{"data":{"skill":{"slug":"google-mantis-calibrate","name":"mantis-calibrate","icon":"📦","repo":"https://github.com/google/mantis/tree/f48a85e8823ee6f4824ae9a24b9b2efb8aab8c9a/mantis-calibrate","status":"approved","author":"google","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"6f1a74c0-6bf6-4d32-b52b-f9e40c177acd","skill_id":"d3bdf197-77ed-4bdd-9e8b-4bc26cffdf0e","version":1,"content_hash":"v3:9958c759dc9c75fb509d50ad1fe7930c27e2799c:c4eb14c114e308ed9f0147397be8b72cb2a5bb837177918e518d83f0c8c9e29b:aa3c1931002b07954f479025c0285b9ce70690b0d6880f1617eddf85d3331f89:736b696c6c732f676f6f676c652f6d616e7469732d63616c696272617465:19c87ba2c3a9676ed1a3c744c1b48b0b","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 203 static detections are false positives involving Markdown syntax, workflow metadata, or descriptions of vulnerability evidence. One semantic finding identifies helper reuse without integrity verification, enabling code execution if an attacker controls the workspace helper. No evidence found of deliberate prompt injection or data exfiltration in the supplied files.","remediation":[{"issue":"Existing helper code is trusted based only on a version comment.","severity":"high","suggestion":"Regenerate helpers from a trusted template or verify their complete contents before execution. Reject symlinks and use a private, access-controlled helper directory."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":100,"line_start":61},{"file":"SKILL.md","line_end":103,"line_start":100},{"file":"SKILL.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":106,"line_start":104},{"file":"SKILL.md","line_end":107,"line_start":106},{"file":"SKILL.md","line_end":108,"line_start":107},{"file":"SKILL.md","line_end":110,"line_start":108},{"file":"SKILL.md","line_end":111,"line_start":110},{"file":"SKILL.md","line_end":116,"line_start":111},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":120,"line_start":117},{"file":"SKILL.md","line_end":121,"line_start":120},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":126,"line_start":124},{"file":"SKILL.md","line_end":126,"line_start":126},{"file":"SKILL.md","line_end":128,"line_start":127},{"file":"SKILL.md","line_end":128,"line_start":128},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":133,"line_start":133},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":138,"line_start":138},{"file":"SKILL.md","line_end":139,"line_start":139},{"file":"SKILL.md","line_end":144,"line_start":142},{"file":"SKILL.md","line_end":148,"line_start":144},{"file":"SKILL.md","line_end":149,"line_start":148},{"file":"SKILL.md","line_end":153,"line_start":149},{"file":"SKILL.md","line_end":154,"line_start":153},{"file":"SKILL.md","line_end":154,"line_start":154},{"file":"SKILL.md","line_end":155,"line_start":155},{"file":"SKILL.md","line_end":157,"line_start":156},{"file":"SKILL.md","line_end":157,"line_start":157},{"file":"SKILL.md","line_end":161,"line_start":159},{"file":"SKILL.md","line_end":161,"line_start":161},{"file":"SKILL.md","line_end":165,"line_start":163},{"file":"SKILL.md","line_end":166,"line_start":165},{"file":"SKILL.md","line_end":166,"line_start":166},{"file":"SKILL.md","line_end":170,"line_start":169}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":117,"line_start":117},{"file":"SKILL.md","line_end":92,"line_start":92}]}],"critical_findings":[],"high_findings":[{"title":"Workspace Helper Reuse Without Integrity Verification","locations":[{"file":"SKILL.md","line_end":560,"line_start":554},{"file":"SKILL.md","line_end":572,"line_start":562}],"confidence":0.88,"description":"The skill executes an existing workspace helper after checking only \"# MANTIS_HELPER_VERSION = 2\". An attacker controlling that helper can retain the comment and execute arbitrary code with agent permissions.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The instructions explicitly combine helper execution with a first-line version check, without requiring body verification. Exploitation requires attacker control of the workspace helper; no malicious helper is supplied."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":914,"audit_model":"codex","audited_at":"2026-10-04T13:37:45.488+00:00","created_at":"2026-10-05T12:06:18.407748+00:00","static_findings":[{"id":"blocker:references/calibration_rules.md:118:system-reconnaissance","file":"references/calibration_rules.md","pattern":"System reconnaissance","snippet":"reproduction output) include a valid external stack trace, sanitizer trace","category":"blocker","line_end":118,"severity":"low","line_start":118},{"id":"blocker:references/calibration_rules.md:232:system-reconnaissance","file":"references/calibration_rules.md","pattern":"System reconnaissance","snippet":"temporary physical access to the device (e.g., USB key insertion, evil maid","category":"blocker","line_end":233,"severity":"low","line_start":232},{"id":"blocker:references/calibration_rules.md:150:known-jailbreak-keywords","file":"references/calibration_rules.md","pattern":"Known jailbreak keywords","snippet":"probabilistic LLM behavior (e.g., prompt injection, jailbreaking) to trigger","category":"blocker","line_end":150,"severity":"critical","line_start":150},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Command:** `/mantis-calibrate`","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/findings/*.json` (all finding files to load full pipeline state).","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/THREAT_MODEL.md` (if exists, to check threat boundary","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/.mantis_state.json` (to track the current loop pass, and to read","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`active_snapshot` — `{snapshot_id, snapshot_pinned, root}` — for finding","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`impact_score`, `likelihood_score`, `availability_tier`,","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`inferred_exposure`, `attacker_position`, `mantis_risk_score`, `priority`,","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`sanity_triage_applied` (may begin with `STALE_EVIDENCE` when the","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"STALE-EVIDENCE guard suppresses heuristics), `calibration_checklist`","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(entries may carry `STALE_EVIDENCE:` reasons), `outrage_commentary`,","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`executive_summary`). Appends a `history` entry with `snapshot` provenance","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Reusable helper script `workspace/helpers/append_calibrate.py`.","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Confirmed or raw findings must exist in `workspace/findings/`.","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":100,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":103,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> harness per `mantis-pipeline-adapter` Scenario 2):** if `active_snapshot` is","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> present AND `active_snapshot.pass != state.pass_number`, treat the snapshot as","category":"external_commands","line_end":106,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> as HALT (`snapshot_pinned` effectively false: no authoritative