end":4028,"severity":"high","line_start":4028},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4572:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":4572,"severity":"high","line_start":4572},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4949:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":4949,"severity":"high","line_start":4949},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6021:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"controller_process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":6021,"severity":"high","line_start":6021},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6038:python-subprocess-popen","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.Popen","snippet":"controller_process = subprocess.Popen(","category":"external_commands","line_end":6038,"severity":"high","line_start":6038},{"id":"external_commands:runtime/scripts/benchmark.py:135:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"b'process = subprocess.Popen(': 2,","category":"external_commands","line_end":135,"severity":"high","line_start":135},{"id":"external_commands:runtime/scripts/benchmark.py:581:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"def _close_group(process: subprocess.Popen[bytes]) -> int:","category":"external_commands","line_end":581,"severity":"high","line_start":581},{"id":"external_commands:runtime/scripts/benchmark.py:594:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"def _leader_exited_unreaped(process: subprocess.Popen[bytes]) -> bool:","category":"external_commands","line_end":594,"severity":"high","line_start":594},{"id":"external_commands:runtime/scripts/benchmark.py:606:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"process: subprocess.Popen[bytes] | None = None","category":"external_commands","line_end":606,"severity":"high","line_start":606},{"id":"external_commands:runtime/scripts/benchmark.py:615:python-subprocess-popen","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(argv, cwd=cwd, env=git_env(), stdin=subprocess.DEVNULL, stdout=subprocess","category":"external_commands","line_end":615,"severity":"high","line_start":615},{"id":"external_commands:runtime/scripts/codex_usage_report.py:115:python-subprocess-popen","file":"runtime/scripts/codex_usage_report.py","pattern":"Python subprocess.Popen","snippet":"def _close_process_group(process: subprocess.Popen[bytes], pgid: int) -> None:","category":"external_commands","line_end":115,"severity":"high","line_start":115},{"id":"external_commands:runtime/scripts/codex_usage_report.py:157:python-subprocess-popen","file":"runtime/scripts/codex_usage_report.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":157,"severity":"high","line_start":157},{"id":"external_commands:runtime/scripts/codex_usage_report.py:647:python-subprocess-popen","file":"runtime/scripts/codex_usage_report.py","pattern":"Python subprocess.Popen","snippet":"process = subprocess.Popen(","category":"external_commands","line_end":647,"severity":"high","line_start":647},{"id":"external_commands:runtime/scripts/doctor-metadata.py:92:python-subprocess-popen","file":"runtime/scripts/doctor-metadata.py","pattern":"Python subprocess.Popen","snippet":"def terminate_group(process: subprocess.Popen[bytes], signum: int) -> None:","category":"external_commands","line_end":92,"severity":"high","line_start":92},{"id":"external_commands:runtime/qa-gate.sh:447:python-subprocess-run","file":"runtime/qa-gate.sh","pattern":"Python subprocess.run","snippet":"return subprocess.run(","category":"external_commands","line_end":447,"severity":"high","line_start":447},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3408:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"subprocess.run(","category":"external_commands","line_end":3408,"severity":"high","line_start":3408},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3686:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"subprocess.run(","category":"external_commands","line_end":3686,"severity":"high","line_start":3686},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4547:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"provider_checked = subprocess.run(","category":"external_commands","line_end":4547,"severity":"high","line_start":4547},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4552:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"canonical_checked = subprocess.run(","category":"external_commands","line_end":4552,"severity":"high","line_start":4552},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6432:python-subprocess-run","file":"runtime/scripts/agy_dispatch.py","pattern":"Python subprocess.run","snippet":"subprocess.run(","category":"external_commands","line_end":6432,"severity":"high","line_start":6432},{"id":"external_commands:runtime/scripts/benchmark.py:347:python-subprocess-run","file":"runtime/scripts/benchmark.py","pattern":"Python subprocess.run","snippet":"result = subprocess.run(command, cwd=cwd, env=git_env(), stdin=subprocess.DEVNULL, stdout=subprocess","category":"external_commands","line_end":347,"severity":"high","line_start":347},{"id":"external_commands:runtime/scripts/candidate_state.py:30:python-subprocess-run","file":"runtime/scripts/candidate_state.py","pattern":"Python subprocess.run","snippet":"completed = subprocess.run(","category":"external_commands","line_end":30,"severity":"high","line_start":30},{"id":"external_commands:runtime/scripts/evidence_receipt.py:468:python-subprocess-run","file":"runtime/scripts/evidence_receipt.py","pattern":"Python subprocess.run","snippet":"completed = subprocess.run(","category":"external_commands","line_end":468,"severity":"high","line_start":468},{"id":"external_commands:runtime/scripts/workflow.py:493:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":493,"severity":"high","line_start":493},{"id":"external_commands:runtime/scripts/workflow.py:544:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":544,"severity":"high","line_start":544},{"id":"external_commands:runtime/scripts/workflow.py:576:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":576,"severity":"high","line_start":576},{"id":"external_commands:runtime/scripts/workflow.py:762:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":762,"severity":"high","line_start":762},{"id":"external_commands:runtime/scripts/workflow.py:784:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"return subprocess.run(","category":"external_commands","line_end":784,"severity":"high","line_start":784},{"id":"external_commands:runtime/scripts/workflow.py:1121:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(","category":"external_commands","line_end":1121,"severity":"high","line_start":1121},{"id":"external_commands:runtime/scripts/workflow.py:1800:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"proc = subprocess.run(verify_cmd, check=False)","category":"external_commands","line_end":1800,"severity":"high","line_start":1800},{"id":"external_commands:runtime/scripts/workflow.py:1854:python-subprocess-run","file":"runtime/scripts/workflow.py","pattern":"Python subprocess.run","snippet":"fin_proc = subprocess.run(","category":"external_commands","line_end":1854,"severity":"high","line_start":1854},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3554:symlink-creation","file":"runtime/scripts/agy_dispatch.py","pattern":"Symlink creation","snippet":"os.symlink(target_text, target)","category":"filesystem","line_end":3554,"severity":"high","line_start":3554},{"id":"scripts:runtime/scripts/benchmark.py:88:dynamic-import-expression","file":"runtime/scripts/benchmark.py","pattern":"Dynamic import() expression","snippet":"from evidence_receipt import (  # noqa: E402","category":"scripts","line_end":96,"severity":"medium","line_start":88},{"id":"scripts:runtime/scripts/benchmark.py:97:dynamic-import-expression","file":"runtime/scripts/benchmark.py","pattern":"Dynamic import() expression","snippet":"from model_selection import (  # noqa: E402","category":"scripts","line_end":100,"severity":"medium","line_start":97},{"id":"scripts:runtime/scripts/evidence_receipt.py:29:dynamic-import-expression","file":"runtime/scripts/evidence_receipt.py","pattern":"Dynamic import() expression","snippet":"from model_selection import (  # noqa: E402","category":"scripts","line_end":37,"severity":"medium","line_start":29},{"id":"scripts:runtime/scripts/evidence_receipt.py:38:dynamic-import-expression","file":"runtime/scripts/evidence_receipt.py","pattern":"Dynamic import() expression","snippet":"from recommendation_record import (  # noqa: E402","category":"scripts","line_end":41,"severity":"medium","line_start":38},{"id":"scripts:runtime/scripts/evidence_report.py:25:dynamic-import-expression","file":"runtime/scripts/evidence_report.py","pattern":"Dynamic import() expression","snippet":"from evidence_receipt import (  # noqa: E402","category":"scripts","line_end":34,"severity":"medium","line_start":25},{"id":"scripts:runtime/scripts/evidence_report.py:35:dynamic-import-expression","file":"runtime/scripts/evidence_report.py","pattern":"Dynamic import() expression","snippet":"from recommendation_record import (  # noqa: E402","category":"scripts","line_end":38,"severity":"medium","line_start":35},{"id":"scripts:runtime/scripts/job_lifecycle.py:35:dynamic-import-expression","file":"runtime/scripts/job_lifecycle.py","pattern":"Dynamic import() expression","snippet":"from candidate_state import (  # noqa: E402","category":"scripts","line_end":38,"severity":"medium","line_start":35},{"id":"scripts:runtime/scripts/job_lifecycle.py:39:dynamic-import-expression","file":"runtime/scripts/job_lifecycle.py","pattern":"Dynamic import() expression","snippet":"from evidence_receipt import (  # noqa: E402","category":"scripts","line_end":44,"severity":"medium","line_start":39},{"id":"scripts:runtime/scripts/job_lifecycle.py:45:dynamic-import-expression","file":"runtime/scripts/job_lifecycle.py","pattern":"Dynamic import() expression","snippet":"from agy_dispatch import (  # noqa: E402","category":"scripts","line_end":54,"severity":"medium","line_start":45},{"id":"scripts:runtime/scripts/model-recommendation.py:12:dynamic-import-expression","file":"runtime/scripts/model-recommendation.py","pattern":"Dynamic import() expression","snippet":"from recommendation_record import (","category":"scripts","line_end":18,"severity":"medium","line_start":12},{"id":"filesystem:runtime/scripts/benchmark.py:420:hard-link-creation","file":"runtime/scripts/benchmark.py","pattern":"Hard link creation","snippet":"os.link(temp, name, src_dir_fd=fd, dst_dir_fd=fd, follow_symlinks=False)","category":"filesystem","line_end":420,"severity":"medium","line_start":420},{"id":"filesystem:runtime/scripts/evidence_receipt.py:882:hard-link-creation","file":"runtime/scripts/evidence_receipt.py","pattern":"Hard link creation","snippet":"os.link(temporary, target, follow_symlinks=False)","category":"filesystem","line_end":882,"severity":"medium","line_start":882},{"id":"filesystem:runtime/scripts/evidence_report.py:341:hard-link-creation","file":"runtime/scripts/evidence_report.py","pattern":"Hard link creation","snippet":"os.link(","category":"filesystem","line_end":341,"severity":"medium","line_start":341},{"id":"filesystem:runtime/scripts/model_evidence_campaign.py:355:hard-link-creation","file":"runtime/scripts/model_evidence_campaign.py","pattern":"Hard link creation","snippet":"os.link(","category":"filesystem","line_end":355,"severity":"medium","line_start":355},{"id":"filesystem:runtime/scripts/swebench_workflow_study.py:277:hard-link-creation","file":"runtime/scripts/swebench_workflow_study.py","pattern":"Hard link creation","snippet":"os.link(temp,name,src_dir_fd=root_fd,dst_dir_fd=root_fd,follow_symlinks=False); linked=True","category":"filesystem","line_end":277,"severity":"medium","line_start":277},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-access","file":"runtime/agy-worker.sh","pattern":"Hidden file access","snippet":"`~/.gemini`, parent directories, or other user directories.","category":"filesystem","line_end":1262,"severity":"medium","line_start":1262},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-access","file":"runtime/ground-truth.sh","pattern":"Hidden file access","snippet":"p = os.path.expanduser(\"~/.gemini/antigravity-cli/settings.json\")","category":"filesystem","line_end":63,"severity":"medium","line_start":63},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2564:hidden-file-access","file":"runtime/scripts/agy_dispatch.py","pattern":"Hidden file access","snippet":"\"`~/.gemini`, or any other directory. Do not call shell or terminal tools.\\n\"","category":"filesystem","line_end":2564,"severity":"medium","line_start":2564},{"id":"filesystem:scripts/resolve-pipeline.sh:171:hidden-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Hidden file access","snippet":"&& [[ -f \"$PLUGIN_ROOT/.codex-plugin/plugin.json\" ]] \\","category":"filesystem","line_end":171,"severity":"medium","line_start":171},{"id":"filesystem:scripts/resolve-pipeline.sh:177:hidden-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Hidden file access","snippet":"MARKER=\"$SKILL_DIR/.pipeline-root\"","category":"filesystem","line_end":177,"severity":"medium","line_start":177},{"id":"filesystem:runtime/scripts/model_selection.py:1270:python-file-write-append","file":"runtime/scripts/model_selection.py","pattern":"Python file write/append","snippet":"with os.fdopen(descriptor, \"wb\") as handle:","category":"filesystem","line_end":1270,"severity":"medium","line_start":1270},{"id":"filesystem:runtime/agy-worker.sh:939:python-os-file-operations","file":"runtime/agy-worker.sh","pattern":"Python os file operations","snippet":"os.rmdir(path)","category":"filesystem","line_end":939,"severity":"medium","line_start":939},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:427:python-os-file-operations","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Python os file operations","snippet":"os.chmod(path, 0o700, follow_symlinks=False)","category":"filesystem","line_end":427,"severity":"medium","line_start":427},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3479:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(name, dir_fd=recovery_fd)","category":"filesystem","line_end":3479,"severity":"medium","line_start":3479},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3481:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(\"reconciliation-backups\", dir_fd=job_fd)","category":"filesystem","line_end":3481,"severity":"medium","line_start":3481},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3482:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(\"reconciliation-in-progress.json\", dir_fd=job_fd)","category":"filesystem","line_end":3482,"severity":"medium","line_start":3482},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3517:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(parts[-1], dir_fd=parent)","category":"filesystem","line_end":3517,"severity":"medium","line_start":3517},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3519:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(parts[-1], dir_fd=parent)","category":"filesystem","line_end":3519,"severity":"medium","line_start":3519},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4055:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(parts[-1], dir_fd=curr_src)","category":"filesystem","line_end":4055,"severity":"medium","line_start":4055},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4067:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(parts[-1], dir_fd=curr_src)","category":"filesystem","line_end":4067,"severity":"medium","line_start":4067},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4169:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(name_str, dir_fd=parent_fd)","category":"filesystem","line_end":4169,"severity":"medium","line_start":4169},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4171:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.unlink(name_str, dir_fd=parent_fd)","category":"filesystem","line_end":4171,"severity":"medium","line_start":4171},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4177:python-os-file-operations","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python