{"data":{"skill":{"slug":"google-mantis-history","name":"mantis-history","icon":"📦","repo":"https://github.com/google/mantis/tree/f48a85e8823ee6f4824ae9a24b9b2efb8aab8c9a/mantis-history","status":"approved","author":"google","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"21f96382-fd11-469a-ae93-82c68b8efb5c","skill_id":"0bfaf2db-7836-46e9-bf05-698a053f5bb0","version":1,"content_hash":"v3:17c5d34add4a2cc29dbf3b76753657cb3b83523e:ef777063f09b17e5c72bbc692eeaad70b436f0b9708dbb1ebc493addd459617b:c9c11a804c9cf85599b24b542984a9194d1800e9ce555c383f001104ae7ac791:736b696c6c732f676f6f676c652f6d616e7469732d686973746f7279:de1f075af76c0ae5ec5baff1e73a558a","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 58 static findings are false positives involving Markdown, legitimate workspace access, or read-only repository checks. A separate semantic risk concerns sending repository diffs and messages to unspecified LLM services without data-sharing safeguards. No evidence found of malicious commands, credential theft, or an actual prompt injection attempt.","remediation":[{"issue":"Repository diffs and messages may be sent to unspecified LLM services.","severity":"medium","suggestion":"Require approval for external processing, select an approved provider, redact secrets, minimize payloads, and offer a local-only analysis option."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":97,"line_start":58},{"file":"SKILL.md","line_end":99,"line_start":97},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":104,"line_start":103},{"file":"SKILL.md","line_end":105,"line_start":104},{"file":"SKILL.md","line_end":116,"line_start":105},{"file":"SKILL.md","line_end":127,"line_start":116},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":128,"line_start":128},{"file":"SKILL.md","line_end":131,"line_start":130},{"file":"SKILL.md","line_end":132,"line_start":131},{"file":"SKILL.md","line_end":133,"line_start":132},{"file":"SKILL.md","line_end":135,"line_start":133},{"file":"SKILL.md","line_end":136,"line_start":135},{"file":"SKILL.md","line_end":140,"line_start":136},{"file":"SKILL.md","line_end":166,"line_start":140},{"file":"SKILL.md","line_end":167,"line_start":166},{"file":"SKILL.md","line_end":168,"line_start":167},{"file":"SKILL.md","line_end":169,"line_start":168},{"file":"SKILL.md","line_end":170,"line_start":169},{"file":"SKILL.md","line_end":173,"line_start":170},{"file":"SKILL.md","line_end":174,"line_start":173},{"file":"SKILL.md","line_end":176,"line_start":174},{"file":"SKILL.md","line_end":177,"line_start":176},{"file":"SKILL.md","line_end":178,"line_start":177},{"file":"SKILL.md","line_end":179,"line_start":178},{"file":"SKILL.md","line_end":206,"line_start":179},{"file":"SKILL.md","line_end":209,"line_start":206},{"file":"SKILL.md","line_end":211,"line_start":209},{"file":"SKILL.md","line_end":230,"line_start":211},{"file":"SKILL.md","line_end":234,"line_start":230},{"file":"SKILL.md","line_end":236,"line_start":234}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":92,"line_start":92},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":137,"line_start":137}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Repository Data Sharing Without Defined Safeguards","locations":[{"file":"SKILL.md","line_end":185,"line_start":181},{"file":"SKILL.md","line_end":199,"line_start":194}],"confidence":0.86,"description":"The skill requests LLM calls containing commit diffs and messages without specifying provider approval, secret redaction, or local-only processing. External implementations could disclose proprietary code or historical secrets.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The instructions explicitly batch diffs and messages into LLM calls but define no data-sharing controls. Actual disclosure depends on the selected execution backend."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":240,"audit_model":"codex","audited_at":"2026-10-04T13:37:49.264+00:00","created_at":"2026-10-05T12:19:05.627523+00:00","static_findings":[{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Command:** `/mantis-history`","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"learnings file (`workspace/historical_learnings.jsonl`).","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--snapshot_root`/`--snapshot_id`/`--state_root`. History reads VCS logs from","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--state_root` only to place its cache/output/script. All absent -> DEGRADED","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/.mantis_state.json` (to track current loop pass).","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mantis-summary.md` (optional, if available).","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/historical_learnings.jsonl`.","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- All under `--state_root/workspace/` (cache, `historical_learnings.jsonl`,","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"extraction script): kept outside the target tree. Optional `history_status`","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"marker (`UNSUPPORTED_VCS` / `PARTIAL_SHALLOW`).","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"invalidated on VCS-history rewrite (`_analyzed_head` no longer reachable) or","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"a vcs_type/repo-identity change. On `none`/`unknown` VCS the stage writes an","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"empty DB + `history_status=UNSUPPORTED_VCS` and exits.","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":97,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":99,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"CRITICAL for history: the pinned snapshot copy STRIPS `.git`/`.hg`/`.repo`, so","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/historical_learnings.jsonl`, and your generated extraction script","category":"external_commands","line_end":104,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"under `--state_root/workspace/` (STATE-RELATIVE) — never into the target tree,","category":"external_commands","line_end":105,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"so a sync/clean cannot wipe them. Record `active_snapshot.snapshot_id` on","category":"external_commands","line_end":116,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read