verdicts, Block","category":"external_commands","line_end":107,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> B NOT_MATCHED, reproduce `not_attempted`). This catches a custom harness that","category":"external_commands","line_end":108,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> preserved `active_snapshot` across the Stage 15 pass increment without","category":"external_commands","line_end":110,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> fires there. Block B itself cannot detect this (it is `snapshot_id`-only, not","category":"external_commands","line_end":111,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> `pass`-aware).","category":"external_commands","line_end":116,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"P0. Read `active_snapshot` (`{snapshot_id, snapshot_pinned, root}`) from","category":"external_commands","line_end":116,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`state_root/workspace/.mantis_state.json` (Block A step 0/1c). NEVER stop if it","category":"external_commands","line_end":120,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"P1. MODE (single decision for the whole run — branches on `active_snapshot`","category":"external_commands","line_end":121,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"presence, 3-state model): - `active_snapshot` is ABSENT in state (no `--sync`","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"emit `STALE_EVIDENCE`, and do NOT emit any HALT/PINNED banners.","category":"external_commands","line_end":126,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`active_snapshot` IS present AND `snapshot_pinned` is not exactly `true` (HALT","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"mode — the tree raced or could not be pinned) -> MODE = HALT. `SNAPSHOT_ID` =","category":"external_commands","line_end":128,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`active_snapshot.snapshot_id` (a `live:` id). Compute PROVENANCE per P2 below","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"are forbidden this pass. - `snapshot_pinned` == `true` -> MODE = PINNED.","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`SNAPSHOT_ID` = `active_snapshot.snapshot_id`. Full provenance + STALE-EVIDENCE","category":"external_commands","line_end":133,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"compare rule: - `F.discovery_commit` missing OR empty OR the literal `\"MIXED\"`","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"-> NOT_MATCHED. - `F.discovery_commit` != `SNAPSHOT_ID` (exact string compare,","category":"external_commands","line_end":138,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"no fuzzy) -> NOT_MATCHED. - `F.discovery_commit` == `SNAPSHOT_ID` -> MATCHED.","category":"external_commands","line_end":139,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"either: - PROVENANCE(F) == NOT_MATCHED, OR - the finding's `code_paths` target","category":"external_commands","line_end":144,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"strip a trailing `:<digits>`; read ONLY the pinned root, NEVER the live tree. If","category":"external_commands","line_end":148,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(pre-adjustment) score; and ensure the literal token `STALE_EVIDENCE` is the","category":"external_commands","line_end":149,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"FIRST token of `sanity_triage_applied` (add it once, before any UNKNOWN warnings","category":"external_commands","line_end":153,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"otherwise have. - **`repro_failure`** (Section 3 rule): do NOT force-LOW; set","category":"external_commands","line_end":154,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`calibration_checklist.repro_failure.outcome = \"UNKNOWN\"`, `reason` beginning","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"STALE_EVIDENCE: \"`. - **`vague_code_paths`** (Section 3 rule): do NOT","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"force-LOW; set `calibration_checklist.vague_code_paths.outcome = \"UNKNOWN\"`,","category":"external_commands","line_end":157,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`reason` beginning `\"STALE_EVIDENCE: \"`. - **`static_confirmation` trace-lift**","category":"external_commands","line_end":157,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"apply the trace-lift; KEEP the static HIGH cap in force (`likelihood_score` \\<=","category":"external_commands","line_end":161,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`calibration_checklist.static_confirmation.outcome = \"APPLIES\"`, `reason`","category":"external_commands","line_end":161,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"STALE_EVIDENCE: trace-lift suppressed; trace/crash-log may predate the active snapshot; \"`.","category":"external_commands","line_end":165,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"P5. NON-SOURCE finding: if the finding's `code_paths` entry is a non-source","category":"external_commands","line_end":166,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"LOCATOR (contains `\"://\"`, or is not of the form `<path>:<integer>` — per Block","category":"external_commands","line_end":166,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`vague_code_paths`, and static trace re-inspection — and score from the","category":"external_commands","line_end":170,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"finding's DECLARED metadata (`attacker_position`, `privileges_required`,","category":"external_commands","line_end":170,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`production_viability`, `repro_status`, threat model). A non-source skip is NOT","category":"external_commands","line_end":171,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"flagged `STALE_EVIDENCE` (it is normal, not drift). Non-source findings default","category":"external_commands","line_end":173,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`inferred_exposure` to `\"INTERNAL\"` (0.8) unless the finding/threat-model","category":"external_commands","line_end":173,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read all JSON files from the `workspace/findings/` directory. Because the","category":"external_commands","line_end":180,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"provide the complete picture of each finding's journey (including its `id`,","category":"external_commands","line_end":185,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `production_viability` is missing, treat it as `\"CONDITIONAL_VIABLE\"`.","category":"external_commands","line_end":185,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `repro_status` is missing, treat it as `\"not_attempted\"`.","category":"external_commands","line_end":186,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read `workspace/kb/THREAT_MODEL.md` from the Knowledge Base (if it exists)","category":"external_commands","line_end":200,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"ONLY the pinned snapshot:** pass `--snapshot_root=<active_snapshot.root>`,","category":"external_commands","line_end":201,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--snapshot_id=<active_snapshot.snapshot_id>`, and","category":"external_commands","line_end":202,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--state_root=<workspace