os file operations","snippet":"os.rmdir(stg_str)","category":"filesystem","line_end":4177,"severity":"medium","line_start":4177},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3490:python-os-file-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python os file operations","snippet":"os.chmod(current, 0o700)","category":"filesystem","line_end":3490,"severity":"medium","line_start":3490},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3601:python-os-file-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python os file operations","snippet":"os.chmod(destination, 0o700)","category":"filesystem","line_end":3601,"severity":"medium","line_start":3601},{"id":"filesystem:runtime/scripts/benchmark.py:427:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.unlink(temp, dir_fd=fd)","category":"filesystem","line_end":427,"severity":"medium","line_start":427},{"id":"filesystem:runtime/scripts/benchmark.py:441:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.unlink(target, dir_fd=fd)","category":"filesystem","line_end":441,"severity":"medium","line_start":441},{"id":"filesystem:runtime/scripts/benchmark.py:465:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.unlink(name, dir_fd=fd); os.fsync(fd)","category":"filesystem","line_end":465,"severity":"medium","line_start":465},{"id":"filesystem:runtime/scripts/benchmark.py:757:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"os.chmod(work, 0o700)","category":"filesystem","line_end":757,"severity":"medium","line_start":757},{"id":"filesystem:runtime/scripts/benchmark.py:770:python-os-file-operations","file":"runtime/scripts/benchmark.py","pattern":"Python os file operations","snippet":"selection_path.write_bytes(canonical_bytes(variant[\"selection\"])); os.chmod(selection_path, 0o600)","category":"filesystem","line_end":770,"severity":"medium","line_start":770},{"id":"filesystem:runtime/scripts/codex_usage_report.py:223:python-os-file-operations","file":"runtime/scripts/codex_usage_report.py","pattern":"Python os file operations","snippet":"os.chmod(str(temp_path), 0o700)","category":"filesystem","line_end":223,"severity":"medium","line_start":223},{"id":"filesystem:runtime/scripts/evidence_report.py:263:python-os-file-operations","file":"runtime/scripts/evidence_report.py","pattern":"Python os file operations","snippet":"os.unlink(name, dir_fd=parent_fd)","category":"filesystem","line_end":263,"severity":"medium","line_start":263},{"id":"filesystem:runtime/scripts/evidence_report.py:353:python-os-file-operations","file":"runtime/scripts/evidence_report.py","pattern":"Python os file operations","snippet":"os.unlink(temporary, dir_fd=parent_fd)","category":"filesystem","line_end":353,"severity":"medium","line_start":353},{"id":"filesystem:runtime/scripts/job_lifecycle.py:690:python-os-file-operations","file":"runtime/scripts/job_lifecycle.py","pattern":"Python os file operations","snippet":"os.unlink(temporary, dir_fd=self.parent_fd)","category":"filesystem","line_end":690,"severity":"medium","line_start":690},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3497:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.rmtree(destination)","category":"filesystem","line_end":3497,"severity":"medium","line_start":3497},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3555:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.copystat(source, target, follow_symlinks=False)","category":"filesystem","line_end":3555,"severity":"medium","line_start":3555},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3561:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.copy2(source, target, follow_symlinks=False)","category":"filesystem","line_end":3561,"severity":"medium","line_start":3561},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3595:python-shutil-operations","file":"runtime/scripts/agy_dispatch.py","pattern":"Python shutil operations","snippet":"shutil.copystat(source, target, follow_symlinks=False)","category":"filesystem","line_end":3595,"severity":"medium","line_start":3595},{"id":"filesystem:runtime/scripts/benchmark.py:740:python-shutil-operations","file":"runtime/scripts/benchmark.py","pattern":"Python shutil operations","snippet":"shutil.rmtree(path)","category":"filesystem","line_end":740,"severity":"medium","line_start":740},{"id":"filesystem:runtime/scripts/job_lifecycle.py:851:python-shutil-operations","file":"runtime/scripts/job_lifecycle.py","pattern":"Python shutil operations","snippet":"shutil.rmtree(directory, ignore_errors=True)","category":"filesystem","line_end":851,"severity":"medium","line_start":851},{"id":"external_commands:runtime/agy-worker.sh:14:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"#   * Under --sandbox, SHELL commands need an `unsandboxed(<target>)` allow-rule; a","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:runtime/agy-worker.sh:15:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"#     `command(<name>)` rule alone is NOT enough. But a worker editing files via its","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:runtime/agy-worker.sh:1262:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"`~/.gemini`, parent directories, or other user directories.","category":"external_commands","line_end":1262,"severity":"medium","line_start":1262},{"id":"external_commands:runtime/agy-worker.sh:1263:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"- Never call shell or terminal tools, including `pwd`, `ls`, `find`, or `git`.","category":"external_commands","line_end":1263,"severity":"medium","line_start":1263},{"id":"external_commands:runtime/agy-worker.sh:1300:ruby-shell-backtick-execution","file":"runtime/agy-worker.sh","pattern":"Ruby/shell backtick execution","snippet":"# the `tools:` list is meaningless here — tool access is governed by agy's own","category":"external_commands","line_end":1300,"severity":"medium","line_start":1300},{"id":"external_commands:runtime/ground-truth.sh:5:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# When agy was asked to research its own CLI, it confidently invented `agy run`,","category":"external_commands","line_end":5,"severity":"medium","line_start":5},{"id":"external_commands:runtime/ground-truth.sh:6:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# `--headless`, `--slim`, `--no-prompt`, `--workspace` and an `agy auth status --json`","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:runtime/ground-truth.sh:8:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# `agy --help` got it right. Conclusion: a model's memory of its own tooling is","category":"external_commands","line_end":8,"severity":"medium","line_start":8},{"id":"external_commands:runtime/ground-truth.sh:13:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# account review: it invokes only `agy --version` and `agy --help`. The optional","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:runtime/ground-truth.sh:14:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"# account phase is a separate explicit action because `models`, `agents`, plugin","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:runtime/ground-truth.sh:76:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"1.2.2 deprecates `unsandboxed` rules in favor of `command` rules; this report does","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:runtime/ground-truth.sh:80:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- The prompt is `--print`'s ARGUMENT VALUE. agy ignores stdin in print mode. With","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:runtime/ground-truth.sh:81:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"`--print` placed before other flags, agy reads the NEXT FLAG as the message.","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:runtime/ground-truth.sh:82:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"Therefore `--print` must always be built LAST.","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:runtime/ground-truth.sh:86:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- Under `--sandbox`, running a shell command needs an `unsandboxed(<target>)`","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:runtime/ground-truth.sh:87:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"allow-rule. A `command(<name>)` rule alone is NOT sufficient.","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:runtime/ground-truth.sh:91:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- `stream-json` event shape: {\"event\":\"...\",\"init\":...}, then repeated","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:runtime/ground-truth.sh:98:ruby-shell-backtick-execution","file":"runtime/ground-truth.sh","pattern":"Ruby/shell backtick execution","snippet":"- The observed unsupported examples `agy run`, `agy exec`, and `agy auth` print","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:9:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"``sandbox-exec`` is a deprecated macOS interface.  The implementation therefore","category":"external_commands","line_end":9,"severity":"medium","line_start":9},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:11:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"caller must re-run :func:`confirm_contained_launch` immediately before ``Popen``.","category":"external_commands","line_end":11,"severity":"medium","line_start":11},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:679:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Render the fixed default-deny profile; dynamic paths use ``-D`` params.\"\"\"","category":"external_commands","line_end":679,"severity":"medium","line_start":679},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:976:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Revalidate every native authority immediately before caller ``Popen``.\"\"\"","category":"external_commands","line_end":976,"severity":"medium","line_start":976},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:1079:ruby-shell-backtick-execution","file":"runtime/scripts/agy_dispatch_containment.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Bind the session leader created by ``Popen(start_new_session=True)``.\"\"\"","category":"external_commands","line_end":1079,"severity":"medium","line_start":1079},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use this skill when `agy` can usefully explore a repository, implement bounded work,","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and implementation to `agy` before Codex duplicates it. Codex reads only scope and","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"$PIPELINE/doctor.sh\" --repo /absolute/path/to/target` can check offline","category":"external_commands","line_end":27,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"prerequisites before provider use. `ready` does not prove authentication, provider","category":"external_commands","line_end":37,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use initial `--allow-scoped-repair` for approved multi-turn scoped work. Approval is a","category":"external_commands","line_end":45,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Prefer `--provider-scope FILE --approve-transmission-sha SHA256` for bounded jobs. It binds exact re","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Whole-worktree dispatch remains an explicit exception. Treat the entire disposable worktree passed a","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Neither `workflow.sh run` nor the advanced `agy-worker.sh` initial dispatch has an implicit transmis","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"New jobs default to `--provider-isolation session`, which uses the existing AGY session without AGY ","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Explore, understand, review, or plan | `explore` | 2 | Spot-check material claims and state covera","category":"external_commands","line_end":65,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Implement a feature, refactor, tests, or bounded repair | `task` | 2 | Inspect the diff and run re","category":"external_commands","line_end":66,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Build a project or perform broad audit-and-fix work | `project` | 5 | Review repo-wide changes and","category":"external_commands","line_end":68,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`explore` and `task` accept `1..2` cycles; `project` accepts `1..5`. Personas are","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"quality gates. The raw `--boost` profile is an advanced, separately acknowledged","category":"external_commands","line_end":78,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Explicit delegation-first requires running the `delegation-policy.sh` evaluator before substantive r","category":"external_commands","line_end":84,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Prefer `workflow.sh` for `run --preview`, approved `run`, read-only `status`, and","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`verify-finalize`. Review the content-free preview, then run with its exact approved","category":"external_commands","line_end":91,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"in an isolated verification copy, never an envelope's `commands_run` or `tests_run`;","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--allow-scoped-repair`, which binds the same approved scope, selected model,","category":"external_commands","line_end":101,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"ends; `restart` is an explicit user decision. See [Project lifecycle and verification](references/PR","category":"external_commands","line_end":107,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"when writes can escape the disposable worktree, enter `.git`, or traverse a symlink","category":"external_commands","line_end":117,"severity":"medium","line_start":107},{"id":"external_commands:README.md:56:shell-command-substitution","file":"README.md","pattern":"Shell command substitution","snippet":"PIPELINE=\"$(bash \"$SKILL_ROOT/scripts/resolve-pipeline.sh\")\" || exit $?","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:71:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"PIPELINE=\"$(bash \"$SKILL_ROOT/scripts/resolve-pipeline.sh\")\" || exit $?","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:80:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"BASE=\"$(git -C \"$TARGET\" rev-parse HEAD)\"","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:81:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"STATE_DIR=\"$(mktemp -d -t agyworker-state.XXXXXX)\"","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:82:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"WT=\"$(mktemp -d -t agyworker-worktree.XXXXXX)\"","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:251:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"VERIFY_PARENT=\"$(mktemp -d -t agyworker-verify.XXXXXX)\" || exit $?","category":"external_commands","line_end":251,"severity":"medium","line_start":251},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:252:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"VERIFY_PARENT=\"$(CDPATH= cd -- \"$VERIFY_PARENT\" && pwd -P)\" || exit $?","category":"external_commands","line_end":252,"severity":"medium","line_start":252},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:286:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"STATUS_JSON=\"$(\"$PIPELINE/agy-worker.sh\" status --job-id \"$JOB_ID\" --format json)\"","category":"external_commands","line_end":286,"severity":"medium","line_start":286},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:287:shell-command-substitution","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Shell command substitution","snippet":"STATE_AND_CANDIDATE=\"$(printf '%s\\n' \"$STATUS_JSON\" | python3 -c '","category":"external_commands","line_end":289,"severity":"medium","line_start":287},{"id":"external_commands:runtime/agy-worker.sh:25:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"CALLER_UMASK=\"$(umask)\"","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:runtime/agy-worker.sh:30:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"SCRIPT_DIR=\"$(CDPATH= cd -- \"$SCRIPT_SOURCE_DIR\" && pwd -P)\"","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:runtime/agy-worker.sh:237:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\" || exit 64","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:runtime/agy-worker.sh:464:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"provider_env_occurrences=$((provider_env_occurrences + 1))","category":"external_commands","line_end":464,"severity":"medium","line_start":464},{"id":"external_commands:runtime/agy-worker.sh:473:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"job_id=\"job-$(python3 -I -S -B - <<'PY'","category":"external_commands","line_end":475,"severity":"medium","line_start":473},{"id":"external_commands:runtime/agy-worker.sh:497:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"tier_seen=$((tier_cli_seen + tier_env_seen))","category":"external_commands","line_end":497,"severity":"medium","line_start":497},{"id":"external_commands:runtime/agy-worker.sh:498:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"model_seen=$((model_cli_seen + model_env_seen))","category":"external_commands","line_end":498,"severity":"medium","line_start":498},{"id":"external_commands:runtime/agy-worker.sh:499:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"effort_seen=$((effort_cli_seen + effort_env_seen))","category":"external_commands","line_end":499,"severity":"medium","line_start":499},{"id":"external_commands:runtime/agy-worker.sh:603:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"boost_policy_sha=\"$(printf '%s' \"$boost_policy_text\" | shasum -a 256 | awk '{print $1}')\"","category":"external_commands","line_end":603,"severity":"medium","line_start":603},{"id":"external_commands:runtime/agy-worker.sh:604:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"expected_boost_risk_sha=\"$(printf '%s\\n%s\\n' \"$boost_policy_sha\" \"$job_id\" | shasum -a 256 | awk '{p","category":"external_commands","line_end":604,"severity":"medium","line_start":604},{"id":"external_commands:runtime/agy-worker.sh:649:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"idle_seconds=\"$(duration_seconds \"$idle_timeout\")\" || { echo \"agy-worker.sh: invalid idle timeout\" >","category":"external_commands","line_end":649,"severity":"medium","line_start":649},{"id":"external_commands:runtime/agy-worker.sh:650:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"hard_seconds=\"$(duration_seconds \"$hard_timeout\")\" || { echo \"agy-worker.sh: invalid hard timeout\" >","category":"external_commands","line_end":650,"severity":"medium","line_start":650},{"id":"external_commands:runtime/agy-worker.sh:651:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"max_seconds=\"$(duration_seconds \"$max_runtime\")\" || { echo \"agy-worker.sh: invalid max runtime\" >&2;","category":"external_commands","line_end":651,"severity":"medium","line_start":651},{"id":"external_commands:runtime/agy-worker.sh:652:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"notice_seconds=\"$(duration_seconds \"$notice_interval\")\" || { echo \"agy-worker.sh: invalid notice int","category":"external_commands","line_end":652,"severity":"medium","line_start":652},{"id":"external_commands:runtime/agy-worker.sh:663:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"prospective_workdir=\"$(CDPATH= cd -- \"$workdir\" 2>/dev/null && pwd -P)\" || {","category":"external_commands","line_end":663,"severity":"medium","line_start":663},{"id":"external_commands:runtime/agy-worker.sh:685:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"if ! LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\"; then","category":"external_commands","line_end":685,"severity":"medium","line_start":685},{"id":"external_commands:runtime/agy-worker.sh:690:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"SCHEMA=\"$(cd \"$(dirname \"$SCHEMA\")\" && pwd)/$(basename \"$SCHEMA\")\"","category":"external_commands","line_end":690,"severity":"medium","line_start":690},{"id":"external_commands:runtime/agy-worker.sh:692:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"workdir=\"$(cd \"$workdir\" && pwd -P)\"","category":"external_commands","line_end":692,"severity":"medium","line_start":692},{"id":"external_commands:runtime/agy-worker.sh:696:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"resolved_dir=\"$(cd \"$d\" && pwd -P)\"","category":"external_commands","line_end":696,"severity":"medium","line_start":696},{"id":"external_commands:runtime/agy-worker.sh:720:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"current_manifest_sha=\"$(","category":"external_commands","line_end":725,"severity":"medium","line_start":720},{"id":"external_commands:runtime/agy-worker.sh:901:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"job_dir_identity=\"$(python3 -I -S -B - \"$job_dir\" <<'PY'","category":"external_commands","line_end":906,"severity":"medium","line_start":901},{"id":"external_commands:runtime/agy-worker.sh:980:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"model=\"$(python3 -B \"$SCRIPT_DIR/scripts/model_selection.py\" \"${selection_args[@]}\")\"","category":"external_commands","line_end":980,"severity":"medium","line_start":980},{"id":"external_commands:runtime/agy-worker.sh:1009:shell-command-substitution","file":"runtime/agy-worker.sh","pattern":"Shell command substitution","snippet":"observed_version=\"$(python3 -B \"$SCRIPT_DIR/scripts/model_selection.py\" \\","category":"external_commands","line_end":1011,"severity":"medium","line_start":1009},{"id":"external_commands:scripts/resolve-pipeline.sh:6:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"SCRIPT_DIR=\"$(CDPATH= cd -- \"$(dirname -- \"${BASH_SOURCE[0]}\")\" && pwd -P)\"","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:scripts/resolve-pipeline.sh:7:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"SKILL_DIR=\"$(CDPATH= cd -- \"$SCRIPT_DIR/..\" && pwd -P)\"","category":"external_commands","line_end":7,"severity":"medium","line_start":7},{"id":"external_commands:scripts/resolve-pipeline.sh:12:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"pipeline_root=\"$(CDPATH= cd -- \"$1\" 2>/dev/null && pwd -P)\" || return 1","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:scripts/resolve-pipeline.sh:19:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"component_canonical=\"$(CDPATH= cd -- \"$parent_canonical/$component\" \\","category":"external_commands","line_end":20,"severity":"medium","line_start":19},{"id":"external_commands:scripts/resolve-pipeline.sh:40:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"runtime_canonical=\"$(CDPATH= cd -- \"$runtime_root\" 2>/dev/null && pwd -P)\" \\","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:scripts/resolve-pipeline.sh:45:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"parent_canonical=\"$(CDPATH= cd -- \"$runtime_canonical/$parent\" \\","category":"external_commands","line_end":46,"severity":"medium","line_start":45},{"id":"external_commands:scripts/resolve-pipeline.sh:93:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"parent_canonical=\"$(CDPATH= cd -- \"$runtime_canonical/$dependency_parent\" \\","category":"external_commands","line_end":94,"severity":"medium","line_start":93},{"id":"external_commands:scripts/resolve-pipeline.sh:154:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"parent_canonical=\"$(CDPATH= cd -- \"$runtime_canonical/$dependency_parent\" \\","category":"external_commands","line_end":155,"severity":"medium","line_start":154},{"id":"external_commands:scripts/resolve-pipeline.sh:164:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"&& \"$(/usr/bin/stat -f '%Lp' \"$dependency_canonical\" 2>/dev/null \\","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:scripts/resolve-pipeline.sh:169:shell-command-substitution","file":"scripts/resolve-pipeline.sh","pattern":"Shell command substitution","snippet":"PLUGIN_ROOT=\"$(CDPATH= cd -- \"$SKILL_DIR/../..\" 2>/dev/null && pwd -P)\" || PLUGIN_ROOT=\"\"","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:23:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"PIPELINE=\"$(bash \"$SKILL_ROOT/scripts/resolve-pipeline.sh\")\" || exit $?","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:42:temp-directory-access","file":"references/SECURITY_AND_COMPATIBILITY.md","pattern":"Temp directory access","snippet":"HOME/TMP/XDG with private directories for scoped launches. Version/help probes are","category":"filesystem","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:runtime/agy-worker.sh:15:template-literal-with-command-substitution","file":"runtime/agy-worker.sh","pattern":"Template literal with command substitution","snippet":"#     `command(<name>)` rule alone is NOT enough. But a worker editing files via its","category":"external_commands","line_end":1262,"severity":"medium","line_start":15},{"id":"external_commands:runtime/ground-truth.sh:14:template-literal-with-command-substitution","file":"runtime/ground-truth.sh","pattern":"Template literal with command substitution","snippet":"# account phase is a separate explicit action because `models`, `agents`, plugin","category":"external_commands","line_end":76,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:22:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:runtime/qa-gate.sh:623:unix-shell-invocation","file":"runtime/qa-gate.sh","pattern":"Unix shell invocation","snippet":"/bin/bash -c \"${verify_specs[$i]}\"","category":"external_commands","line_end":623,"severity":"medium","line_start":623},{"id":"external_commands:runtime/qa-gate.sh:639:unix-shell-invocation","file":"runtime/qa-gate.sh","pattern":"Unix shell invocation","snippet":"/bin/bash -c \"${verify_specs[$i]}\"","category":"external_commands","line_end":639,"severity":"medium","line_start":639},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:27:unix-shell-invocation","file":"runtime/scripts/agy_dispatch_verification.py","pattern":"Unix shell invocation","snippet":"SCRIPT_SHELLS = frozenset({\"/bin/bash\", \"/bin/sh\"})","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1416:unix-shell-invocation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Unix shell invocation","snippet":"\"/bin/sh\", \"-c\", supervisor, \"bounded-git-supervisor\",","category":"external_commands","line_end":1416,"severity":"medium","line_start":1416},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1146:unix-shell-invocation","file":"runtime/scripts/evidence_receipt.py","pattern":"Unix shell invocation","snippet":"\"/bin/bash\",","category":"external_commands","line_end":1146,"severity":"medium","line_start":1146},{"id":"blocker:runtime/agy-worker.sh:154:network-reconnaissance","file":"runtime/agy-worker.sh","pattern":"Network reconnaissance","snippet":"result emits its bound worker envelope unless --format text. A non-zero run exit means","category":"blocker","line_end":154,"severity":"low","line_start":154},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:95:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"--branch \"$JOB_BRANCH\" --base \"$BASE\" --job-id \"$JOB_ID\" \\","category":"blocker","line_end":95,"severity":"low","line_start":95},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:112:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"--branch \"$JOB_BRANCH\" --base \"$BASE\" --job-id \"$JOB_ID\" \\","category":"blocker","line_end":112,"severity":"low","line_start":112},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:201:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"- A structurally valid provider `ERROR` candidate is retrieved and reviewed before","category":"blocker","line_end":201,"severity":"low","line_start":201},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:203:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"- A structurally valid `CANCELED` or `CANCELLED` candidate is preserved for review","category":"blocker","line_end":203,"severity":"low","line_start":203},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:254:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"\"$PIPELINE/agy-worker.sh\" verification-copy --job-id \"$JOB_ID\" \\","category":"blocker","line_end":254,"severity":"low","line_start":254},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:286:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"STATUS_JSON=\"$(\"$PIPELINE/agy-worker.sh\" status --job-id \"$JOB_ID\" --format json)\"","category":"blocker","line_end":286,"severity":"low","line_start":286},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:321:system-reconnaissance","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"System reconnaissance","snippet":"\"$PIPELINE/agy-worker.sh\" continue --job-id \"$JOB_ID\" \\","category":"blocker","line_end":321,"severity":"low","line_start":321},{"id":"blocker:references/TROUBLESHOOTING.md:54:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"failure. A model change cannot repair a permission, missing executable, invalid","category":"blocker","line_end":55,"severity":"low","line_start":54},{"id":"blocker:references/TROUBLESHOOTING.md:65:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"This can be valid CLI behavior. Parse `result.structured_output`; do not treat the","category":"blocker","line_end":65,"severity":"low","line_start":65},{"id":"blocker:references/TROUBLESHOOTING.md:88:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"that same intended job and transmission. An invalid or stale digest, broader workflow,","category":"blocker","line_end":88,"severity":"low","line_start":88},{"id":"blocker:references/TROUBLESHOOTING.md:96:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"A structurally valid `ERROR` candidate is reviewable. Retrieve `result`, inspect the","category":"blocker","line_end":96,"severity":"low","line_start":96},{"id":"blocker:references/TROUBLESHOOTING.md:100:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"A structurally valid `CANCELED` or `CANCELLED` candidate is preserved for review and","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:references/TROUBLESHOOTING.md:139:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"outward/broken/Git-administration symlinks, or an invalid destination boundary. A","category":"blocker","line_end":139,"severity":"low","line_start":139},{"id":"blocker:references/TROUBLESHOOTING.md:141:system-reconnaissance","file":"references/TROUBLESHOOTING.md","pattern":"System reconnaissance","snippet":"only