existing summaries (e.g. `mantis-summary.md` if available) or quickly","category":"external_commands","line_end":127,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`vcs_type` from `.mantis_state.json` `vcs_info` (or detect it in the LIVE","category":"external_commands","line_end":127,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"root). If `vcs_type` is `none` or `unknown`, OR the VCS history is","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/historical_learnings.jsonl`, set a top-of-file / sidecar marker","category":"external_commands","line_end":131,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`history_status = \"UNSUPPORTED_VCS\"`, and EXIT — never fabricate history.","category":"external_commands","line_end":132,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For `multi-vcs` (.repo): either iterate history per sub-project, or write","category":"external_commands","line_end":133,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the empty file with `history_status = \"UNSUPPORTED_VCS\"` rather than run a","category":"external_commands","line_end":135,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`git rev-parse --is-shallow-repository` == true): proceed but set","category":"external_commands","line_end":136,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`history_status = \"PARTIAL_SHALLOW\"` so downstream stages do NOT read \"no","category":"external_commands","line_end":140,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/.mantis_state.json` and resolve the current ISO 8601 timestamp.","category":"external_commands","line_end":166,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"cache (JSON or SQLite) under `workspace/` mapping","category":"external_commands","line_end":167,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`revision_id -> analyzed`, AND storing the full extracted record for each","category":"external_commands","line_end":168,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"analyzed revision plus an `_analyzed_head` high-water mark and the","category":"external_commands","line_end":169,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`vcs_type` + repo identity the cache was built against. On each run,","category":"external_commands","line_end":170,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"REBUILD `workspace/historical_learnings.jsonl` from the cache (do NOT","category":"external_commands","line_end":173,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"output DB to empty. Only analyze revisions NEWER than `_analyzed_head`.","category":"external_commands","line_end":174,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Rewrite detection:** before trusting the cache, verify `_analyzed_head`","category":"external_commands","line_end":176,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`git cat-file -e <_analyzed_head>` succeeds AND","category":"external_commands","line_end":177,"severity":"medium","line_start":176},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`git merge-base --is-ancestor <_analyzed_head> HEAD`; hg:","category":"external_commands","line_end":178,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`hg log -r <_analyzed_head>` succeeds). If it does not (force-push /","category":"external_commands","line_end":179,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"rebase / squash) OR `vcs_type`/repo identity changed, INVALIDATE the","category":"external_commands","line_end":206,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"into a JSONL file named `workspace/historical_learnings.jsonl`, matching","category":"external_commands","line_end":209,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Historical Learnings Schema Format (`workspace/historical_learnings.jsonl`)","category":"external_commands","line_end":211,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":230,"severity":"medium","line_start":211},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":234,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"revisions, and generate the `workspace/historical_learnings.jsonl` file.","category":"external_commands","line_end":236,"severity":"medium","line_start":234},{"id":"filesystem:SKILL.md:33:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- `workspace/.mantis_state.json` (to track current loop pass).","category":"filesystem","line_end":33,"severity":"medium","line_start":33},{"id":"filesystem:SKILL.md:68:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"c. Else read state_root/workspace/.mantis_state.json (state_root from","category":"filesystem","line_end":68,"severity":"medium","line_start":68},{"id":"filesystem:SKILL.md:74:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"verify CODE_ROOT/.mantis_snapshot_id exists and equals SNAPSHOT_ID. If missing","category":"filesystem","line_end":74,"severity":"medium","line_start":74},{"id":"filesystem:SKILL.md:92:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"run in the LIVE repository root (which still has .git/.hg/.repo), NOT CODE_ROOT","category":"filesystem","line_end":92,"severity":"medium","line_start":92},{"id":"filesystem:SKILL.md:94:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"lacks .git/.hg/.repo.","category":"filesystem","line_end":94,"severity":"medium","line_start":94},{"id":"filesystem:SKILL.md:140:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"`workspace/.mantis_state.json` and resolve the current ISO 8601 timestamp.","category":"filesystem","line_end":140,"severity":"medium","line_start":140},{"id":"filesystem:SKILL.md:89:temp-file-creation","file":"SKILL.md","pattern":"Temp file creation","snippet":"(mktemp -d from CODE_ROOT), never with cwd=CODE_ROOT. Read-only inspection may","category":"filesystem","line_end":89,"severity":"low","line_start":89},{"id":"filesystem:SKILL.md:137:hard-link-creation","file":"SKILL.md","pattern":"Hard link creation","snippet":"historical vuln for this file\" as \"clean.