parent>` so every subagent resolves the same","category":"external_commands","line_end":268,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"likelihood, reduce the `likelihood_score` by **1 or 2** (but not below","category":"external_commands","line_end":277,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `status` is **FALSE_POSITIVE** or **NEEDS_RESEARCH**, or if","category":"external_commands","line_end":278,"severity":"medium","line_start":277},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`production_viability` is **NON_VIABLE**: Drop this finding completely.","category":"external_commands","line_end":280,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `production_viability` is **VIABLE**, **CONDITIONAL_VIABLE**, or","category":"external_commands","line_end":289,"severity":"medium","line_start":280},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/kb/THREAT_MODEL.md` does not exist or does not mention the","category":"external_commands","line_end":295,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"non-source LOCATOR findings — default `inferred_exposure` to","category":"external_commands","line_end":296,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"INTERNAL\"` (0.8) unless the finding or threat model declares","category":"external_commands","line_end":298,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"NOT_MATCHED or its `code_paths` file is absent under CODE_ROOT, do","category":"external_commands","line_end":303,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`inferred_exposure` to `\"INTERNAL\"` unless there is clear evidence","category":"external_commands","line_end":303,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"INTERNAL\"` exposure.","category":"external_commands","line_end":312,"severity":"medium","line_start":306},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Resolve **`inferred_exposure`** based on the Network/Trust Exposure","category":"external_commands","line_end":314,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Multiplier 1.0 (Exposed Interface) -> `\"EXPOSED\"`","category":"external_commands","line_end":315,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Multiplier 0.8 (Internal Component) -> `\"INTERNAL\"`","category":"external_commands","line_end":316,"severity":"medium","line_start":315},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Multiplier 0.5 (Privileged/Trusted Zone) -> `\"PRIVILEGED\"`","category":"external_commands","line_end":318,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read `attacker_position` from the finding JSON.","category":"external_commands","line_end":319,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Determine by Barrier, Not Transport:** The `attacker_position`","category":"external_commands","line_end":330,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the interface is bound to `localhost` or uses local IPC (unix","category":"external_commands","line_end":331,"severity":"medium","line_start":330},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"sockets, pipes, shared memory), the position is `\"LOCAL\"`, even","category":"external_commands","line_end":335,"severity":"medium","line_start":331},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"control plane), the position is `\"INTERNAL_NETWORK\"` (or","category":"external_commands","line_end":336,"severity":"medium","line_start":335},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"IN_CLUSTER\"` if restricted to pod-to-pod), even if it is a web","category":"external_commands","line_end":338,"severity":"medium","line_start":336},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The position is only `\"EXTERNAL\"` if the interface is directly","category":"external_commands","line_end":343,"severity":"medium","line_start":338},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"PHYSICAL_TEMPORARY\"` or `\"PHYSICAL_LONG_TERM\"`, regardless of","category":"external_commands","line_end":343,"severity":"medium","line_start":343},{"id":"external_commands:SKILL.md:349:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Phrases matching `\"authenticated <role>\"`, `\"customer with\"`,","category":"external_commands","line_end":349,"severity":"medium","line_start":349},{"id":"external_commands:SKILL.md:350:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"tenant <role>\"`, `\"Fitbit user\"` on a public product ->","category":"external_commands","line_end":350,"severity":"medium","line_start":350},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"EXTERNAL\"` (with `privileges_required: \"LOW\"`).","category":"external_commands","line_end":351,"severity":"medium","line_start":351},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Phrases matching `\"local user\"`, `\"local shell\"`,","category":"external_commands","line_end":352,"severity":"medium","line_start":352},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"local access\"` -> `\"LOCAL\"`.","category":"external_commands","line_end":353,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Phrases matching `\"peer <role> in same job/cluster/pod\"`,","category":"external_commands","line_end":355,"severity":"medium","line_start":354},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"co-tenant\"`,","category":"external_commands","line_end":356,"severity":"medium","line_start":355},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"in-cluster (Kubernetes/container-orchestrator) workload\"`,","category":"external_commands","line_end":357,"severity":"medium","line_start":356},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"NCCL peer rank\"` -> `\"IN_CLUSTER\"`.","category":"external_commands","line_end":357,"severity":"medium","line_start":357},{"id":"external_commands:SKILL.md:358:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Phrases matching `\"malicious dependency\"`, `\"upstream package\"`,","category":"external_commands","line_end":358,"severity":"medium","line_start":358},{"id":"external_commands:SKILL.md:359:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"build-time\"`, `\"CI pipeline\"` -> `\"SUPPLY_CHAIN\"`.","category":"external_commands","line_end":359,"severity":"medium","line_start":359},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Phrases matching `\"host hypervisor\"`, `\"host OS\"`,","category":"external_commands","line_end":360,"severity":"medium","line_start":360},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"hypervisor access\"` -> `\"HOST_SYSTEM\"`.","category":"external_commands","line_end":361,"severity":"medium","line_start":361},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Phrases matching `\"physical access\"`, `\"fault injection\"` ->","category":"external_commands","line_end":362,"severity":"medium","line_start":362},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"PHYSICAL_LONG_TERM\"` or `\"PHYSICAL_TEMPORARY\"` based on","category":"external_commands","line_end":363,"severity":"medium","line_start":363},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"EXTERNAL\"`: If the component is `\"EXPOSED\"`, or it's an auth","category":"external_commands","line_end":367,"severity":"medium","line_start":367},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"LOCAL\"`: If it's a local privilege escalation (LPE) or SUID","category":"external_commands","line_end":371,"severity":"medium","line_start":369},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"IN_CLUSTER\"`: If it targets in-cluster infrastructure (CSI/CNI)","category":"external_commands","line_end":373,"severity":"medium","line_start":371},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"HOST_SYSTEM\"`: If the attacker is the hypervisor, host OS, or","category":"external_commands","line_end":379,"severity":"medium","line_start":373},{"id":"external_commands:SKILL.md:379:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"LOCAL\"` (or `\"IN_CLUSTER\"` for Kubernetes pod-to-node; a","category":"external_commands","line_end":379,"severity":"medium","line_start":379},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"HOST_SYSTEM\"`.","category":"external_commands","line_end":382,"severity":"medium","line_start":381},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"PHYSICAL_LONG_TERM\"` / `\"PHYSICAL_TEMPORARY\"`: If the bug","category":"external_commands","line_end":382,"severity":"medium","line_start":382},{"id":"external_commands:SKILL.md:385:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"SUPPLY_CHAIN\"`: For build-time or dependency modification","category":"external_commands","line_end":387,"severity":"medium","line_start":385},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"INTERNAL_NETWORK\"`: Default fallback for other internal","category":"external_commands","line_end":390,"severity":"medium","line_start":387},{"id":"external_commands:SKILL.md:390:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the `attacker_position` is `\"LOCAL\"` or `\"IN_CLUSTER\"`, you","category":"external_commands","line_end":390,"severity":"medium","line_start":390},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**MUST** resolve `inferred_exposure` to `\"INTERNAL\"` (using 0.8","category":"external_commands","line_end":391,"severity":"medium","line_start":391},{"id":"external_commands:SKILL.md:393:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"mapped to `\"EXPOSED\"` in the Threat Model, unless the exploit","category":"external_commands","line_end":395,"severity":"medium","line_start":393},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the `attacker_position` is `\"INTERNAL_NETWORK\"`, you **MUST**","category":"external_commands","line_end":395,"severity":"medium","line_start":395},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"resolve `inferred_exposure` to at most `\"INTERNAL\"` (using 0.8","category":"external_commands","line_end":396,"severity":"medium","line_start":396},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"EXPOSED\"` in the Threat Model, as the interface is not directly","category":"external_commands","line_end":400,"severity":"medium","line_start":398},{"id":"external_commands:SKILL.md:400:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the `attacker_position` is `\"EXTERNAL\"`, you **MUST** resolve","category":"external_commands","line_end":400,"severity":"medium","line_start":400},{"id":"external_commands:SKILL.md:401:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`inferred_exposure` to `\"EXPOSED\"` (using 1.0 multiplier) even if","category":"external_commands","line_end":401,"severity":"medium","line_start":401},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the component is mapped to `\"INTERNAL\"` or `\"PRIVILEGED\"` in the","category":"external_commands","line_end":402,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:411:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"availability-only (DoS), check the component's `availability_tier` in","category":"external_commands","line_end":413,"severity":"medium","line_start":411},{"id":"external_commands:SKILL.md:413:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `LOW_CRITICALITY`: Reduce multiplier to **0.5**.","category":"external_commands","line_end":414,"severity":"medium","line_start":413},{"id":"external_commands:SKILL.md:414:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `STANDARD`: Reduce multiplier to **0.8**.","category":"external_commands","line_end":415,"severity":"medium","line_start":414},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CRITICAL`: Keep multiplier at **1.0**.","category":"external_commands","line_end":421,"severity":"medium","line_start":415},{"id":"external_commands:SKILL.md:421:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"snapshot, `code_paths` file is absent under the pinned CODE_ROOT) —","category":"external_commands","line_end":423,"severity":"medium","line_start":421},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"multiplier and set `STALE_EVIDENCE` as the first token of","category":"external_commands","line_end":424,"severity":"medium","line_start":423},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`sanity_triage_applied`.** Any dead-code analysis you do run MUST","category":"external_commands","line_end":429,"severity":"medium","line_start":424},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `user_interaction` is **REQUIRED** (e.g., CSRF, Clickjacking, or","category":"external_commands","line_end":435,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `production_viability` is **SAMPLE_OR_TEST**:","category":"external_commands","line_end":441,"severity":"medium","line_start":435},{"id":"external_commands:SKILL.md:441:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`0.4`, as this would incorrectly increase it if the component's","category":"external_commands","line_end":443,"severity":"medium","line_start":441},{"id":"external_commands:SKILL.md:443:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`0.4` (e.g. `0.2`).","category":"external_commands","line_end":443,"severity":"medium","line_start":443},{"id":"external_commands:SKILL.md:444:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- In the `executive_summary`, explicitly state that this is not a","category":"external_commands","line_end":448,"severity":"medium","line_start":444},{"id":"external_commands:SKILL.md:448:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `production_viability` is **CONDITIONAL_VIABLE**:","category":"external_commands","line_end":454,"severity":"medium","line_start":448},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Interaction). Do not override the Context Multiplier directly to `0.7`,","category":"external_commands","line_end":456,"severity":"medium","line_start":454},{"id":"external_commands:SKILL.md:456:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"already deep/isolated (`0.5`).","category":"external_commands","line_end":457,"severity":"medium","line_start":456},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- In the `executive_summary`, document the specific conditions required","category":"external_commands","line_end":484,"severity":"medium","line_start":457},{"id":"external_commands:SKILL.md:484:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Check if the `THREAT_MODEL.md` defines any `Calibration Overrides` (e.g.,","category":"external_commands","line_end":484,"severity":"medium","line_start":484},{"id":"external_commands:SKILL.md:485:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`LIFT_CAP: PHYSICAL_LONG_TERM`). If an override exists for a finding's","category":"external_commands","line_end":501,"severity":"medium","line_start":485},{"id":"external_commands:SKILL.md:501:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`code_paths` file is absent under the pinned CODE_ROOT), the following","category":"external_commands","line_end":503,"severity":"medium","line_start":501},{"id":"external_commands:SKILL.md:503:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"re-inspection: `repro_failure` (do not force-LOW), `vague_code_paths` (do","category":"external_commands","line_end":503,"severity":"medium","line_start":503},{"id":"external_commands:SKILL.md:504:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"not force-LOW), and the `static_confirmation` **trace-lift exception** (do","category":"external_commands","line_end":508,"severity":"medium","line_start":504},{"id":"external_commands:SKILL.md:508:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"token `STALE_EVIDENCE` as the FIRST token of `sanity_triage_applied`**","category":"external_commands","line_end":508,"severity":"medium","line_start":508},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(before any `Incomplete Calibration (UNKNOWN: ...)` warnings and before the","category":"external_commands","line_end":510,"severity":"medium","line_start":509},{"id":"external_commands:SKILL.md:510:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"fired-rule list). Record the guarded rules in `calibration_checklist` as","category":"external_commands","line_end":511,"severity":"medium","line_start":510},{"id":"external_commands:SKILL.md:511:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"specified in preamble P4 (`repro_failure`/`vague_code_paths` -> `UNKNOWN`","category":"external_commands","line_end":511,"severity":"medium","line_start":511},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"with a `STALE_EVIDENCE:` reason; `static_confirmation` -> `APPLIES` with a","category":"external_commands","line_end":512,"severity":"medium","line_start":512},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`STALE_EVIDENCE:` reason noting the trace-lift was suppressed). In MODE ==","category":"external_commands","line_end":517,"severity":"medium","line_start":513},{"id":"external_commands:SKILL.md:517:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Policy for UNKNOWN outcomes:** If a rule is evaluated as `UNKNOWN`, do","category":"external_commands","line_end":521,"severity":"medium","line_start":517},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the `\"sanity_triage_applied\"` string:","category":"external_commands","line_end":522,"severity":"medium","line_start":521},{"id":"external_commands:SKILL.md:522:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"Incomplete Calibration (UNKNOWN: <rule_name>)\"` (or a semicolon-separated","category":"external_commands","line_end":526,"severity":"medium","line_start":522},{"id":"external_commands:SKILL.md:526:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`sanity_triage_applied` as a semicolon-separated list, most restrictive","category":"external_commands","line_end":527,"severity":"medium","line_start":526},{"id":"external_commands:SKILL.md:527:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"first (e.g., `\"Local Attack Vector; Internal/Nested\"`), appended after any","category":"external_commands","line_end":535,"severity":"medium","line_start":527},{"id":"external_commands:SKILL.md:535:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`privileges_required` is **NONE**) who is not already in an effective","category":"external_commands","line_end":536,"severity":"medium","line_start":535},{"id":"external_commands:SKILL.md:536:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"position to compromise the system, AND `user_interaction` is **NONE**","category":"external_commands","line_end":541,"severity":"medium","line_start":536},{"id":"external_commands:SKILL.md:541:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`availability_tier` is explicitly documented as `CRITICAL` in the Threat","category":"external_commands","line_end":541,"severity":"medium","line_start":541},{"id":"external_commands:SKILL.md:557:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/helpers/append_calibrate.py`) during your first finding update.","category":"external_commands","line_end":560,"severity":"medium","line_start":557},{"id":"external_commands:SKILL.md:560:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"to `workspace/findings/<id>.json`.","category":"external_commands","line_end":563,"severity":"medium","line_start":560},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`append_calibrate.py` MUST be the exact comment","category":"external_commands","line_end":564,"severity":"medium","line_start":563},{"id":"external_commands:SKILL.md:564:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`# MANTIS_HELPER_VERSION = 2`. Before reusing an existing helper, read its","category":"external_commands","line_end":566,"severity":"medium","line_start":564},{"id":"external_commands:SKILL.md:566:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`# MANTIS_HELPER_VERSION = 2` (marker missing or a different integer),","category":"external_commands","line_end":568,"severity":"medium","line_start":566},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"new `snapshot` history field and the `STALE_EVIDENCE` handling). The","category":"external_commands","line_end":568,"severity":"medium","line_start":568},{"id":"external_commands:SKILL.md:569:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"regenerated helper MUST be able to write the `snapshot` key into the","category":"external_commands","line_end":570,"severity":"medium","line_start":569},{"id":"external_commands:SKILL.md:570:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"appended `history` entry and to prepend `STALE_EVIDENCE` to","category":"external_commands","line_end":570,"severity":"medium","line_start":570},{"id":"external_commands:SKILL.md:571:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`sanity_triage_applied`. The helper is STATE-RELATIVE","category":"external_commands","line_end":572,"severity":"medium","line_start":571},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`workspace/helpers/...