when its bounded inspection is small enough; otherwise the failure stays an invalid","category":"blocker","line_end":142,"severity":"low","line_start":141},{"id":"blocker:runtime/agents/bulk-test-writer.md:46:system-reconnaissance","file":"runtime/agents/bulk-test-writer.md","pattern":"System reconnaissance","snippet":"invalid state that the public constructor deliberately rejects, first create a valid","category":"blocker","line_end":46,"severity":"low","line_start":46},{"id":"blocker:runtime/agents/diff-reviewer.md:34:system-reconnaissance","file":"runtime/agents/diff-reviewer.md","pattern":"System reconnaissance","snippet":"4. **Secret exposure** — credentials, tokens, internal hostnames added to tracked files.","category":"blocker","line_end":34,"severity":"low","line_start":34},{"id":"blocker:runtime/agents/repo-inventory.md:40:system-reconnaissance","file":"runtime/agents/repo-inventory.md","pattern":"System reconnaissance","snippet":"- Report only what you actually read. If you did not open a file, do not describe","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"blocker:runtime/agy-worker.sh:2:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"# agy-worker.sh — dispatch a bounded job to agy and return a schema-valid result envelope.","category":"blocker","line_end":2,"severity":"low","line_start":2},{"id":"blocker:runtime/agy-worker.sh:79:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"valid = (","category":"blocker","line_end":79,"severity":"low","line_start":79},{"id":"blocker:runtime/agy-worker.sh:82:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"and metadata.st_uid == os.geteuid()","category":"blocker","line_end":82,"severity":"low","line_start":82},{"id":"blocker:runtime/agy-worker.sh:85:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"raise SystemExit(0 if valid else 1)","category":"blocker","line_end":85,"severity":"low","line_start":85},{"id":"blocker:runtime/agy-worker.sh:134:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh status|result --job-id JOB [--format json|text]","category":"blocker","line_end":134,"severity":"low","line_start":134},{"id":"blocker:runtime/agy-worker.sh:135:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh verification-copy --job-id JOB --destination NEW_DIRECTORY_IN_0700_PARENT [--format js","category":"blocker","line_end":135,"severity":"low","line_start":135},{"id":"blocker:runtime/agy-worker.sh:136:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh self-verify --job-id JOB --approve-state-sha SHA [--format json|text]","category":"blocker","line_end":136,"severity":"low","line_start":136},{"id":"blocker:runtime/agy-worker.sh:137:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh resume --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] [--format js","category":"blocker","line_end":137,"severity":"low","line_start":137},{"id":"blocker:runtime/agy-worker.sh:138:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh restart --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] [--format j","category":"blocker","line_end":138,"severity":"low","line_start":138},{"id":"blocker:runtime/agy-worker.sh:139:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh continue --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] [--format ","category":"blocker","line_end":139,"severity":"low","line_start":139},{"id":"blocker:runtime/agy-worker.sh:140:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh continue --job-id JOB --approve-state-sha SHA --use-self-verification [--format json|t","category":"blocker","line_end":140,"severity":"low","line_start":140},{"id":"blocker:runtime/agy-worker.sh:141:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh finalize --job-id JOB --approve-state-sha SHA [--approve-migration-sha SHA] \\","category":"blocker","line_end":141,"severity":"low","line_start":141},{"id":"blocker:runtime/agy-worker.sh:143:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh wait --job-id JOB --after-state-sha SHA [--timeout 60s] [--format json|text]","category":"blocker","line_end":143,"severity":"low","line_start":143},{"id":"blocker:runtime/agy-worker.sh:144:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh cancel --job-id JOB --approve-state-sha SHA","category":"blocker","line_end":144,"severity":"low","line_start":144},{"id":"blocker:runtime/agy-worker.sh:145:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh extend --job-id JOB --approve-state-sha SHA --by 2h","category":"blocker","line_end":145,"severity":"low","line_start":145},{"id":"blocker:runtime/agy-worker.sh:155:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"stdout is NOT a valid envelope. Artifacts land in $AGY_WORKER_LOG_DIR.","category":"blocker","line_end":155,"severity":"low","line_start":155},{"id":"blocker:runtime/agy-worker.sh:157:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"Exit codes: 0 ok · 2 no prompt · 3 empty output · 4 schema invalid · 5 unclassified agy failure","category":"blocker","line_end":157,"severity":"low","line_start":157},{"id":"blocker:runtime/agy-worker.sh:163:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"64 invalid usage","category":"blocker","line_end":163,"severity":"low","line_start":163},{"id":"blocker:runtime/agy-worker.sh:166:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh resume --job-id JOB --approve-state-sha STATE_SHA","category":"blocker","line_end":166,"severity":"low","line_start":166},{"id":"blocker:runtime/agy-worker.sh:167:system-reconnaissance","file":"runtime/agy-worker.sh","pattern":"System reconnaissance","snippet":"agy-worker.sh restart --job-id JOB --approve-state-sha STATE_SHA","category":"blocker","line_end":167,"severity":"low","line_start":167},{"id":"blocker:scripts/resolve-pipeline.sh:183:system-reconnaissance","file":"scripts/resolve-pipeline.sh","pattern":"System reconnaissance","snippet":"echo \"agy-worker: invalid standalone pipeline marker\" >&2","category":"blocker","line_end":183,"severity":"low","line_start":183},{"id":"env_access:runtime/scripts/agy_dispatch_verification.py:151:configuration-library","file":"runtime/scripts/agy_dispatch_verification.py","pattern":"Configuration library","snippet":"raise VerificationError(\"verification descendants remain unconfirmed\")","category":"env_access","line_end":151,"severity":"low","line_start":151},{"id":"network:runtime/compat/agy-version-manifest.json:20:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.2.7-6731160","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:runtime/compat/agy-version-manifest.json:64:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.2.6-5912685","category":"network","line_end":64,"severity":"low","line_start":64},{"id":"network:runtime/compat/agy-version-manifest.json:111:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.2.2-6061403","category":"network","line_end":111,"severity":"low","line_start":111},{"id":"network:runtime/compat/agy-version-manifest.json:163:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.27-521119","category":"network","line_end":163,"severity":"low","line_start":163},{"id":"network:runtime/compat/agy-version-manifest.json:212:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.26-555015","category":"network","line_end":212,"severity":"low","line_start":212},{"id":"network:runtime/compat/agy-version-manifest.json:257:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.12-587761","category":"network","line_end":257,"severity":"low","line_start":257},{"id":"network:runtime/compat/agy-version-manifest.json:277:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.16-660797","category":"network","line_end":277,"severity":"low","line_start":277},{"id":"network:runtime/compat/agy-version-manifest.json:303:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://storage.googleapis.com/antigravity-public/antigravity-cli/1.1.22-571154","category":"network","line_end":303,"severity":"low","line_start":303},{"id":"network:runtime/compat/agy-version-manifest.json:347:hardcoded-url","file":"runtime/compat/agy-version-manifest.json","pattern":"Hardcoded URL","snippet":"\"distribution_url\": \"https://github.com/google-antigravity/antigravity-cli/releases/download/1.1.24/","category":"network","line_end":347,"severity":"low","line_start":347},{"id":"network:runtime/compat/model-effort-matrix.schema.json:2:hardcoded-url","file":"runtime/compat/model-effort-matrix.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/compat/model-effort-matrix.schema.json:3:hardcoded-url","file":"runtime/compat/model-effort-matrix.schema.json","pattern":"Hardcoded URL","snippet":"\"$id\": \"https://cagdasyurekli.github.io/codex-agy-worker/schemas/model-effort-matrix-v1.json\",","category":"network","line_end":3,"severity":"low","line_start":3},{"id":"network:runtime/compat/version-manifest.schema.json:2:hardcoded-url","file":"runtime/compat/version-manifest.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/benchmark-plan.schema.json:1:hardcoded-url","file":"runtime/schemas/benchmark-plan.schema.json","pattern":"Hardcoded URL","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"exp","category":"network","line_end":1,"severity":"low","line_start":1},{"id":"network:runtime/schemas/benchmark-result.schema.json:1:hardcoded-url","file":"runtime/schemas/benchmark-result.schema.json","pattern":"Hardcoded URL","snippet":"{\"$schema\":\"http://json-schema.org/draft-07/schema#\",\"additionalProperties\":false,\"properties\":{\"com","category":"network","line_end":1,"severity":"low","line_start":1},{"id":"network:runtime/schemas/delegation-policy.schema.json:2:hardcoded-url","file":"runtime/schemas/delegation-policy.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/evidence-receipt.schema.json:2:hardcoded-url","file":"runtime/schemas/evidence-receipt.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/job-state.schema.json:2:hardcoded-url","file":"runtime/schemas/job-state.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-preview.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-advisory-preview.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-advisory-summary.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-aggregate.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-evaluation.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-evaluation.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:runtime/schemas/model-evidence-campaign-plan.schema.json:2:hardcoded-url","file":"runtime/schemas/model-evidence-campaign-plan.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"env_access:runtime/scripts/agy_dispatch_worktree.py:1379:python-environment-access","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Python environment access","snippet":"environment = os.environ.copy()","category":"env_access","line_end":1379,"severity":"low","line_start":1379},{"id":"env_access:runtime/scripts/evidence_receipt.py:1115:python-environment-access","file":"runtime/scripts/evidence_receipt.py","pattern":"Python environment access","snippet":"if name in os.environ:","category":"env_access","line_end":1115,"severity":"low","line_start":1115},{"id":"env_access:runtime/scripts/evidence_receipt.py:1117:python-environment-access","file":"runtime/scripts/evidence_receipt.py","pattern":"Python environment access","snippet":"(os.fsencode(name), b\"\\0\", os.fsencode(os.environ[name]), b\"\\0\")","category":"env_access","line_end":1117,"severity":"low","line_start":1117},{"id":"env_access:runtime/scripts/evidence_receipt.py:1521:python-environment-access","file":"runtime/scripts/evidence_receipt.py","pattern":"Python environment access","snippet":"os.execvpe(command[0], command, dict(os.environ))","category":"env_access","line_end":1521,"severity":"low","line_start":1521},{"id":"env_access:runtime/scripts/feedback-triage.py:360:python-environment-access","file":"runtime/scripts/feedback-triage.py","pattern":"Python environment access","snippet":"environment = os.environ.copy()","category":"env_access","line_end":360,"severity":"low","line_start":360},{"id":"env_access:runtime/scripts/model_selection.py:98:python-environment-access","file":"runtime/scripts/model_selection.py","pattern":"Python environment access","snippet":"environment = {name: os.environ[name] for name in allowed if name in os.environ}","category":"env_access","line_end":98,"severity":"low","line_start":98},{"id":"env_access:runtime/scripts/workflow.py:711:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"configured = os.environ.get(\"XDG_STATE_HOME\")","category":"env_access","line_end":711,"severity":"low","line_start":711},{"id":"env_access:runtime/scripts/workflow.py:718:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"home_text = os.environ.get(\"HOME\")","category":"env_access","line_end":718,"severity":"low","line_start":718},{"id":"env_access:runtime/scripts/workflow.py:750:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"environment = dict(os.environ)","category":"env_access","line_end":750,"severity":"low","line_start":750},{"id":"env_access:runtime/scripts/workflow.py:1115:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"env = dict(os.environ)","category":"env_access","line_end":1115,"severity":"low","line_start":1115},{"id":"env_access:runtime/scripts/workflow.py:1186:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"os.environ.get(\"AGY_WORKER_LOG_DIR\") or (state_path.parent / \"logs\")","category":"env_access","line_end":1186,"severity":"low","line_start":1186},{"id":"env_access:runtime/scripts/workflow.py:1598:python-environment-access","file":"runtime/scripts/workflow.py","pattern":"Python environment access","snippet":"os.environ.get(\"AGY_WORKER_LOG_DIR\") or (SCRIPTS.parent / \"logs\")","category":"env_access","line_end":1598,"severity":"low","line_start":1598},{"id":"filesystem:runtime/qa-gate.sh:434:python-glob-pattern-matching","file":"runtime/qa-gate.sh","pattern":"Python glob/pattern matching","snippet":"import fnmatch","category":"filesystem","line_end":434,"severity":"low","line_start":434},{"id":"filesystem:runtime/qa-gate.sh:513:python-glob-pattern-matching","file":"runtime/qa-gate.sh","pattern":"Python glob/pattern matching","snippet":"if not any(fnmatch.fnmatchcase(path, pattern) for pattern in allow)","category":"filesystem","line_end":513,"severity":"low","line_start":513},{"id":"filesystem:runtime/qa-gate.sh:518:python-glob-pattern-matching","file":"runtime/qa-gate.sh","pattern":"Python glob/pattern matching","snippet":"if only and not any(fnmatch.fnmatchcase(path, pattern) for pattern in only)","category":"filesystem","line_end":518,"severity":"low","line_start":518},{"id":"network:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:25:python-http-libraries","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Python HTTP libraries","snippet":"scoped work; provider-launch notices are status, not repeated permission requests.","category":"network","line_end":25,"severity":"low","line_start":25},{"id":"network:runtime/scripts/codex_usage_report.py:726:python-http-libraries","file":"runtime/scripts/codex_usage_report.py","pattern":"Python HTTP libraries","snippet":"pending_requests.pop(resp_id, None)","category":"network","line_end":726,"severity":"low","line_start":726},{"id":"network:SKILL.md:36:python-http-libraries","file":"SKILL.md","pattern":"Python HTTP libraries","snippet":"digest/state refresh; provider-launch notices are status, not repeated permission requests.","category":"network","line_end":36,"severity":"low","line_start":36},{"id":"filesystem:runtime/agy-worker.sh:237:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\" || exit 