{"data":{"skill":{"slug":"chipflow-context-tools","name":"context-daddy","icon":"📦","repo":"https://github.com/ChipFlow/claude-context-tools/tree/main/","status":"approved","author":"ChipFlow","authorVersion":null,"skillstoreRevision":3},"audit":{"id":"3a401005-a5e0-4833-8605-388304af5efb","skill_id":"75c58b03-ad9c-40ad-aa3f-81b72b8ceca9","version":11,"content_hash":"v3:c68df504887c54bf71d2d467a1fbebde49467868:1a839ce2b5a4a20537d74ebb1c736bdcfd7a0fee60b826370d4aa1834719c2e5:b63255863cf22984b0457ebfee8e01a76f3a17526f5faa0e8108751e4fe43bd8:736b696c6c732f63686970666c6f772f636f6e746578742d746f6f6c73:67718f4394d0df6e47e91a13cad07b5d","risk_level":"low","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 94 static findings are false positives caused by documentation, metadata, and static assets. The reviewed material describes local indexing and optional tooling, with no evidence of credential exfiltration, malicious persistence, prompt injection, or executable command injection.","remediation":[{"issue":"Local project and global Claude files are created for indexes, logs, narratives, and goals.","severity":"low","suggestion":"Document the exact files created, retention behavior, and a user-controlled cleanup procedure before installation."},{"issue":"The bundled Mermaid asset is minified and triggered a size-based scanner blind spot.","severity":"low","suggestion":"Record the upstream Mermaid version and integrity or provenance details so future reviews can verify the bundled dependency."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"book.toml","line_end":11,"line_start":11},{"file":"book.toml","line_end":12,"line_start":12},{"file":"logo2.svg","line_end":10,"line_start":10},{"file":"logo2.svg","line_end":11,"line_start":11},{"file":"mermaid-init.js","line_end":3,"line_start":3}]},{"factor":"external_commands","evidence":[{"file":"CHANGELOG.md","line_end":467,"line_start":467},{"file":"CHANGELOG.md","line_end":475,"line_start":475},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":28,"line_start":19},{"file":"SKILL.md","line_end":31,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":34,"line_start":33},{"file":"SKILL.md","line_end":35,"line_start":34},{"file":"SKILL.md","line_end":48,"line_start":35},{"file":"SKILL.md","line_end":50,"line_start":48},{"file":"SKILL.md","line_end":62,"line_start":50},{"file":"SKILL.md","line_end":64,"line_start":62},{"file":"SKILL.md","line_end":68,"line_start":64},{"file":"SKILL.md","line_end":71,"line_start":68},{"file":"SKILL.md","line_end":72,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":79,"line_start":77},{"file":"SKILL.md","line_end":82,"line_start":79},{"file":"SKILL.md","line_end":86,"line_start":82},{"file":"SKILL.md","line_end":88,"line_start":86},{"file":"SKILL.md","line_end":91,"line_start":88},{"file":"SKILL.md","line_end":96,"line_start":91},{"file":"SKILL.md","line_end":98,"line_start":96},{"file":"SKILL.md","line_end":101,"line_start":98},{"file":"SKILL.md","line_end":104,"line_start":101},{"file":"SKILL.md","line_end":109,"line_start":104},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":115,"line_start":112},{"file":"SKILL.md","line_end":119,"line_start":115},{"file":"SKILL.md","line_end":125,"line_start":119},{"file":"SKILL.md","line_end":126,"line_start":125},{"file":"SKILL.md","line_end":132,"line_start":126},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":136,"line_start":134},{"file":"SKILL.md","line_end":150,"line_start":136},{"file":"SKILL.md","line_end":173,"line_start":150},{"file":"SKILL.md","line_end":183,"line_start":173},{"file":"SKILL.md","line_end":186,"line_start":183},{"file":"SKILL.md","line_end":189,"line_start":186},{"file":"SKILL.md","line_end":192,"line_start":189},{"file":"SKILL.md","line_end":196,"line_start":192},{"file":"SKILL.md","line_end":198,"line_start":196},{"file":"SKILL.md","line_end":201,"line_start":198},{"file":"SKILL.md","line_end":207,"line_start":201},{"file":"SKILL.md","line_end":208,"line_start":207},{"file":"SKILL.md","line_end":215,"line_start":208},{"file":"SKILL.md","line_end":218,"line_start":215},{"file":"SKILL.md","line_end":219,"line_start":218},{"file":"SKILL.md","line_end":220,"line_start":219}]},{"factor":"filesystem","evidence":[{"file":"CHANGELOG.md","line_end":49,"line_start":49},{"file":"CHANGELOG.md","line_end":109,"line_start":109},{"file":"CHANGELOG.md","line_end":49,"line_start":49},{"file":"CHANGELOG.md","line_end":109,"line_start":109},{"file":"CLAUDE.md","line_end":76,"line_start":76},{"file":"CLAUDE.md","line_end":118,"line_start":118},{"file":"CLAUDE.md","line_end":76,"line_start":76},{"file":"CLAUDE.md","line_end":118,"line_start":118},{"file":"README.md","line_end":95,"line_start":95},{"file":"README.md","line_end":138,"line_start":138},{"file":"README.md","line_end":95,"line_start":95},{"file":"README.md","line_end":138,"line_start":138}]},{"factor":"env_access","evidence":[{"file":"CLAUDE.md","line_end":140,"line_start":140},{"file":"README.md","line_end":145,"line_start":145}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Unscanned file (too_large) — manual review required","locations":[{"file":"mermaid.min.js","line_end":1,"line_start":1}],"confidence":1,"description":"[unscanned: too_large]","review_kind":"security","source_category":"metadata","source_severity":"low","confidence_reasoning":"Force-confirmed metadata/low static finding; AI false-positive verdict rejected."