`, Block A step 3) — never write it under CODE_ROOT.","category":"external_commands","line_end":577,"severity":"medium","line_start":572},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"impact_score\"` (1-5)","category":"external_commands","line_end":579,"severity":"medium","line_start":577},{"id":"external_commands:SKILL.md:579:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"likelihood_score\"` (1-5)","category":"external_commands","line_end":581,"severity":"medium","line_start":579},{"id":"external_commands:SKILL.md:581:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"availability_tier\"` (CRITICAL, STANDARD, LOW_CRITICALITY or null)","category":"external_commands","line_end":583,"severity":"medium","line_start":581},{"id":"external_commands:SKILL.md:583:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"inferred_exposure\"` (EXPOSED, INTERNAL, or PRIVILEGED)","category":"external_commands","line_end":585,"severity":"medium","line_start":583},{"id":"external_commands:SKILL.md:585:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"attacker_position\"` (preserved from input, or populated from fallback","category":"external_commands","line_end":588,"severity":"medium","line_start":585},{"id":"external_commands:SKILL.md:588:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"mantis_risk_score\"` (the final Hazard score)","category":"external_commands","line_end":590,"severity":"medium","line_start":588},{"id":"external_commands:SKILL.md:590:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"priority\"` (CRITICAL, HIGH, MEDIUM, LOW)","category":"external_commands","line_end":592,"severity":"medium","line_start":590},{"id":"external_commands:SKILL.md:592:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"sanity_triage_applied\"` (semicolon-separated list, or null). Ordering:","category":"external_commands","line_end":593,"severity":"medium","line_start":592},{"id":"external_commands:SKILL.md:593:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`STALE_EVIDENCE` first if the finding was STALE (preamble P4); then any","category":"external_commands","line_end":594,"severity":"medium","line_start":593},{"id":"external_commands:SKILL.md:594:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`Incomplete Calibration (UNKNOWN: <rule>)` warnings; then the Section 3","category":"external_commands","line_end":596,"severity":"medium","line_start":594},{"id":"external_commands:SKILL.md:596:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"STALE_EVIDENCE; Incomplete Calibration (UNKNOWN: physical_long_term); Local Attack Vector\"`.","category":"external_commands","line_end":598,"severity":"medium","line_start":596},{"id":"external_commands:SKILL.md:598:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"calibration_checklist\"` object containing evaluations for all 27 sanity","category":"external_commands","line_end":602,"severity":"medium","line_start":598},{"id":"external_commands:SKILL.md:602:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":632,"severity":"medium","line_start":602},{"id":"external_commands:SKILL.md:632:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":634,"severity":"medium","line_start":632},{"id":"external_commands:SKILL.md:634:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For each rule, `outcome` must be set to:","category":"external_commands","line_end":636,"severity":"medium","line_start":634},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"APPLIES\"`: if the sanity cap rule applies (fires) to this finding,","category":"external_commands","line_end":637,"severity":"medium","line_start":636},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"capping or downgrading its score/priority. A detailed `reason` string is","category":"external_commands","line_end":639,"severity":"medium","line_start":637},{"id":"external_commands:SKILL.md:639:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"DOES_NOT_APPLY\"`: if the sanity cap rule does not apply. The `reason`","category":"external_commands","line_end":639,"severity":"medium","line_start":639},{"id":"external_commands:SKILL.md:641:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"UNKNOWN\"`: if it is unresolved. A detailed `reason` string is","category":"external_commands","line_end":641,"severity":"medium","line_start":641},{"id":"external_commands:SKILL.md:644:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For backward compatibility, the schema also permits `\"fires\": <bool>` (with","category":"external_commands","line_end":645,"severity":"medium","line_start":644},{"id":"external_commands:SKILL.md:645:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`reason` required only if `fires` is `true`), but the new `\"outcome\"`","category":"external_commands","line_end":645,"severity":"medium","line_start":645},{"id":"external_commands:SKILL.md:648:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"outrage_commentary\"` (your reasoning about the outrage factor)","category":"external_commands","line_end":650,"severity":"medium","line_start":648},{"id":"external_commands:SKILL.md:650:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"executive_summary\"`","category":"external_commands","line_end":652,"severity":"medium","line_start":650},{"id":"external_commands:SKILL.md:652:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- An entry to the `\"history\"` array:","category":"external_commands","line_end":654,"severity":"medium","line_start":652},{"id":"external_commands:SKILL.md:654:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":663,"severity":"medium","line_start":654},{"id":"filesystem:SKILL.md:29:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- `workspace/.mantis_state.json` (to track the current loop pass, and to read","category":"filesystem","line_end":29,"severity":"medium","line_start":29},{"id":"filesystem:SKILL.md:71:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"c. Else read state_root/workspace/.mantis_state.json (state_root from","category":"filesystem","line_end":71,"severity":"medium","line_start":71},{"id":"filesystem:SKILL.md:77:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"verify CODE_ROOT/.mantis_snapshot_id exists and equals SNAPSHOT_ID. If missing","category":"filesystem","line_end":77,"severity":"medium","line_start":77},{"id":"filesystem:SKILL.md:95:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"run in the LIVE repository root (which still has .git/.hg/.repo), NOT CODE_ROOT","category":"filesystem","line_end":95,"severity":"medium","line_start":95},{"id":"filesystem:SKILL.md:97:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"lacks .git/.hg/.repo.","category":"filesystem","line_end":97,"severity":"medium","line_start":97},{"id":"filesystem:SKILL.md:117:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"`state_root/workspace/.mantis_state.json` (Block A step 0/1c). NEVER stop if it","category":"filesystem","line_end":117,"severity":"medium","line_start":117},{"id":"filesystem:SKILL.md:92:temp-file-creation","file":"SKILL.md","pattern":"Temp file creation","snippet":"(mktemp -d from CODE_ROOT), never with cwd=CODE_ROOT. Read-only inspection may","category":"filesystem","line_end":92,"severity":"low","line_start":92},{"id":"blocker:SKILL.md:73:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"-> active_snapshot.root / .snapshot_id / .snapshot_pinned.","category":"blocker","line_end":73,"severity":"low","line_start":73},{"id":"blocker:SKILL.md:76:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. SENTINEL CHECK (only if snapshot_pinned is true AND you did NOT take path 1a):","category":"blocker","line_end":76,"severity":"low","line_start":76},{"id":"blocker:SKILL.md:77:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"verify CODE_ROOT/.mantis_snapshot_id exists and equals SNAPSHOT_ID. If missing","category":"blocker","line_end":77,"severity":"low","line_start":77},{"id":"blocker:SKILL.md:158:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"(Section 3 rule, its \"valid external stack trace/sanitizer...