64","category":"filesystem","line_end":237,"severity":"low","line_start":237},{"id":"filesystem:runtime/agy-worker.sh:663:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"prospective_workdir=\"$(CDPATH= cd -- \"$workdir\" 2>/dev/null && pwd -P)\" || {","category":"filesystem","line_end":663,"severity":"low","line_start":663},{"id":"filesystem:runtime/agy-worker.sh:673:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"mkdir -p \"$LOG_DIR\" 2>/dev/null || {","category":"filesystem","line_end":673,"severity":"low","line_start":673},{"id":"filesystem:runtime/agy-worker.sh:685:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"if ! LOG_DIR=\"$(CDPATH= cd -- \"$LOG_DIR\" 2>/dev/null && pwd -P)\"; then","category":"filesystem","line_end":685,"severity":"low","line_start":685},{"id":"filesystem:runtime/agy-worker.sh:897:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"if ! mkdir \"$job_dir\" 2>/dev/null; then","category":"filesystem","line_end":897,"severity":"low","line_start":897},{"id":"filesystem:runtime/agy-worker.sh:1011:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"--observe-installed-version 2>/dev/null)\"","category":"filesystem","line_end":1011,"severity":"low","line_start":1011},{"id":"filesystem:runtime/agy-worker.sh:1030:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"--verify-record-executable \"$selection_file\" > /dev/null 2>&1","category":"filesystem","line_end":1030,"severity":"low","line_start":1030},{"id":"filesystem:runtime/agy-worker.sh:1200:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"chmod 0700 \"$staged_dir\" 2>/dev/null || true","category":"filesystem","line_end":1200,"severity":"low","line_start":1200},{"id":"filesystem:runtime/agy-worker.sh:1201:standard-device-file-access","file":"runtime/agy-worker.sh","pattern":"Standard device file access","snippet":"[[ ! -f \"$staged_prompt_file\" ]] || chmod 0600 \"$staged_prompt_file\" 2>/dev/null || true","category":"filesystem","line_end":1201,"severity":"low","line_start":1201},{"id":"filesystem:runtime/doctor.sh:21:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"*) source_path=\"$(command -v -- \"$source_path\" 2>/dev/null || true)\" ;;","category":"filesystem","line_end":21,"severity":"low","line_start":21},{"id":"filesystem:runtime/doctor.sh:24:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"CDPATH= cd -- \"${source_path%/*}\" 2>/dev/null && pwd -P","category":"filesystem","line_end":24,"severity":"low","line_start":24},{"id":"filesystem:runtime/doctor.sh:32:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"runtime_canonical=\"$(CDPATH= cd -- \"$runtime_root\" 2>/dev/null && pwd -P)\" \\","category":"filesystem","line_end":32,"severity":"low","line_start":32},{"id":"filesystem:runtime/doctor.sh:38:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":38,"severity":"low","line_start":38},{"id":"filesystem:runtime/doctor.sh:86:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":86,"severity":"low","line_start":86},{"id":"filesystem:runtime/doctor.sh:147:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":147,"severity":"low","line_start":147},{"id":"filesystem:runtime/doctor.sh:156:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"&& \"$(/usr/bin/stat -f '%Lp' \"$dependency_canonical\" 2>/dev/null \\","category":"filesystem","line_end":156,"severity":"low","line_start":156},{"id":"filesystem:runtime/doctor.sh:157:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"|| /usr/bin/stat -c '%a' \"$dependency_canonical\" 2>/dev/null)\" == 644 ]] || return 1","category":"filesystem","line_end":157,"severity":"low","line_start":157},{"id":"filesystem:runtime/doctor.sh:172:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"CDPATH= cd -- \"$1\" 2>/dev/null && pwd -P","category":"filesystem","line_end":172,"severity":"low","line_start":172},{"id":"filesystem:runtime/doctor.sh:198:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"2>/dev/null || cleanup_failed=1","category":"filesystem","line_end":198,"severity":"low","line_start":198},{"id":"filesystem:runtime/doctor.sh:199:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"/bin/rmdir \"$workspace\" 2>/dev/null || cleanup_failed=1","category":"filesystem","line_end":199,"severity":"low","line_start":199},{"id":"filesystem:runtime/doctor.sh:225:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"\"$base_dir/agy-worker-doctor.XXXXXX\" 2>/dev/null)\"","category":"filesystem","line_end":225,"severity":"low","line_start":225},{"id":"filesystem:runtime/doctor.sh:230:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"/bin/chmod 700 \"$workspace\" 2>/dev/null || {","category":"filesystem","line_end":230,"severity":"low","line_start":230},{"id":"filesystem:runtime/doctor.sh:231:standard-device-file-access","file":"runtime/doctor.sh","pattern":"Standard device file access","snippet":"/bin/rmdir \"$workspace\" 2>/dev/null || true","category":"filesystem","line_end":231,"severity":"low","line_start":231},{"id":"filesystem:scripts/resolve-pipeline.sh:12:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"pipeline_root=\"$(CDPATH= cd -- \"$1\" 2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":12,"severity":"low","line_start":12},{"id":"filesystem:scripts/resolve-pipeline.sh:20:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":20,"severity":"low","line_start":20},{"id":"filesystem:scripts/resolve-pipeline.sh:40:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"runtime_canonical=\"$(CDPATH= cd -- \"$runtime_root\" 2>/dev/null && pwd -P)\" \\","category":"filesystem","line_end":40,"severity":"low","line_start":40},{"id":"filesystem:scripts/resolve-pipeline.sh:46:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":46,"severity":"low","line_start":46},{"id":"filesystem:scripts/resolve-pipeline.sh:94:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":94,"severity":"low","line_start":94},{"id":"filesystem:scripts/resolve-pipeline.sh:155:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"2>/dev/null && pwd -P)\" || return 1","category":"filesystem","line_end":155,"severity":"low","line_start":155},{"id":"filesystem:scripts/resolve-pipeline.sh:164:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"&& \"$(/usr/bin/stat -f '%Lp' \"$dependency_canonical\" 2>/dev/null \\","category":"filesystem","line_end":164,"severity":"low","line_start":164},{"id":"filesystem:scripts/resolve-pipeline.sh:165:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"|| /usr/bin/stat -c '%a' \"$dependency_canonical\" 2>/dev/null)\" == 644 ]] || return 1","category":"filesystem","line_end":165,"severity":"low","line_start":165},{"id":"filesystem:scripts/resolve-pipeline.sh:169:standard-device-file-access","file":"scripts/resolve-pipeline.sh","pattern":"Standard device file access","snippet":"PLUGIN_ROOT=\"$(CDPATH= cd -- \"$SKILL_DIR/../..\" 2>/dev/null && pwd -P)\" || PLUGIN_ROOT=\"\"","category":"filesystem","line_end":169,"severity":"low","line_start":169},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:81:temp-file-creation","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Temp file creation","snippet":"STATE_DIR=\"$(mktemp -d -t agyworker-state.XXXXXX)\"","category":"filesystem","line_end":81,"severity":"low","line_start":81},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:82:temp-file-creation","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Temp file creation","snippet":"WT=\"$(mktemp -d -t agyworker-worktree.XXXXXX)\"","category":"filesystem","line_end":82,"severity":"low","line_start":82},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:251:temp-file-creation","file":"references/PROJECT_LIFECYCLE_AND_VERIFICATION.md","pattern":"Temp file creation","snippet":"VERIFY_PARENT=\"$(mktemp -d -t agyworker-verify.XXXXXX)\" || exit $?","category":"filesystem","line_end":251,"severity":"low","line_start":251},{"id":"filesystem:runtime/doctor.sh:224:temp-file-creation","file":"runtime/doctor.sh","pattern":"Temp file creation","snippet":"workspace=\"$(/usr/bin/mktemp -d \\","category":"filesystem","line_end":224,"severity":"low","line_start":224},{"id":"filesystem:runtime/qa-gate.sh:314:temp-file-creation","file":"runtime/qa-gate.sh","pattern":"Temp file creation","snippet":"workspace=\"$(/usr/bin/mktemp -d \\","category":"filesystem","line_end":314,"severity":"low","line_start":314},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:814:temp-file-creation","file":"runtime/scripts/agy_dispatch_worktree.py","pattern":"Temp file creation","snippet":"# `mktemp` commonly returns /var/... on macOS while","category":"filesystem","line_end":814,"severity":"low","line_start":814},{"id":"filesystem:runtime/scripts/benchmark.py:24:temp-file-creation","file":"runtime/scripts/benchmark.py","pattern":"Temp file creation","snippet":"import tempfile","category":"filesystem","line_end":24,"severity":"low","line_start":24},{"id":"filesystem:runtime/scripts/benchmark.py:756:temp-file-creation","file":"runtime/scripts/benchmark.py","pattern":"Temp file creation","snippet":"work = Path(tempfile.mkdtemp(prefix=\"agy-benchmark.\", dir=str(root)))","category":"filesystem","line_end":756,"severity":"low","line_start":756},{"id":"filesystem:runtime/scripts/codex_usage_report.py:31:temp-file-creation","file":"runtime/scripts/codex_usage_report.py","pattern":"Temp file creation","snippet":"import tempfile","category":"filesystem","line_end":31,"severity":"low","line_start":31},{"id":"filesystem:runtime/scripts/codex_usage_report.py:221:temp-file-creation","file":"runtime/scripts/codex_usage_report.py","pattern":"Temp file creation","snippet":"with tempfile.TemporaryDirectory(prefix=\"agy-codex-schema-\") as temp_dir:","category":"filesystem","line_end":221,"severity":"low","line_start":221},{"id":"filesystem:runtime/scripts/job_lifecycle.py:26:temp-file-creation","file":"runtime/scripts/job_lifecycle.py","pattern":"Temp file creation","snippet":"import tempfile","category":"filesystem","line_end":26,"severity":"low","line_start":26},{"id":"filesystem:runtime/scripts/job_lifecycle.py:837:temp-file-creation","file":"runtime/scripts/job_lifecycle.py","pattern":"Temp file creation","snippet":"directory = Path(tempfile.mkdtemp(prefix=\"agy-worker-empty-hooks.\", dir=\"/tmp\"))","category":"filesystem","line_end":837,"severity":"low","line_start":837}],"finding_verdicts":[{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1002:certificate-key-files","reason":"The code validates bound Keychain metadata and preference-file identity before launch. It does not embed or extract certificate or private-key material.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1004:certificate-key-files","reason":"The code validates bound Keychain metadata and preference-file identity before launch. It does not embed or extract certificate or private-key material.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1007:certificate-key-files","reason":"The code validates bound Keychain metadata and preference-file identity before launch. It does not embed or extract certificate or private-key material.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1008:certificate-key-files","reason":"The code validates bound Keychain metadata and preference-file identity before launch. It does not embed or extract certificate or private-key material.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch_containment.py:1018:certificate-key-files","reason":"The code validates bound Keychain metadata and preference-file identity before launch. It does not embed or extract certificate or private-key material.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2581:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch_worktree.py:2597:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch.py:4444:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/agy_dispatch.py:4465:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:430:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:457:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:470:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:489:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:501:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:510:certificate-key-files","reason":"The code validates bound Keychain metadata and preference-file identity before launch. It does not embed or extract certificate or private-key material.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:512:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:524:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:530:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:539:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:546:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:587:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:607:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:613:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:runtime/scripts/model_evidence_campaign.py:628:certificate-key-files","reason":"The match is Python dictionary key validation, not certificate or private-key handling. The snippet compares permitted object fields.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:references/SECURITY_AND_COMPATIBILITY.md:26:crypto-seed-private-key-mention","reason":"The documentation warns operators to exclude private keys from provider-readable content. This is a protective instruction, not secret collection or key handling.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:50:crypto-seed-private-key-mention","reason":"The documentation warns operators to exclude private keys from provider-readable content. This is a protective instruction, not secret collection or key handling.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/benchmarks/v1/portable-source.json:1:heuristic-extremely-long-line-2076-chars-likely-","reason":"The file is compact machine-readable JSON containing schemas or a checksum manifest. Its long line is valid structured data, not an encoded executable payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-advisory.schema.json:1:heuristic-extremely-long-line-2424-chars-likely-","reason":"The file is compact machine-readable JSON containing schemas or a checksum manifest. Its long line is valid structured data, not an encoded executable payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-plan.schema.json:1:heuristic-extremely-long-line-2929-chars-likely-","reason":"The file is compact machine-readable JSON containing schemas or a checksum manifest. Its long line is valid structured data, not an encoded executable payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/schemas/benchmark-result.schema.json:1:heuristic-extremely-long-line-3160-chars-likely-","reason":"The file is compact machine-readable JSON containing schemas or a checksum manifest. Its long line is valid structured data, not an encoded executable payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/schemas/swebench-workflow-study-report.schema.json:1:heuristic-extremely-long-line-6721-chars-likely-","reason":"The file is compact machine-readable JSON containing schemas or a checksum manifest. Its long line is valid structured data, not an encoded executable payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/schemas/benchmark-plan.schema.json:1:heuristic-extremely-long-line-7848-chars-likely-","reason":"The file is compact machine-readable JSON containing schemas or a checksum manifest. Its long line is valid structured data, not an encoded executable payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:1:heuristic-multiple-bracket-chains-20-jsfuck-obfu","reason":"The bracket sequence comes from nested JSON Schema syntax or ordinary Python type expressions. No JSFuck interpreter, decoder, or hidden payload is present.