{"data":{"skill":{"slug":"google-mantis-structural-index","name":"mantis-structural-index","icon":"📦","repo":"https://github.com/google/mantis/tree/f48a85e8823ee6f4824ae9a24b9b2efb8aab8c9a/mantis-structural-index","status":"approved","author":"google","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"c8417104-18d3-41f1-8bf2-e13fd78e92c2","skill_id":"9df0bd21-fe2d-42a7-bac0-087d4aedaa9e","version":1,"content_hash":"v3:0bd3c12a7023af664e0537d6e6f74414f1b538f3:5a65e55890846a1592a044bd9c117579305030f4c442daf79f3b6a9b3befe9bc:88d39712415df7ead48c304bb2ac088f1219e94288840141a88d63e65d969788:736b696c6c732f676f6f676c652f6d616e7469732d7374727563747572616c2d696e646578:4286bf659dea151026dc68ba6f1afde4","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 225 static matches are documentation syntax or legitimate indexing operations, not the reported threats. Semantic review identifies forgeable helper-version checks and missing remote-query disclosure controls. No evidence found of malicious payloads, credential theft, or audit-directed prompt injection in the supplied skill.","remediation":[{"issue":"Executable helper reuse checks a version comment instead of trusted content.","severity":"high","suggestion":"Regenerate helpers from trusted source or verify their complete content against trusted hashes before execution. Reject symlinks and restrict helper-directory ownership and write permissions."},{"issue":"Remote providers have no explicit endpoint approval or data-disclosure policy.","severity":"medium","suggestion":"Default to local queries and require approval for each remote endpoint. Require protected transport, validate destinations, and document which repository metadata may leave the workspace."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":132,"line_start":93},{"file":"SKILL.md","line_end":142,"line_start":132},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":144,"line_start":143},{"file":"SKILL.md","line_end":147,"line_start":144},{"file":"SKILL.md","line_end":148,"line_start":147},{"file":"SKILL.md","line_end":149,"line_start":148},{"file":"SKILL.md","line_end":149,"line_start":149},{"file":"SKILL.md","line_end":153,"line_start":150},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":154,"line_start":154},{"file":"SKILL.md","line_end":155,"line_start":155},{"file":"SKILL.md","line_end":158,"line_start":157},{"file":"SKILL.md","line_end":171,"line_start":158},{"file":"SKILL.md","line_end":172,"line_start":171},{"file":"SKILL.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":175,"line_start":174},{"file":"SKILL.md","line_end":177,"line_start":175},{"file":"SKILL.md","line_end":177,"line_start":177},{"file":"SKILL.md","line_end":180,"line_start":178}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":744,"line_start":744},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":312,"line_start":312},{"file":"SKILL.md","line_end":124,"line_start":124}]}],"critical_findings":[],"high_findings":[{"title":"Helper Reuse Relies on a Forgeable Version Marker","locations":[{"file":"SKILL.md","line_end":271,"line_start":260},{"file":"SKILL.md","line_end":301,"line_start":296}],"confidence":0.86,"description":"Existing executable helpers are reused after checking only the marker '# MANTIS_HELPER_VERSION = 5'. An attacker who can modify workspace helpers can retain that marker and substitute code executed during indexing or queries.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The instructions explicitly permit helper reuse based on a public version comment without requiring content integrity or trusted ownership. Exploitation requires workspace write access; no actual substituted helper was supplied."}],"medium_findings":[{"title":"Remote Queries Lack an Explicit Data-Disclosure Boundary","locations":[{"file":"SKILL.md","line_end":304,"line_start":302},{"file":"SKILL.md","line_end":675,"line_start":647},{"file":"SKILL.md","line_end":685,"line_start":677}],"confidence":0.73,"description":"Remote query providers can be selected through MANTIS_STRUCTURAL_INDEX_URL or manifest configuration. Symbol and file queries may disclose repository metadata without required endpoint approval, transport protection, or a data-sharing policy.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The specification offers remote access to operations accepting symbol names and file paths but states no explicit endpoint or disclosure restrictions. No evidence found of a malicious destination or implemented transfer; this is a conditional design risk."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":747,"audit_model":"codex","audited_at":"2026-10-04T13:37:57.429+00:00","created_at":"2026-10-05T12:12:15.25584+00:00","static_findings":[{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"code-reading analysis stage (summarize/architecture). It only needs `CODE_ROOT`","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\+ `SNAPSHOT_ID` and must not depend on architecture/KB.","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"degrading gracefully to grep. Provides `find_callers(symbol)`,","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`get_function_boundary(file, line)`, and call-site awareness to improve LLM","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Command:** `/mantis-structural-index`","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"code under `CODE_ROOT`.","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--snapshot_root`/`--snapshot_id`/`--state_root`. All absent → MODE-OFF/legacy","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`./workspace/kb/structural_index/`).","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/.mantis_state.json` (to read `active_snapshot` for provenance","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/manifest.json` (to check `snapshot_id` for","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index.jsonl` (backward-compat provenance check if","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/units/` (content-addressed cache for","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/native/` and sidecar `provenance.json` files","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"source files under `CODE_ROOT`).","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/manifest.json` (STATE-RELATIVE — atomic","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/catalog.sqlite` (STATE-RELATIVE —","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/units/` (STATE-RELATIVE — content-addressed","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/shards/` (STATE-RELATIVE — partitioned","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/native/` (STATE-RELATIVE — prebuilt index","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index/tmp/` (STATE-RELATIVE — temporary objects","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/kb/structural_index.jsonl` (STATE-RELATIVE — compatibility","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/helpers/build_structural_index.py` (STATE-RELATIVE — the builder","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workspace/helpers/query_structural_index.py` (STATE-RELATIVE — the query","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Source files must exist under `CODE_ROOT`. If `CODE_ROOT` is not resolved","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(MODE-OFF and no readable `active_snapshot`), build against the current","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"directory with `snapshot_id` set to `\"unknown\"`. Do NOT skip — this is the","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"invokes it (the harness, `mantis-plan`, or `mantis-researcher`). It never","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read-only on `CODE_ROOT`. Writes only to STATE-RELATIVE paths. Re-running","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"with the same `CODE_ROOT` and `SNAPSHOT_ID` reuses the existing index","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(manifest `snapshot_id` match) rather than rebuilding — except in MODE-OFF,","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":132,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":142,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **MODE-OFF check (FIRST):** In MODE-OFF (`SNAPSHOT_ID` is `\"unknown\"` or","category":"external_commands","line_end":142,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"absent) → **always rebuild**. Do NOT reuse a previous `\"unknown\"` index,","category":"external_commands","line_end":144,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"because the live tree is mutable and `\"unknown\"` is a constant (not a","category":"external_commands","line_end":147,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. If `workspace/kb/structural_index/manifest.json` exists, read its","category":"external_commands","line_end":148,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`snapshot_id` field.","category":"external_commands","line_end":149,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. If `snapshot_id` matches the current `SNAPSHOT_ID` (and `SNAPSHOT_ID` is NOT","category":"external_commands","line_end":149,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"unknown\"`) → **reuse the index immediately and STOP**. Do NOT invoke Step","category":"external_commands","line_end":153,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. If `manifest.json` is absent but `workspace/kb/structural_index.jsonl` exists","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(backward compat), read its provenance header (`_provenance`, `snapshot_id`","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"keys). If `snapshot_id` matches (and is NOT `\"unknown\"`) → **reuse and","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. If `SNAPSHOT_ID` differs → proceed to rebuild (Steps 2–5). For incremental","category":"external_commands","line_end":158,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"reuse: before rebuilding a semantic unit, check `units/` for a","category":"external_commands","line_end":171,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(precision: `semantic`) — if a pre-built index matching the current","category":"external_commands","line_end":172,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`snapshot_id` or `root_fingerprint` is available. Most precise: full","category":"external_commands","line_end":172,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Compiler / typechecker-backed extractor** (precision: `typecheck`) — if","category":"external_commands","line_end":175,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`compile_commands.json`, build context, or typechecker is available.","category":"external_commands","line_end":177,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Language-aware AST extraction** (precision: `ast`) — if `tree-sitter`,","category":"external_commands","line_end":177,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`ast-grep`, or a language-specific parser is available. Full AST parsing:","category":"external_commands","line_end":180,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Symbol-only extraction** (precision: `symbol-only`) — if `ctags` or","category":"external_commands","line_end":180,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"equivalent is on `PATH`. Symbol table only (function definitions, locations —","category":"external_commands","line_end":184,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Heuristic fallback** (precision: `heuristic`) — Python stdlib regex pass","category":"external_commands","line_end":187,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Coverage-only manifest + lexical fallback** (precision: `coverage-only`) —","category":"external_commands","line_end":188,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"grep; no structural index is written. Manifest records `status: \"empty\"`.","category":"external_commands","line_end":194,"severity":"medium","line_start":188},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/kb/structural_index/native/` and subdirectories","category":"external_commands","line_end":195,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`native/{scip,lsif,kythe}/` for prebuilt index files.","category":"external_commands","line_end":199,"severity":"medium","line_start":195},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`provenance.json` manifest located at","category":"external_commands","line_end":200,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/kb/structural_index/native/provenance.json` or","category":"external_commands","line_end":201,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`native/<kind>/provenance.json`. The manifest contains an array of","category":"external_commands","line_end":203,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`[{\"kind\": \"scip|lsif|kythe\", \"path\": \"...