\"","category":"filesystem","line_end":137,"severity":"medium","line_start":137},{"id":"blocker:SKILL.md:70:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"-> active_snapshot.root / .snapshot_id / .snapshot_pinned.","category":"blocker","line_end":70,"severity":"low","line_start":70},{"id":"blocker:SKILL.md:73:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. SENTINEL CHECK (only if snapshot_pinned is true AND you did NOT take path 1a):","category":"blocker","line_end":73,"severity":"low","line_start":73},{"id":"blocker:SKILL.md:74:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"verify CODE_ROOT/.mantis_snapshot_id exists and equals SNAPSHOT_ID. If missing","category":"blocker","line_end":74,"severity":"low","line_start":74},{"id":"blocker:SKILL.md:157:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"messages or titles do not match these relevant keywords to avoid","category":"blocker","line_end":158,"severity":"low","line_start":157},{"id":"blocker:SKILL.md:167:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"`revision_id -> analyzed`, AND storing the full extracted record for each","category":"blocker","line_end":167,"severity":"low","line_start":167}],"finding_verdicts":[{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The backticks format the skill invocation name in Markdown. This is not Ruby code or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks format the documented output path. No executable expression appears on this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The backticks delimit optional argument names in prose. They do not execute shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The inline code identifies the state_root option for output placement. The surrounding text describes fallback behavior, not execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The backticks mark a workspace state filename in the input contract. No Ruby or shell expression is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"This line names an optional summary document using Markdown inline code. It contains no execution instruction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The inline code names the expected historical learnings output. Backticks here are Markdown formatting, not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"This line documents the workspace destination for cache and output files. The marked paths are not executable expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks identify a status field in the output contract. Mentioning an extraction script does not constitute backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The inline code lists two history status values. These are data labels, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The backticks identify a cache high-water mark in the invalidation policy. No shell substitution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The backticks delimit unsupported VCS type values. These are ordinary configuration labels in prose.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The inline code describes an unsupported-history status marker. It is not a command execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"This is the opening Markdown fence for locator-resolution pseudocode. The block defines workspace boundaries and does not contain Ruby backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"This is the closing Markdown fence for locator-resolution instructions. The nearby VCS metadata names are explanatory text, not executable substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The backticks identify VCS metadata directories removed from snapshots. They do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"This text names the output database and generated script destination. Inline code formatting is not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The marked path specifies state-relative storage outside the target tree. No command substitution or executable payload is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The inline code identifies the snapshot provenance field. The surrounding range describes analysis setup, not backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The marked filename is an optional architecture summary input. Reading project summaries is legitimate context gathering without shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The backticks identify state fields and the application state filename. This is a VCS-support check, not executable Ruby or shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"This line formats VCS type values in a conditional description. No execution expression is supplied.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"The backticks mark the output filename and nearby status assignment. These describe data output rather than shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The inline expression is an unsupported-history status value. The instruction explicitly prevents fabrication when history is unavailable.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"This line labels multi-VCS handling in Markdown. It documents an unsupported-history fallback without shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"The inline code specifies an unsupported-history marker. The surrounding text discourages running incompatible extraction scripts.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"The documented git rev-parse command is a read-only shallow-clone check. Markdown backticks do not create a shell substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The inline code is a partial-history status marker. The surrounding warning prevents downstream interpretation of missing history as proof of safety.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The marked path names application state used for pass tracking. The surrounding instructions do not contain executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The backticks identify the local workspace cache directory. This is output placement documentation, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"The inline code describes a revision-to-analysis cache mapping. It is data notation, not Ruby or shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The backticks identify the cache high-water mark field. No executable expression appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The inline code names the VCS type used for cache identity checks. The line describes cache metadata rather than execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The marked filename is the database rebuilt from cached records. Markdown formatting does not execute the path.