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/schemas/model-selection.schema.json:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","reason":"The bracket sequence comes from nested JSON Schema syntax or ordinary Python type expressions. No JSFuck interpreter, decoder, or hidden payload is present.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","reason":"The bracket sequence comes from nested JSON Schema syntax or ordinary Python type expressions. No JSFuck interpreter, decoder, or hidden payload is present.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch_containment.py:1:heuristic-multiple-bracket-chains-9-jsfuck-obfus","reason":"The bracket sequence comes from nested JSON Schema syntax or ordinary Python type expressions. No JSFuck interpreter, decoder, or hidden payload is present.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/evidence_report.py:131:heuristic-very-high-entropy-string-6-02-bits-lik","reason":"The matched value is an explicit alphabet of permitted characters used for validation. It is readable source data, not encrypted or encoded payload content.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch_containment.py:582:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch_containment.py:612:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2563:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch_worktree.py:2605:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:723:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:1361:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2586:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2608:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2752:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/agy_dispatch.py:2759:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/compatibility.py:174:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/evidence_report.py:145:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/job_lifecycle.py:392:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/model_selection.py:625:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/model_selection.py:640:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:runtime/scripts/swebench_workflow_study.py:58:hex-encoded-characters","reason":"The code checks for NUL and control characters in untrusted text. The escape literals implement input rejection and do not decode or conceal a payload.","verdict":"false_positive","confidence":0.97},{"id":"env_access:runtime/qa-gate.sh:120:database-connection-strings","reason":"The database variable names appear in a credential denylist used to require stronger authorization. No connection string value is read at this location.","verdict":"false_positive","confidence":0.97},{"id":"env_access:runtime/scripts/evidence_receipt.py:955:database-connection-strings","reason":"The database variable names appear in a credential denylist used to require stronger authorization. No connection string value is read at this location.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-in-home-directory","reason":"The matched home-directory text is documentation or a provider prompt that forbids access to ~/.gemini and other user directories. It does not perform filesystem access.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-in-home-directory","reason":"The optional account phase reads ~/.gemini/antigravity-cli/settings.json from the user's home directory. The action is documented and explicit, but it accesses private tool configuration.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2564:hidden-file-in-home-directory","reason":"The matched home-directory text is documentation or a provider prompt that forbids access to ~/.gemini and other user directories. It does not perform filesystem access.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:816:non-standard-device-file-access","reason":"The native sandbox profile permits writes to inherited /dev/fd descriptors. It does not open a hardware device or grant general device-file access.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:204:path-traversal-sequence","reason":"The sequence is a relative Markdown link to package documentation. It is not used as a runtime filesystem path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/qa-gate.sh:472:path-traversal-sequence","reason":"The code explicitly detects and rejects parent traversal or absolute paths. The matched sequence is part of a boundary check.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:591:path-traversal-sequence","reason":"The code explicitly detects and rejects parent traversal or absolute paths. The matched sequence is part of a boundary check.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:2610:path-traversal-sequence","reason":"The code explicitly detects and rejects parent traversal or absolute paths. The matched sequence is part of a boundary check.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3540:path-traversal-sequence","reason":"The traversal text appears only in a comment explaining a contained-symlink edge case. Runtime code resolves and verifies the target before use.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:169:path-traversal-sequence","reason":"The resolver computes a fixed package-relative parent and immediately validates expected plugin markers and canonical paths. No untrusted traversal component is accepted.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:777:process-exec","reason":"The native sandbox profile explicitly allows the provider process to execute the bound target and tools from staged and system paths. This is required functionality, but it grants meaningful command-execution authority.","verdict":"confirmed","severity":"high","confidence":0.94},{"id":"external_commands:runtime/scripts/agy_dispatch.py:2937:process-exec","reason":"The match is the fixed-path loading of a bundled helper or a declarative sandbox rule. It does not evaluate caller-controlled source text.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6003:process-spawn","reason":"The match names the dispatch lifecycle function or calls it with fixed internal modes. The actual provider process launch is separately identified and adjudicated.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6486:process-spawn","reason":"The match names the dispatch lifecycle function or calls it with fixed internal modes. The actual provider process launch is separately identified and adjudicated.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6640:process-spawn","reason":"The match names the dispatch lifecycle function or calls it with fixed internal modes. The actual provider process launch is separately identified and adjudicated.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6642:process-spawn","reason":"The match names the dispatch lifecycle function or calls it with fixed internal modes. The actual provider process launch is separately identified and adjudicated.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6646:process-spawn","reason":"The match names the dispatch lifecycle function or calls it with fixed internal modes. The actual provider process launch is separately identified and adjudicated.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6652:process-spawn","reason":"The match names the dispatch lifecycle function or calls it with fixed internal modes. The actual provider process launch is separately identified and adjudicated.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/agy-worker.sh:1430:python-import-function","reason":"The embedded Python uses __import__ only for fixed standard-library modules such as stat and hashlib. Module names are constants and cannot be supplied by a caller.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/agy-worker.sh:1431:python-import-function","reason":"The embedded Python uses __import__ only for fixed standard-library modules such as stat and hashlib. Module names are constants and cannot be supplied by a caller.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/agy-worker.sh:1443:python-import-function","reason":"The embedded Python uses __import__ only for fixed standard-library modules such as stat and hashlib. Module names are constants and cannot be supplied by a caller.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/agy-worker.sh:1446:python-import-function","reason":"The embedded Python uses __import__ only for fixed standard-library modules such as stat and hashlib. Module names are constants and cannot be supplied by a caller.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/agy-worker.sh:1457:python-import-function","reason":"The embedded Python uses __import__ only for fixed standard-library modules such as stat and hashlib. Module names are constants and cannot be supplied by a caller.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/agy-worker.sh:1478:python-import-function","reason":"The embedded Python uses __import__ only for fixed standard-library modules such as stat and hashlib. Module names are constants and cannot be supplied by a caller.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/agy_dispatch_containment.py:777:python-exec-function","reason":"The exec compiles a fixed sibling Python module from the installed bundle, or the text is a sandbox profile directive. No user-controlled code string is evaluated.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/agy_dispatch.py:2937:python-exec-function","reason":"The exec compiles a fixed sibling Python module from the installed bundle, or the text is a sandbox profile directive. No user-controlled code string is evaluated.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:674:python-globals-manipulation","reason":"The code exposes a fixed allowlist of bundled helper functions for portable module loading and test patching. Caller input cannot choose the global names.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/agy_dispatch_worktree.py:4215:python-globals-manipulation","reason":"The code exposes a fixed allowlist of bundled helper functions for portable module loading and test patching. Caller input cannot choose the global names.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/agy_dispatch.py:46:python-globals-manipulation","reason":"The code exposes a fixed allowlist of bundled helper functions for portable module loading and test patching. Caller input cannot choose the global names.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/agy_dispatch.py:3207:python-globals-manipulation","reason":"The code exposes a fixed allowlist of bundled helper functions for portable module loading and test patching. Caller input cannot choose the global names.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1521:python-os-exec-variants","reason":"The no-shell verifier replaces the process with a caller-selected, validated argv command. Validation limits parsing attacks, but the feature intentionally executes external project tooling.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:278:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:308:python-subprocess-popen","reason":"The process uses a fixed executable and argument vector for local Git, schema validation, controller, or Keychain discovery. No shell interpolation or caller-selected executable is present.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:94:python-subprocess-popen","reason":"This Popen launches the selected verification command inside the prepared containment profile. Verification can execute repository code, so the documented approval and isolation controls remain security-critical.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:205:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:238:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:244:python-subprocess-popen","reason":"The process uses a fixed executable and argument vector for local Git, schema validation, controller, or Keychain discovery. No shell interpolation or caller-selected executable is present.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1396:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1414:python-subprocess-popen","reason":"The process uses a fixed executable and argument vector for local Git, schema validation, controller, or Keychain discovery. No shell interpolation or caller-selected executable is present.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3964:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4028:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4572:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4949:python-subprocess-popen","reason":"This Popen is the live Antigravity provider launch and gives the external worker access to approved repository content. The executable and environment are bound, but provider execution remains a high-impact trust boundary.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6021:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6038:python-subprocess-popen","reason":"The process uses a fixed executable and argument vector for local Git, schema validation, controller, or Keychain discovery. No shell interpolation or caller-selected executable is present.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/benchmark.py:135:python-subprocess-popen","reason":"The benchmark launches fixed, manifest-bound local verification commands with a minimal environment and time limits. The plan does not accept arbitrary executable payloads.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/benchmark.py:581:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/benchmark.py:594:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/benchmark.py:606:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/benchmark.py:615:python-subprocess-popen","reason":"The benchmark launches fixed, manifest-bound local verification commands with a minimal environment and time limits. The plan does not accept arbitrary executable payloads.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/codex_usage_report.py:115:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/codex_usage_report.py:157:python-subprocess-popen","reason":"The report launches the fixed local Codex app-server protocol with bounded streams. It does not construct a shell command or pass repository text as executable input.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/codex_usage_report.py:647:python-subprocess-popen","reason":"The report launches the fixed local Codex app-server protocol with bounded streams. It does not construct a shell command or pass repository text as executable input.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/doctor-metadata.py:92:python-subprocess-popen","reason":"The match is a type annotation or process-cleanup helper, not a process launch.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/qa-gate.sh:447:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3408:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:3686:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4547:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:4552:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/agy_dispatch.py:6432:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/benchmark.py:347:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/candidate_state.py:30:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/evidence_receipt.py:468:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:493:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:544:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:576:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:762:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:784:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:1121:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:1800:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:runtime/scripts/workflow.py:1854:python-subprocess-run","reason":"The subprocess call uses a fixed local executable and structured arguments for Git, schema validation, or bundled lifecycle commands. It does not invoke a shell.