\" exception): do NOT","category":"blocker","line_end":158,"severity":"low","line_start":158},{"id":"blocker:SKILL.md:346:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"string that does not exactly match one of the valid enum values","category":"blocker","line_end":346,"severity":"low","line_start":346},{"id":"blocker:SKILL.md:348:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"valid enum using these mappings:","category":"blocker","line_end":348,"severity":"low","line_start":348}],"finding_verdicts":[{"id":"blocker:references/calibration_rules.md:118:system-reconnaissance","reason":"The rule evaluates existing stack or sanitizer traces as reproduction evidence. It does not collect system information or execute reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/calibration_rules.md:232:system-reconnaissance","reason":"USB insertion and physical attacks describe vulnerability prerequisites for a priority cap. They are not instructions to enumerate or probe systems.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/calibration_rules.md:150:known-jailbreak-keywords","reason":"Prompt injection and jailbreaking are named as attack categories in a calibration rule. The passage does not instruct the auditor to bypass safeguards.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The backticks format a skill invocation name, not an executable shell expression. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks format documented workspace paths and finding fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"This is a fenced locator-resolution procedure, not Ruby or shell code using executable backticks. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"This is a fenced locator-resolution procedure, not Ruby or shell code using executable backticks. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The backticks format snapshot pass checks and status values in a defensive note. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The backticks format snapshot pass checks and status values in a defensive note. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The backticks format snapshot pass checks and status values in a defensive note. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The backticks format snapshot pass checks and status values in a defensive note. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The backticks format snapshot pass checks and status values in a defensive note. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The backticks format snapshot pass checks and status values in a defensive note. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The backticks format snapshot pass checks and status values in a defensive note. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"The backticks format provenance fields, locator syntax, and conservative stale-evidence scoring rules. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The backticks format pipeline inputs, fallback values, and snapshot arguments for delegated calibration. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The backticks format scoring metadata and eligibility rules, not executable shell expressions. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","reason":"The backticks format scoring metadata and eligibility rules, not executable shell expressions. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"The backticks format scoring metadata and eligibility rules, not executable shell expressions. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:349:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:350:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:358:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:359:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:379:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:385:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:390:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:393:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:400:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:401:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"The backticks format exposure metadata, attacker-position enums, and normalization mappings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:411:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:413:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:414:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:421:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:441:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:443:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:444:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:448:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:456:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","reason":"The backticks format context multipliers, viability values, and stale-evidence annotations. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:484:ruby-shell-backtick-execution","reason":"The backticks format project calibration override names within the documented scoring policy. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:485:ruby-shell-backtick-execution","reason":"The backticks format project calibration override names within the documented scoring policy. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:501:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:503:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:504:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:508:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:510:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:511:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:517:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:522:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:526:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:527:ruby-shell-backtick-execution","reason":"The backticks format rule outcomes and audit warnings that preserve conservative scores. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:535:ruby-shell-backtick-execution","reason":"The backticks format prerequisite and availability fields used to restrict CRITICAL priority. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:536:ruby-shell-backtick-execution","reason":"The backticks format prerequisite and availability fields used to restrict CRITICAL priority. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:541:ruby-shell-backtick-execution","reason":"The backticks format prerequisite and availability fields used to restrict CRITICAL priority. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:557:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:560:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:564:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:566:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:569:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:570:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:571:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","reason":"The backticks format helper paths, version comments, and update fields, not shell command substitution. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:579:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:581:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:583:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:585:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:588:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:590:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:592:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:593:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:594:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:596:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:598:ruby-shell-backtick-execution","reason":"The backticks format output field names and example calibration warnings. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:602:ruby-shell-backtick-execution","reason":"The fenced JSON checklist is an output template, not an executable shell or Ruby block. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:632:ruby-shell-backtick-execution","reason":"The fenced JSON checklist is an output template, not an executable shell or Ruby block. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:634:ruby-shell-backtick-execution","reason":"The backticks format checklist outcome values and backward-compatible field names. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","reason":"The backticks format checklist outcome values and backward-compatible field names. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","reason":"The backticks format checklist outcome values and backward-compatible field names. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:639:ruby-shell-backtick-execution","reason":"The backticks format checklist outcome values and backward-compatible field names. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:641:ruby-shell-backtick-execution","reason":"The backticks format checklist outcome values and backward-compatible field names. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:644:ruby-shell-backtick-execution","reason":"The backticks format checklist outcome values and backward-compatible field names. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:645:ruby-shell-backtick-execution","reason":"The backticks format checklist outcome values and backward-compatible field names. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:648:ruby-shell-backtick-execution","reason":"The backticks format commentary, summary, and history output fields. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:650:ruby-shell-backtick-execution","reason":"The backticks format commentary, summary, and history output fields. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:652:ruby-shell-backtick-execution","reason":"The backticks format commentary, summary, and history output fields. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:654:ruby-shell-backtick-execution","reason":"The fenced JSON history entry is an output template, not an executable shell or Ruby block. The source context confirms Markdown syntax rather than the detected execution pattern.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:29:hidden-file-access","reason":"The hidden file is declared Mantis workflow state used for pass and snapshot provenance. No credential-file access or unrelated hidden-file collection is instructed.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:71:hidden-file-access","reason":"The locator procedure reads the declared workspace state to resolve the active snapshot. This is application metadata, not secret discovery.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:77:hidden-file-access","reason":"The snapshot sentinel verifies that the selected tree matches its recorded identifier. This defensive metadata check does not access credentials.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:95:hidden-file-access","reason":"The passage directs legitimate VCS history and diff inspection to the live repository containing its metadata. It does not request secret extraction.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:97:hidden-file-access","reason":"The passage explains why snapshots may lack VCS metadata and should not cause a halt. It does not request access to unrelated hidden files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:117:hidden-file-access","reason":"The state read supplies snapshot provenance for calibration and permits missing state. It targets declared workflow metadata, not private configuration or credentials.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:92:temp-file-creation","reason":"The temporary directory is a private shadow for artifact-producing commands, protecting the pinned snapshot from modification. No destructive or exfiltrating use is described.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:73:system-reconnaissance","reason":"The dotted names are fields of the active snapshot state object. They are not commands for collecting host information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:76:system-reconnaissance","reason":"The sentinel check validates snapshot provenance before inspection. No system enumeration is requested.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:77:system-reconnaissance","reason":"The check compares a snapshot sentinel with the expected identifier and stops on mismatch. This is integrity validation, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:158:system-reconnaissance","reason":"The passage suppresses score increases based on potentially stale stack or sanitizer traces. It describes evidence handling, not system data collection.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:346:system-reconnaissance","reason":"The word enum concerns validating attacker-position metadata against allowed values. No operating-system enumeration is instructed.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:348:system-reconnaissance","reason":"The passage normalizes free-text attacker positions into documented enumeration values. It does not enumerate processes, users, or system resources.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Workspace Helper Reuse Without Integrity Verification","severity":"high","locations":[{"file":"SKILL.md","line_end":560,"line_start":554},{"file":"SKILL.md","line_end":572,"line_start":562}],"confidence":0.88,"description":"The skill executes an existing workspace helper after checking only \"# MANTIS_HELPER_VERSION = 2\". An attacker controlling that helper can retain the comment and execute arbitrary code with agent permissions.","confidence_reasoning":"The instructions explicitly combine helper execution with a first-line version check, without requiring body verification. Exploitation requires attacker control of the workspace helper; no malicious helper is supplied."}],"subject_marketplace_commit_sha":"9958c759dc9c75fb509d50ad1fe7930c27e2799c","subject_content_hash":"c4eb14c114e308ed9f0147397be8b72cb2a5bb837177918e518d83f0c8c9e29b","subject_tree_hash":"aa3c1931002b07954f479025c0285b9ce70690b0d6880f1617eddf85d3331f89","subject_plugin_path":"skills/google/mantis-calibrate","audit_payload_hash":"19c87ba2c3a9676ed1a3c744c1b48b0b","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"9958c759dc9c75fb509d50ad1fe7930c27e2799c","contentHash":"c4eb14c114e308ed9f0147397be8b72cb2a5bb837177918e518d83f0c8c9e29b","treeHash":"aa3c1931002b07954f479025c0285b9ce70690b0d6880f1617eddf85d3331f89","pluginPath":"skills/google/mantis-calibrate","auditPayloadHash":"19c87ba2c3a9676ed1a3c744c1b48b0b"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/google-mantis-calibrate/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}