}],"dangerous_patterns":[],"files_scanned":10,"total_lines":1450,"audit_model":"claude","audited_at":"2026-07-18T10:24:18.049+00:00","created_at":"2026-07-19T13:53:07.171281+00:00","static_findings":[{"id":"sensitive:.gitignore:25:environment-file-access","file":".gitignore","pattern":"Environment file access","snippet":".env","category":"sensitive","line_end":25,"severity":"high","line_start":25},{"id":"sensitive:.gitignore:21:sqlite-database-file","file":".gitignore","pattern":"SQLite database file","snippet":"Thumbs.db","category":"sensitive","line_end":21,"severity":"medium","line_start":21},{"id":"network:book.toml:11:hardcoded-url","file":"book.toml","pattern":"Hardcoded URL","snippet":"git-repository-url = \"https://github.com/ChipFlow/context-daddy\"","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:book.toml:12:hardcoded-url","file":"book.toml","pattern":"Hardcoded URL","snippet":"edit-url-template = \"https://github.com/ChipFlow/context-daddy/edit/main/{path}\"","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"external_commands:CHANGELOG.md:467:nohup-background-persistent-process","file":"CHANGELOG.md","pattern":"nohup (background persistent process)","snippet":"- Background thread for indexing (replaced nohup subprocess)","category":"external_commands","line_end":467,"severity":"medium","line_start":467},{"id":"external_commands:CHANGELOG.md:475:nohup-background-persistent-process","file":"CHANGELOG.md","pattern":"nohup (background persistent process)","snippet":"- nohup subprocess spawning","category":"external_commands","line_end":475,"severity":"medium","line_start":475},{"id":"filesystem:CHANGELOG.md:49:hidden-file-in-home-directory","file":"CHANGELOG.md","pattern":"Hidden file in home directory","snippet":"- **Context injection tracking** - All hooks wrapped by `hook-runner.sh` which logs output sizes to ","category":"filesystem","line_end":49,"severity":"high","line_start":49},{"id":"filesystem:CHANGELOG.md:109:hidden-file-in-home-directory","file":"CHANGELOG.md","pattern":"Hidden file in home directory","snippet":"- Goals stored globally in `~/.claude/goals/`","category":"filesystem","line_end":109,"severity":"high","line_start":109},{"id":"filesystem:CHANGELOG.md:49:hidden-file-access","file":"CHANGELOG.md","pattern":"Hidden file access","snippet":"- **Context injection tracking** - All hooks wrapped by `hook-runner.sh` which logs output sizes to ","category":"filesystem","line_end":49,"severity":"medium","line_start":49},{"id":"filesystem:CHANGELOG.md:109:hidden-file-access","file":"CHANGELOG.md","pattern":"Hidden file access","snippet":"- Goals stored globally in `~/.claude/goals/`","category":"filesystem","line_end":109,"severity":"medium","line_start":109},{"id":"blocker:CHANGELOG.md:322:system-reconnaissance","file":"CHANGELOG.md","pattern":"System reconnaissance","snippet":"- **Clarified messaging**: Changed \"MCP tools guaranteed to work\" to \"context-tools MCP guaranteed t","category":"blocker","line_end":322,"severity":"low","line_start":322},{"id":"blocker:CHANGELOG.md:334:network-reconnaissance","file":"CHANGELOG.md","pattern":"Network reconnaissance","snippet":"- **Reduced auto-wait timeout**: 60s → 15s for better responsiveness","category":"blocker","line_end":335,"severity":"low","line_start":334},{"id":"blocker:CHANGELOG.md:412:network-reconnaissance","file":"CHANGELOG.md","pattern":"Network reconnaissance","snippet":"- **Resource limits**: 4GB memory (RLIMIT_AS) and 20 min CPU time (RLIMIT_CPU) for indexing subproce","category":"blocker","line_end":413,"severity":"low","line_start":412},{"id":"blocker:CHANGELOG.md:422:network-reconnaissance","file":"CHANGELOG.md","pattern":"Network reconnaissance","snippet":"- **Removed file locking**: SQLite's built-in locking is sufficient for concurrent access","category":"blocker","line_end":423,"severity":"low","line_start":422},{"id":"blocker:CHANGELOG.md:447:network-reconnaissance","file":"CHANGELOG.md","pattern":"Network reconnaissance","snippet":"- **Auto-wait behavior**: Tools automatically wait up to 60s if indexing in progress","category":"blocker","line_end":448,"severity":"low","line_start":447},{"id":"filesystem:CLAUDE.md:76:hidden-file-in-home-directory","file":"CLAUDE.md","pattern":"Hidden file in home directory","snippet":"- **Storage**: Goals in `~/.claude/goals/<uuid>.md`, project index in `.claude/active-goals.json`","category":"filesystem","line_end":76,"severity":"high","line_start":76},{"id":"filesystem:CLAUDE.md:118:hidden-file-in-home-directory","file":"CLAUDE.md","pattern":"Hidden file in home directory","snippet":"All context-injecting hooks are wrapped by `scripts/hook-runner.sh`, which