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3554:symlink-creation","reason":"The code recreates only a source symlink whose resolved target was verified to remain inside the worktree and outside Git administration. It rebases the link into an isolated verification copy.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/benchmark.py:88:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/benchmark.py:97:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/evidence_receipt.py:29:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/evidence_receipt.py:38:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/evidence_report.py:25:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/evidence_report.py:35:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/job_lifecycle.py:35:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/job_lifecycle.py:39:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/job_lifecycle.py:45:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"scripts:runtime/scripts/model-recommendation.py:12:dynamic-import-expression","reason":"The snippet is a normal static Python import from a bundled sibling module. There is no runtime import expression or caller-controlled module name.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:420:hard-link-creation","reason":"The hard link is used for same-directory atomic publication after owner, mode, identity, and no-follow checks. It does not link arbitrary caller paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/evidence_receipt.py:882:hard-link-creation","reason":"The hard link is used for same-directory atomic publication after owner, mode, identity, and no-follow checks. It does not link arbitrary caller paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/evidence_report.py:341:hard-link-creation","reason":"The hard link is used for same-directory atomic publication after owner, mode, identity, and no-follow checks. It does not link arbitrary caller paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/model_evidence_campaign.py:355:hard-link-creation","reason":"The hard link is used for same-directory atomic publication after owner, mode, identity, and no-follow checks. It does not link arbitrary caller paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/swebench_workflow_study.py:277:hard-link-creation","reason":"The hard link is used for same-directory atomic publication after owner, mode, identity, and no-follow checks. It does not link arbitrary caller paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:1262:hidden-file-access","reason":"The matched home-directory text is documentation or a provider prompt that forbids access to ~/.gemini and other user directories. It does not perform filesystem access.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/ground-truth.sh:63:hidden-file-access","reason":"The optional account phase opens ~/.gemini/antigravity-cli/settings.json to display permission settings. This is intentional diagnostics, but it is genuine hidden-file access.","verdict":"confirmed","severity":"medium","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:2564:hidden-file-access","reason":"The matched home-directory text is documentation or a provider prompt that forbids access to ~/.gemini and other user directories. It does not perform filesystem access.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:171:hidden-file-access","reason":"The matched home-directory text is documentation or a provider prompt that forbids access to ~/.gemini and other user directories. It does not perform filesystem access.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:177:hidden-file-access","reason":"The matched home-directory text is documentation or a provider prompt that forbids access to ~/.gemini and other user directories. It does not perform filesystem access.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/model_selection.py:1270:python-file-write-append","reason":"The code writes a new mode-0600 temporary selection record, validates its exact bytes, and atomically replaces the requested destination. It does not append to an existing sensitive file.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:939:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_containment.py:427:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3479:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3481:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3482:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3517:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:3519:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4055:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4067:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4169:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4171:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:4177:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3490:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3601:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:427:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:441:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:465:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:757:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:770:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/codex_usage_report.py:223:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/evidence_report.py:263:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/evidence_report.py:353:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/job_lifecycle.py:690:python-os-file-operations","reason":"The operation is bounded cleanup, private-directory permission setup, or transactional reconciliation using directory descriptors and no-follow checks. It does not target arbitrary ambient paths.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3497:python-shutil-operations","reason":"The copy or removal is restricted to a validated verification copy, benchmark workspace, or temporary lifecycle directory. Boundary and symlink checks precede the operation.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3555:python-shutil-operations","reason":"The copy or removal is restricted to a validated verification copy, benchmark workspace, or temporary lifecycle directory. Boundary and symlink checks precede the operation.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3561:python-shutil-operations","reason":"The copy or removal is restricted to a validated verification copy, benchmark workspace, or temporary lifecycle directory. Boundary and symlink checks precede the operation.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch.py:3595:python-shutil-operations","reason":"The copy or removal is restricted to a validated verification copy, benchmark workspace, or temporary lifecycle directory. Boundary and symlink checks precede the operation.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:740:python-shutil-operations","reason":"The copy or removal is restricted to a validated verification copy, benchmark workspace, or temporary lifecycle directory. Boundary and symlink checks precede the operation.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/job_lifecycle.py:851:python-shutil-operations","reason":"The copy or removal is restricted to a validated verification copy, benchmark workspace, or temporary lifecycle directory. Boundary and symlink checks precede the operation.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:14:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:15:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:1262:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:1263:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:1300:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:5:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:6:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:8:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:13:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:14:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:76:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:80:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:81:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:82:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:86:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:87:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:91:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:98:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:9:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:11:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:679:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:976:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch_containment.py:1079:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The backticks are Markdown code spans or comments describing command names. They are not shell backtick operators executed by the runtime.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:56:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:71:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:80:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:81:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:82:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:251:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:252:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:286:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:287:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:25:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:30:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:237:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:464:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:473:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:497:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:498:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:499:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:603:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:604:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:649:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:650:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:651:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:652:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:663:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:685:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:690:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:692:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:696:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:720:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:901:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:980:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:1009:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:6:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:7:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:12:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:19:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:40:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:45:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:93:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:154:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:164:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:scripts/resolve-pipeline.sh:169:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:23:shell-command-substitution","reason":"The shell uses quoted command substitution for fixed package resolution, canonical paths, digests, or bounded helper output. The result is handled as data, not re-evaluated as shell code.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/SECURITY_AND_COMPATIBILITY.md:42:temp-directory-access","reason":"The documentation describes replacing HOME, TMP, and XDG with private directories during native isolation. It does not access a temporary directory at this location.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/agy-worker.sh:15:template-literal-with-command-substitution","reason":"The match is Markdown or a shell comment containing backticks. No template engine evaluates the text.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/ground-truth.sh:14:template-literal-with-command-substitution","reason":"The match is Markdown or a shell comment containing backticks. No template engine evaluates the text.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:22:template-literal-with-command-substitution","reason":"The match is Markdown or a shell comment containing backticks. No template engine evaluates the text.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/qa-gate.sh:623:unix-shell-invocation","reason":"Shell verification passes the selected verification specification to /bin/bash -c. This intentionally supports arbitrary shell commands and therefore carries command-injection and project-code execution risk.","verdict":"confirmed","severity":"medium","confidence":0.99},{"id":"external_commands:runtime/qa-gate.sh:639:unix-shell-invocation","reason":"The alternate gate branch also executes the selected verification specification through /bin/bash -c. The clean environment reduces exposure but does not remove arbitrary shell execution.","verdict":"confirmed","severity":"medium","confidence":0.99},{"id":"external_commands:runtime/scripts/agy_dispatch_verification.py:27:unix-shell-invocation","reason":"The code defines shell executable names for rejection and policy checks. It does not launch a shell at this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/agy_dispatch_worktree.py:1416:unix-shell-invocation","reason":"The shell runs a fixed supervisor program and passes the bound Git executable as positional arguments. Repository values are not interpolated into the shell source.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:runtime/scripts/evidence_receipt.py:1146:unix-shell-invocation","reason":"The Bash executable starts the fixed bundled QA gate script with structured arguments and a sanitized environment. It does not execute caller text at this location.