\", \"snapshot_id\": \"...\", \"root_fingerprint\": \"...\", \"langu","category":"external_commands","line_end":204,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A native index is matched if its declared `snapshot_id` equals `SNAPSHOT_ID`","category":"external_commands","line_end":204,"severity":"medium","line_start":204},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(when `SNAPSHOT_ID != \"unknown\"`) or its `root_fingerprint` matches the","category":"external_commands","line_end":205,"severity":"medium","line_start":205},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"workspace's calculated root fingerprint. If the `files` array is absent or","category":"external_commands","line_end":208,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"in `manifest.native_indexes` but do not update `coverage` rows; fall through","category":"external_commands","line_end":208,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"their entries in `manifest.native_indexes`, and set the `coverage` table","category":"external_commands","line_end":213,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`backend` (e.g., `\"scip\"` or `\"scip-clangd\"`) for all files listed in the","category":"external_commands","line_end":214,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"provenance manifest. If `catalog.sqlite` is NOT populated with symbols from","category":"external_commands","line_end":217,"severity":"medium","line_start":215},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`coverage.status = \"deferred\"` and `precision = \"deferred\"` (with","category":"external_commands","line_end":217,"severity":"medium","line_start":217},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`indexed_files = 0`). This prevents the query helper from claiming an","category":"external_commands","line_end":219,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"un-ingested partition is \"authoritative empty\" at `semantic` precision,","category":"external_commands","line_end":220,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"ensuring consumers run the mandatory grep fallback. When `catalog.sqlite` IS","category":"external_commands","line_end":221,"severity":"medium","line_start":220},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"populated (e.g., via Option B pre-ingestion or `scip-to-sqlite`), set","category":"external_commands","line_end":222,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`precision = \"semantic\"` and `status = \"indexed\"`.","category":"external_commands","line_end":222,"severity":"medium","line_start":222},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"language server does not automatically qualify as a `semantic` backend.","category":"external_commands","line_end":236,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`build_structural_index.py`, `# MANTIS_HELPER_VERSION = 5`, grep-and-regenerate","category":"external_commands","line_end":236,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Explicit target files and symbols** (from `plan.json`, if available).","category":"external_commands","line_end":250,"severity":"medium","line_start":244},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Apply deterministic `max_units` (default: 10000) or `max_source_bytes` (default:","category":"external_commands","line_end":250,"severity":"medium","line_start":250},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"invocation can resume. Statuses: `complete`, `partial`, `empty`, `failed`.","category":"external_commands","line_end":252,"severity":"medium","line_start":252},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"#### Builder: `build_structural_index.py`","category":"external_commands","line_end":268,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Write the builder to `workspace/helpers/build_structural_index.py`. The FIRST","category":"external_commands","line_end":269,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"LINE MUST be exactly `# MANTIS_HELPER_VERSION = 5`. Before reusing an","category":"external_commands","line_end":270,"severity":"medium","line_start":269},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"existing helper, grep its first lines for `MANTIS_HELPER_VERSION = 5`; if","category":"external_commands","line_end":273,"severity":"medium","line_start":270},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Semantic Units), computes content-addressed cache keys, checks `units/` for","category":"external_commands","line_end":275,"severity":"medium","line_start":273},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and writes results to `catalog.sqlite`.","category":"external_commands","line_end":277,"severity":"medium","line_start":275},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Symbols**: `symbol_id`, `name`, `qualified_name`, `namespace`,","category":"external_commands","line_end":277,"severity":"medium","line_start":277},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`language`, `file_path`, `start_line`, `end_line`, `kind`, `signature`,","category":"external_commands","line_end":278,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`backend`, `precision`.","category":"external_commands","line_end":279,"severity":"medium","line_start":279},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Call edges**: `caller_id`, `callee_id`, `callee_name`, `file_path`,","category":"external_commands","line_end":280,"severity":"medium","line_start":280},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`line`, `edge_kind`.","category":"external_commands","line_end":281,"severity":"medium","line_start":281},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Function boundaries**: `symbol_id`, `file_path`, `start_line`,","category":"external_commands","line_end":282,"severity":"medium","line_start":282},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`end_line`, `signature`, `language`.","category":"external_commands","line_end":283,"severity":"medium","line_start":283},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Coverage**: `file_path`, `indexed`, `backend`, `precision`,","category":"external_commands","line_end":284,"severity":"medium","line_start":284},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`unit_cache_key`, `status`.","category":"external_commands","line_end":285,"severity":"medium","line_start":285},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A