logs output sizes to `~/.","category":"filesystem","line_end":118,"severity":"high","line_start":118},{"id":"filesystem:CLAUDE.md:76:hidden-file-access","file":"CLAUDE.md","pattern":"Hidden file access","snippet":"- **Storage**: Goals in `~/.claude/goals/<uuid>.md`, project index in `.claude/active-goals.json`","category":"filesystem","line_end":76,"severity":"medium","line_start":76},{"id":"filesystem:CLAUDE.md:118:hidden-file-access","file":"CLAUDE.md","pattern":"Hidden file access","snippet":"All context-injecting hooks are wrapped by `scripts/hook-runner.sh`, which logs output sizes to `~/.","category":"filesystem","line_end":118,"severity":"medium","line_start":118},{"id":"env_access:CLAUDE.md:140:generic-api-secret-keys","file":"CLAUDE.md","pattern":"Generic API/secret keys","snippet":"- E2E tests require `ANTHROPIC_API_KEY` secret (skipped if not set)","category":"env_access","line_end":140,"severity":"high","line_start":140},{"id":"network:logo2.svg:10:hardcoded-url","file":"logo2.svg","pattern":"Hardcoded URL","snippet":"xmlns:inkscape=\"http://www.inkscape.org/namespaces/inkscape\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:logo2.svg:11:hardcoded-url","file":"logo2.svg","pattern":"Hardcoded URL","snippet":"xmlns:sodipodi=\"http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd\"","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:mermaid-init.js:3:hardcoded-url","file":"mermaid-init.js","pattern":"Hardcoded URL","snippet":"// file, You can obtain one at https://mozilla.org/MPL/2.0/.","category":"network","line_end":3,"severity":"low","line_start":3},{"id":"blocker:mermaid-init.js:22:system-reconnaissance","file":"mermaid-init.js","pattern":"System reconnaissance","snippet":"// Simplest way to make mermaid re-render the diagrams in the new theme is via refreshing the page","category":"blocker","line_end":22,"severity":"low","line_start":22},{"id":"filesystem:README.md:95:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"- `~/.claude/learnings.md` - Global","category":"filesystem","line_end":95,"severity":"high","line_start":95},{"id":"filesystem:README.md:138:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"~/.claude/goals/           # Goal files (global)","category":"filesystem","line_end":138,"severity":"high","line_start":138},{"id":"filesystem:README.md:95:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"- `~/.claude/learnings.md` - Global","category":"filesystem","line_end":95,"severity":"medium","line_start":95},{"id":"filesystem:README.md:138:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"~/.claude/goals/           # Goal files (global)","category":"filesystem","line_end":138,"severity":"medium","line_start":138},{"id":"env_access:README.md:145:generic-api-secret-keys","file":"README.md","pattern":"Generic API/secret keys","snippet":"- `ANTHROPIC_API_KEY` for narrative generation","category":"env_access","line_end":145,"severity":"high","line_start":145},{"id":"sensitive:README.md:131:sqlite-database-file","file":"README.md","pattern":"SQLite database file","snippet":"├── repo-map.db            # Symbol index","category":"sensitive","line_end":131,"severity":"medium","line_start":131},{"id":"blocker:README.md:23:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"Understanding code isn't just about parsing syntax. It's about the *stories* - \"here be dragons\", \"w","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **MCP Symbol Server**: Enables fast symbol search via `search_symbols` and `get_file_symbols` tool","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":31,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Find a function/class/method by name or pattern** → `search_symbols`","category":"external_commands","line_end":32,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Understand how to use a function** (parameters, return type) → `search_symbols` or `get_symbol_c","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Get the source code of a specific function/class** → `get_symbol_content`","category":"external_commands","line_end":34,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **See all code in a file** → `get_file_symbols`","category":"external_commands","line_end":35,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Discover what functionality exists** in the codebase → `search_symbols` with patterns","category":"external_commands","line_end":48,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Before attempting to use MCP tools (mcp__plugin_context-daddy_repo-map__*), check if `.claude/repo-m","category":"external_commands","line_end":50,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If NO: The project hasn't been indexed yet. Either wait for indexing or run `/context-daddy:repo-m","category":"external_commands","line_end":62,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":64,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":68,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":72,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Result: Instant list of all `setup_model`, `setup_instance`, etc. with locations and signatures.","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":79,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":82,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":86,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":88,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":91,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":96,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":98,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":101,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":104,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":109,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"User needs to check if it's `Phi` or `PhiNode` in `enum InstructionData`.","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":115,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":119,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":125,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":126,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Result: Complete enum with all variants visible, including `PhiNode(_)`.","category":"external_commands","line_end":132,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> \"I see you've installed the context-daddy plugin. The MCP server should auto-configure on restart.","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> If it doesn't load automatically, let me know and I can help troubleshoot using `/context-daddy:se","category":"external_commands","line_end":136,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The MCP server auto-configures from the plugin manifest. Only if auto-config fails should you run `/","category":"external_commands","line_end":150,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":173,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":183,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mcp__plugin_context-daddy_repo-map__search_symbols` - Search symbols by pattern (supports glob wi","category":"external_commands","line_end":186,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mcp__plugin_context-daddy_repo-map__get_file_symbols` - Get all symbols in a specific file","category":"external_commands","line_end":189,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mcp__plugin_context-daddy_repo-map__get_symbol_content` - Get full source code of a symbol by exa","category":"external_commands","line_end":192,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mcp__plugin_context-daddy_repo-map__list_files` - List all indexed files, optionally filtered by ","category":"external_commands","line_end":196,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mcp__plugin_context-daddy_repo-map__reindex_repo_map` - Trigger manual reindex","category":"external_commands","line_end":198,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mcp__plugin_context-daddy_repo-map__repo_map_status` - Check indexing status and staleness","category":"external_commands","line_end":201,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mcp__plugin_context-daddy_repo-map__wait_for_index` - Explicitly wait for indexing to complete","category":"external_commands","line_end":207,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use sqlite3 directly on `.claude/repo-map.db`:","category":"external_commands","line_end":208,"severity":"medium","line_start":207},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":215,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":218,"severity":"medium","line_start":215},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/context-daddy:repo-map` - Regenerate repository map","category":"external_commands","line_end":219,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/context-daddy:manifest` - Refresh project manifest","category":"external_commands","line_end":220,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/context-daddy:learnings` - Manage project learnings","category":"external_commands","line_end":221,"severity":"medium","line_start":220},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/context-daddy:status` - Show plugin status","category":"external_commands","line_end":227,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Python | AST | `.py` |","category":"external_commands","line_end":228,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Rust | tree-sitter-rust | `.rs` |","category":"external_commands","line_end":229,"severity":"medium","line_start":228},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| C++ | tree-sitter-cpp | `.cpp`, `.cc`, `.cxx`, `.hpp`, `.h`, `.hxx` |","category":"external_commands","line_end":229,"severity":"medium","line_start":229},{"id":"sensitive:SKILL.md:48:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"Before attempting to use MCP tools (mcp__plugin_context-daddy_repo-map__*), check if `.claude/repo-m","category":"sensitive","line_end":48,"severity":"medium","line_start":48},{"id":"sensitive:SKILL.md:149:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"**Database