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:154:network-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:95:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:112:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:201:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:203:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:254:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:286:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:321:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/TROUBLESHOOTING.md:54:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/TROUBLESHOOTING.md:65:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/TROUBLESHOOTING.md:88:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/TROUBLESHOOTING.md:96:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/TROUBLESHOOTING.md:100:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/TROUBLESHOOTING.md:139:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/TROUBLESHOOTING.md:141:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agents/bulk-test-writer.md:46:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agents/diff-reviewer.md:34:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agents/repo-inventory.md:40:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:2:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:79:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:82:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:85:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:134:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:135:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:136:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:137:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:138:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:139:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:140:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:141:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:143:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:144:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:145:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:155:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:157:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:163:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:166:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:runtime/agy-worker.sh:167:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:scripts/resolve-pipeline.sh:183:system-reconnaissance","reason":"The match is ordinary documentation, status text, validation logic, or command usage. It does not enumerate remote hosts, ports, users, or system services.","verdict":"false_positive","confidence":0.97},{"id":"env_access:runtime/scripts/agy_dispatch_verification.py:151:configuration-library","reason":"The line raises an error when verification descendants cannot be confirmed. It does not load configuration or inspect secrets.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:20:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:64:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:111:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:163:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:212:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:257:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:277:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:303:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/agy-version-manifest.json:347:hardcoded-url","reason":"The URL is version-manifest metadata for documented Antigravity distributions. This location stores evidence and does not make a network request.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/model-effort-matrix.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/model-effort-matrix.schema.json:3:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/compat/version-manifest.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/benchmark-plan.schema.json:1:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/benchmark-result.schema.json:1:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/delegation-policy.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/evidence-receipt.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/job-state.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-preview.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/model-evidence-campaign-advisory-summary.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate-preview.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/model-evidence-campaign-aggregate.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/model-evidence-campaign-evaluation.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/schemas/model-evidence-campaign-plan.schema.json:2:hardcoded-url","reason":"The URL is JSON Schema metadata and is not fetched by the file. It identifies a schema dialect or document.","verdict":"false_positive","confidence":0.97},{"id":"env_access:runtime/scripts/agy_dispatch_worktree.py:1379:python-environment-access","reason":"The environment copy is used for a fixed local wrapper or bound Git command, which applies its own filtering before provider launch. No environment value is transmitted at this line.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/evidence_receipt.py:1115:python-environment-access","reason":"The verifier reads explicitly named values from the caller environment. The opt-in and private-pipe design reduce risk, but approved names may contain credentials.","verdict":"confirmed","severity":"low","confidence":0.94},{"id":"env_access:runtime/scripts/evidence_receipt.py:1117:python-environment-access","reason":"This line serializes approved environment values into the private verifier payload. Credential acknowledgements are enforced, but sensitive values still cross into executed verification code.","verdict":"confirmed","severity":"low","confidence":0.94},{"id":"env_access:runtime/scripts/evidence_receipt.py:1521:python-environment-access","reason":"The validated verifier receives the gate's environment through execvpe. The environment is sanitized and opt-in, but any approved secret becomes accessible to project tooling.","verdict":"confirmed","severity":"low","confidence":0.92},{"id":"env_access:runtime/scripts/feedback-triage.py:360:python-environment-access","reason":"Feedback triage copies the ambient environment before invoking an authenticated GitHub CLI request. Fixed GitHub routing limits misuse, but the child can receive ambient GitHub credentials.","verdict":"confirmed","severity":"low","confidence":0.9},{"id":"env_access:runtime/scripts/model_selection.py:98:python-environment-access","reason":"The child environment is rebuilt from a strict allowlist and optional approved names. Blocked startup and Git variables are rejected before access.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/workflow.py:711:python-environment-access","reason":"The code reads a standard state or log directory variable and validates the resulting absolute owner-controlled path. It does not inspect credential values.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/workflow.py:718:python-environment-access","reason":"The code reads a standard state or log directory variable and validates the resulting absolute owner-controlled path. It does not inspect credential values.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/workflow.py:750:python-environment-access","reason":"The environment copy is used for a fixed local wrapper or bound Git command, which applies its own filtering before provider launch. No environment value is transmitted at this line.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/workflow.py:1115:python-environment-access","reason":"The environment copy is used for a fixed local wrapper or bound Git command, which applies its own filtering before provider launch. No environment value is transmitted at this line.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/workflow.py:1186:python-environment-access","reason":"The code reads a standard state or log directory variable and validates the resulting absolute owner-controlled path. It does not inspect credential values.","verdict":"false_positive","confidence":0.9},{"id":"env_access:runtime/scripts/workflow.py:1598:python-environment-access","reason":"The code reads a standard state or log directory variable and validates the resulting absolute owner-controlled path. It does not inspect credential values.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:runtime/qa-gate.sh:434:python-glob-pattern-matching","reason":"The gate uses fnmatch to enforce caller-provided allow and only path policies against reported repository changes. It does not expand filesystem paths or execute matches.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/qa-gate.sh:513:python-glob-pattern-matching","reason":"The gate uses fnmatch to enforce caller-provided allow and only path policies against reported repository changes. It does not expand filesystem paths or execute matches.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/qa-gate.sh:518:python-glob-pattern-matching","reason":"The gate uses fnmatch to enforce caller-provided allow and only path policies against reported repository changes. It does not expand filesystem paths or execute matches.","verdict":"false_positive","confidence":0.97},{"id":"network:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:25:python-http-libraries","reason":"The matched word is prose or a dictionary operation named pending_requests. No HTTP library import or network request appears at this location.","verdict":"false_positive","confidence":0.97},{"id":"network:runtime/scripts/codex_usage_report.py:726:python-http-libraries","reason":"The matched word is prose or a dictionary operation named pending_requests. No HTTP library import or network request appears at this location.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:36:python-http-libraries","reason":"The matched word is prose or a dictionary operation named pending_requests. No HTTP library import or network request appears at this location.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:237:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:663:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:673:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:685:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:897:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:1011:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:1030:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:1200:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/agy-worker.sh:1201:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:21:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:24:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:32:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:38:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:86:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:147:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:156:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:157:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:172:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:198:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:199:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:225:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:230:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:231:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:12:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:20:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:40:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:46:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:94:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:155:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:164:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:165:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:scripts/resolve-pipeline.sh:169:standard-device-file-access","reason":"The match is standard shell redirection to /dev/null for suppressing expected diagnostics. It does not read from or write to a non-standard device.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:81:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:82:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/PROJECT_LIFECYCLE_AND_VERIFICATION.md:251:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/doctor.sh:224:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/qa-gate.sh:314:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/agy_dispatch_worktree.py:814:temp-file-creation","reason":"The line is a portability comment about mktemp output. It performs no filesystem operation.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:24:temp-file-creation","reason":"The line only imports Python's tempfile module. It does not create a file.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/benchmark.py:756:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/codex_usage_report.py:31:temp-file-creation","reason":"The line only imports Python's tempfile module. It does not create a file.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/codex_usage_report.py:221:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/job_lifecycle.py:26:temp-file-creation","reason":"The line only imports Python's tempfile module. It does not create a file.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:runtime/scripts/job_lifecycle.py:837:temp-file-creation","reason":"The temporary workspace is created with a unique name and then restricted to the owner for verification, diagnostics, or benchmark cleanup. No predictable shared filename is used.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Approved repository content is transmitted to an external provider","severity":"high","locations":[{"file":"SKILL.md","line_end":50,"line_start":45}],"confidence":0.99,"description":"Scoped files or an entire approved worktree can be readable and transmissible to Google or Gemini. Digest approval reduces accidental scope changes but does not eliminate third-party disclosure.","confidence_reasoning":"The skill explicitly documents provider-readable content, whole-worktree transmission, and the need to remove secrets before launch."},{"title":"Default session isolation retains ambient user authority","severity":"high","locations":[{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":91,"line_start":85}],"confidence":0.99,"description":"The default session mode gives AGY normal user filesystem and network authority outside the staged workspace. Scope reconciliation cannot prevent unobserved reads or network activity.","confidence_reasoning":"Both the primary instructions and security guide state that session mode has no host containment and cannot observe access outside the stage."},{"title":"Native mode grants broad Keychain helper and listener authority","severity":"high","locations":[{"file":"references/SECURITY_AND_COMPATIBILITY.md","line_end":142,"line_start":119}],"confidence":0.99,"description":"Native mode can expose wildcard listeners and broader same-user Keychain operations through the security helper. Approval does not technically limit helper operations to one AGY token.","confidence_reasoning":"The security guide explicitly states that wildcard binds are possible and Keychain reads, additions, changes, and deletions may be allowed."}],"subject_marketplace_commit_sha":"7b5f6226ad3dfaed7068a68fb47e33a511a95cb3","subject_content_hash":"6265484dddafa504df20fa1cc2033d6bbd7243ada5189f892ddd42973c8285e4","subject_tree_hash":"5ed1e9b7a5b0bbee6ff0542508a6ab17283522e7e176033e7531146657f8bd2c","subject_plugin_path":"skills/cagdasyurekli/agy-worker","audit_payload_hash":"2b712c7cff30f18b62689fab595c5377","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"7b5f6226ad3dfaed7068a68fb47e33a511a95cb3","contentHash":"6265484dddafa504df20fa1cc2033d6bbd7243ada5189f892ddd42973c8285e4","treeHash":"5ed1e9b7a5b0bbee6ff0542508a6ab17283522e7e176033e7531146657f8bd2c","pluginPath":"skills/cagdasyurekli/agy-worker","auditPayloadHash":"2b712c7cff30f18b62689fab595c5377"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/cagdasyurekli-agy-worker/audits/7/attestation","status":"superseded"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":3,"capabilityReviewCount":12,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"superseded","verificationState":"not_verified"},"isLatest":false}}