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"The backticks identify a revision checkpoint for incremental processing. This is cache logic, not command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The inline code names the checkpoint whose reachability must be verified. The line supplies no executable payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"The documented git cat-file check only verifies a cached revision exists. No shell interpolation implementation or attacker-controlled command payload is shown.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"The documented git merge-base check tests ancestry without modifying repository data. Backticks format a command example rather than executing it.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"The documented hg log check validates revision reachability for cache invalidation. No unsafe shell interpolation implementation is present.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The inline code identifies VCS type metadata used to invalidate stale caches. The surrounding analysis workflow contains no Ruby backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The backticks mark the intended JSONL output path. This is an output contract, not a shell execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The schema heading formats the output filename as inline code. It contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","reason":"This is a Markdown fence introducing an example record structure. The contents are data fields, not Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"This is the closing Markdown fence for the example record. It does not invoke any shell operation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The marked text is the output filename in the execution-verification phase. Script execution is documented, but no Ruby backtick operation is present.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:33:hidden-file-access","reason":"The hidden file is Mantis workspace state read to determine the current pass. No credential store or unrelated private file is requested.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:68:hidden-file-access","reason":"Reading application state resolves the active snapshot and workspace location. The access is scoped to the documented Mantis state file.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:74:hidden-file-access","reason":"The hidden snapshot sentinel is checked against the expected snapshot identifier. This integrity check stops processing on mismatches.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:92:hidden-file-access","reason":"The metadata directories provide history for the explicitly requested repository analysis. The instruction uses the live repository because snapshots remove VCS metadata.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:94:hidden-file-access","reason":"This line explains that snapshots lack VCS metadata directories. It requests no unrelated hidden-file access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:140:hidden-file-access","reason":"The application state file supplies the current pass number for provenance. No secret collection is described.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:89:temp-file-creation","reason":"The temporary directory supports a private shadow copy instead of writes to a pinned snapshot. No predictable shared filename or unsafe temporary-file permissions are specified.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:137:hard-link-creation","reason":"The line warns against treating missing historical vulnerabilities as evidence of clean code. It contains no hard-link operation.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:70:system-reconnaissance","reason":"This line lists application snapshot metadata fields. It performs no host, account, or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:73:system-reconnaissance","reason":"This is the condition for checking snapshot integrity. It does not enumerate system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:74:system-reconnaissance","reason":"The check compares a project snapshot sentinel with the expected identifier. This is scoped integrity validation, not reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:157:system-reconnaissance","reason":"The text describes filtering commit messages by relevant keywords. It contains no system-information collection command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:167:system-reconnaissance","reason":"The line defines a local cache mapping for analyzed revisions. It does not inspect host identities or system configuration.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Repository Data Sharing Without Defined Safeguards","severity":"medium","locations":[{"file":"SKILL.md","line_end":185,"line_start":181},{"file":"SKILL.md","line_end":199,"line_start":194}],"confidence":0.86,"description":"The skill requests LLM calls containing commit diffs and messages without specifying provider approval, secret redaction, or local-only processing. External implementations could disclose proprietary code or historical secrets.","confidence_reasoning":"The instructions explicitly batch diffs and messages into LLM calls but define no data-sharing controls. Actual disclosure depends on the selected execution backend."}],"subject_marketplace_commit_sha":"17c5d34add4a2cc29dbf3b76753657cb3b83523e","subject_content_hash":"ef777063f09b17e5c72bbc692eeaad70b436f0b9708dbb1ebc493addd459617b","subject_tree_hash":"c9c11a804c9cf85599b24b542984a9194d1800e9ce555c383f001104ae7ac791","subject_plugin_path":"skills/google/mantis-history","audit_payload_hash":"de1f075af76c0ae5ec5baff1e73a558a","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"17c5d34add4a2cc29dbf3b76753657cb3b83523e","contentHash":"ef777063f09b17e5c72bbc692eeaad70b436f0b9708dbb1ebc493addd459617b","treeHash":"c9c11a804c9cf85599b24b542984a9194d1800e9ce555c383f001104ae7ac791","pluginPath":"skills/google/mantis-history","auditPayloadHash":"de1f075af76c0ae5ec5baff1e73a558a"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/google-mantis-history/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}