Schema (.claude/repo-map.db):**","category":"sensitive","line_end":149,"severity":"medium","line_start":149},{"id":"sensitive:SKILL.md:207:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"Use sqlite3 directly on `.claude/repo-map.db`:","category":"sensitive","line_end":207,"severity":"medium","line_start":207},{"id":"sensitive:SKILL.md:210:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"sqlite3 .claude/repo-map.db \"SELECT name, kind, signature, file_path, line_number FROM symbols WHERE","category":"sensitive","line_end":210,"severity":"medium","line_start":210},{"id":"sensitive:SKILL.md:213:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"sqlite3 .claude/repo-map.db \"SELECT * FROM symbols WHERE name = 'function_name'\"","category":"sensitive","line_end":213,"severity":"medium","line_start":213},{"id":"blocker:SKILL.md:177:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Tools automatically wait (up to 60s) if indexing is in progress","category":"blocker","line_end":178,"severity":"low","line_start":177},{"id":"blocker:SKILL.md:198:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- `mcp__plugin_context-daddy_repo-map__repo_map_status` - Check indexing status and staleness","category":"blocker","line_end":199,"severity":"low","line_start":198},{"id":"metadata:mermaid.min.js:1:unscanned-file-too-large-manual-review-required","file":"mermaid.min.js","pattern":"Unscanned file (too_large) — manual review required","snippet":"[unscanned: too_large]","category":"metadata","line_end":1,"severity":"low","line_start":1},{"id":"obfuscation:logo2.svg:257:heuristic-extremely-long-line-22012-chars-likely","file":"logo2.svg","pattern":"[HEURISTIC] Extremely long line (22012 chars) - likely obfuscated","snippet":"       d=\"m 124.63992,121.07699 c -0.16926,3.66078 -0.34068,7.2863 -0.46675,10.721 -1.39857,0.29749 ","category":"obfuscation","line_end":257,"severity":"high","line_start":257},{"id":"obfuscation:logo2.svg:259:heuristic-extremely-long-line-10390-chars-likely","file":"logo2.svg","pattern":"[HEURISTIC] Extremely long line (10390 chars) - likely obfuscated","snippet":"       inkscape:original-d=\"m 125.66397,109.61224 -0.59421,12.32334 h -4.31446 l -0.59421,-12.32334 ","category":"obfuscation","line_end":259,"severity":"high","line_start":259}],"finding_verdicts":[{"id":"sensitive:.gitignore:25:environment-file-access","reason":"The .gitignore entry prevents .env files from being committed; it does not read an environment file or expose a secret.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:.gitignore:21:sqlite-database-file","reason":"The matched text is Thumbs.db, a Windows thumbnail cache entry, not a SQLite database or sensitive data access.","verdict":"false_positive","confidence":0.99},{"id":"network:book.toml:11:hardcoded-url","reason":"This is the public GitHub repository URL in documentation metadata, not a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:book.toml:12:hardcoded-url","reason":"This is a public GitHub edit-link template for documentation, not executable network behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:CHANGELOG.md:467:nohup-background-persistent-process","reason":"The changelog states that a nohup subprocess was replaced; it does not execute a persistent process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:CHANGELOG.md:475:nohup-background-persistent-process","reason":"This is a historical changelog reference to subprocess spawning, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CHANGELOG.md:49:hidden-file-in-home-directory","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CHANGELOG.md:109:hidden-file-in-home-directory","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CHANGELOG.md:49:hidden-file-access","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CHANGELOG.md:109:hidden-file-access","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:322:system-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:334:network-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:412:network-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:422:network-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:447:network-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CLAUDE.md:76:hidden-file-in-home-directory","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CLAUDE.md:118:hidden-file-in-home-directory","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CLAUDE.md:76:hidden-file-access","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:CLAUDE.md:118:hidden-file-access","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"env_access:CLAUDE.md:140:generic-api-secret-keys","reason":"This is a requirements note identifying ANTHROPIC_API_KEY for an optional feature. It neither reads nor transmits an environment value.","verdict":"false_positive","confidence":0.99},{"id":"network:logo2.svg:10:hardcoded-url","reason":"This is a namespace or license URL embedded in a static asset, not a network request or data transfer.","verdict":"false_positive","confidence":0.99},{"id":"network:logo2.svg:11:hardcoded-url","reason":"This is a namespace or license URL embedded in a static asset, not a network request or data transfer.","verdict":"false_positive","confidence":0.99},{"id":"network:mermaid-init.js:3:hardcoded-url","reason":"This is a namespace or license URL embedded in a static asset, not a network request or data transfer.","verdict":"false_positive","confidence":0.99},{"id":"blocker:mermaid-init.js:22:system-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.md:95:hidden-file-in-home-directory","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.md:138:hidden-file-in-home-directory","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.md:95:hidden-file-access","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.md:138:hidden-file-access","reason":"This is documentation describing the plugin’s local Claude configuration and goal storage paths. The reference itself does not access or disclose hidden home-directory files.","verdict":"false_positive","confidence":0.99},{"id":"env_access:README.md:145:generic-api-secret-keys","reason":"This is a requirements note identifying ANTHROPIC_API_KEY for an optional feature. It neither reads nor transmits an environment value.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:README.md:131:sqlite-database-file","reason":"No executable security-relevant behavior is evident in the matched documentation or asset.","verdict":"false_positive","confidence":0.7},{"id":"blocker:README.md:23:system-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"This Markdown documentation uses backticks for MCP tool names, fenced examples, or local sqlite3 queries. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:48:sqlite-database-file","reason":"This documentation describes a local .claude/repo-map.db symbol index and optional read-only sqlite3 queries. It does not contain credentials or access a sensitive database.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:149:sqlite-database-file","reason":"This documentation describes a local .claude/repo-map.db symbol index and optional read-only sqlite3 queries. It does not contain credentials or access a sensitive database.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:207:sqlite-database-file","reason":"This documentation describes a local .claude/repo-map.db symbol index and optional read-only sqlite3 queries. It does not contain credentials or access a sensitive database.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:210:sqlite-database-file","reason":"This documentation describes a local .claude/repo-map.db symbol index and optional read-only sqlite3 queries. It does not contain credentials or access a sensitive database.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:213:sqlite-database-file","reason":"This documentation describes a local .claude/repo-map.db symbol index and optional read-only sqlite3 queries. It does not contain credentials or access a sensitive database.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:177:network-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:198:network-reconnaissance","reason":"The matched prose discusses indexing state, resource limits, or documentation wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"metadata:mermaid.min.js:1:unscanned-file-too-large-manual-review-required","reason":"The file identifies itself as MIT-licensed Mermaid content and begins with a standard minified bundle. Its size alone is not evidence of malicious behavior, although dependency provenance should be maintained.","verdict":"false_positive","confidence":0.78},{"id":"obfuscation:logo2.svg:257:heuristic-extremely-long-line-22012-chars-likely","reason":"The long line is an SVG path data attribute, which is normal for a vector illustration and is not executable code.","verdict":"false_positive","confidence":0.97},{"id":"obfuscation:logo2.svg:259:heuristic-extremely-long-line-10390-chars-likely","reason":"The long line is Inkscape original path data in an SVG asset, a normal non-executable representation of vector geometry.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[],"subject_marketplace_commit_sha":"c68df504887c54bf71d2d467a1fbebde49467868","subject_content_hash":"1a839ce2b5a4a20537d74ebb1c736bdcfd7a0fee60b826370d4aa1834719c2e5","subject_tree_hash":"b63255863cf22984b0457ebfee8e01a76f3a17526f5faa0e8108751e4fe43bd8","subject_plugin_path":"skills/chipflow/context-tools","audit_payload_hash":"67718f4394d0df6e47e91a13cad07b5d","confirmed_risk_level":"low","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"c68df504887c54bf71d2d467a1fbebde49467868","contentHash":"1a839ce2b5a4a20537d74ebb1c736bdcfd7a0fee60b826370d4aa1834719c2e5","treeHash":"b63255863cf22984b0457ebfee8e01a76f3a17526f5faa0e8108751e4fe43bd8","pluginPath":"skills/chipflow/context-tools","auditPayloadHash":"67718f4394d0df6e47e91a13cad07b5d"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/chipflow-context-tools/audits/11/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}