step 6). It MUST NOT write anything under `CODE_ROOT` when","category":"external_commands","line_end":289,"severity":"medium","line_start":288},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`snapshot_pinned` is true (Block A step 4). Backends that produce sidecar","category":"external_commands","line_end":290,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"files (ctags `tags`, cscope `cscope.out`, clangd cache) MUST be redirected to","category":"external_commands","line_end":290,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"STATE-RELATIVE paths: `ctags -f <state>/helpers/tags`,","category":"external_commands","line_end":292,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:292:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`cscope -f <state>/helpers/cscope.out`,","category":"external_commands","line_end":293,"severity":"medium","line_start":292},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`CLANGD_INDEX_STORAGE=<state>/helpers/`. Read-only LSP/SCIP queries to a","category":"external_commands","line_end":296,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"#### Query helper: `query_structural_index.py`","category":"external_commands","line_end":298,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Write the query helper to `workspace/helpers/query_structural_index.py`. The","category":"external_commands","line_end":299,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"FIRST LINE MUST be exactly `# MANTIS_HELPER_VERSION = 5`. Before reusing an","category":"external_commands","line_end":300,"severity":"medium","line_start":299},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"existing helper, grep its first lines for `MANTIS_HELPER_VERSION = 5`; if","category":"external_commands","line_end":303,"severity":"medium","line_start":300},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`catalog.sqlite` (or a remote endpoint — identical API). It IS the","category":"external_commands","line_end":305,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. If `catalog.sqlite` is absent but `structural_index.jsonl` exists, the query","category":"external_commands","line_end":305,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`coverage.partition_status = \"empty\"`.","category":"external_commands","line_end":312,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Write the manifest to `workspace/kb/structural_index/tmp/manifest.json`","category":"external_commands","line_end":314,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`workspace/kb/structural_index/manifest.json`. This is the atomic commit","category":"external_commands","line_end":317,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Write a compatibility pointer to `workspace/kb/structural_index.jsonl`","category":"external_commands","line_end":318,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(STATE-RELATIVE — NEVER under `CODE_ROOT`). Below a configurable threshold","category":"external_commands","line_end":321,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`compat_pointer.full_export = false` and `compat_pointer.symbol_count` set.","category":"external_commands","line_end":321,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. The manifest `provider.backend_versions` field records which backend was used","category":"external_commands","line_end":325,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`{\"go\": {\"backend_name\": \"scip-clangd\", \"precision\": \"semantic\"}, \"python\": {\"backend_name\": \"tree-s","category":"external_commands","line_end":327,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Interrupted builds leave unreferenced temp objects in `tmp/` without","category":"external_commands","line_end":328,"severity":"medium","line_start":327},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"corrupting the last published index. On resume, check `manifest.json` status","category":"external_commands","line_end":329,"severity":"medium","line_start":328},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and `snapshot_id` (Step 1).","category":"external_commands","line_end":333,"severity":"medium","line_start":329},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Return the path to `manifest.json`, `catalog.sqlite`, and the query helper.","category":"external_commands","line_end":333,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":364,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":366,"severity":"medium","line_start":364},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Manifest Schema (`manifest.json`)","category":"external_commands","line_end":368,"severity":"medium","line_start":366},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":393,"severity":"medium","line_start":368},{"id":"external_commands:SKILL.md:393:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":395,"severity":"medium","line_start":393},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Atomic commit**: The manifest is written LAST (atomic rename from `tmp/`).","category":"external_commands","line_end":399,"severity":"medium","line_start":395},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### SQLite Catalog Schema (`catalog.sqlite`)","category":"external_commands","line_end":401,"severity":"medium","line_start":399},{"id":"external_commands:SKILL.md:401:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":498,"severity":"medium","line_start":401},{"id":"external_commands:SKILL.md:498:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":501,"severity":"medium","line_start":498},{"id":"external_commands:SKILL.md:501:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"shard SQLite files under `shards/` by `lang:{language}:bucket:{NN}` (stable","category":"external_commands","line_end":501,"severity":"medium","line_start":501},{"id":"external_commands:SKILL.md:507:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":516,"severity":"medium","line_start":507},{"id":"external_commands:SKILL.md:516:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":518,"severity":"medium","line_start":516},{"id":"external_commands:SKILL.md:518:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Critical**: `snapshot_id` is NOT in the cache key. It goes in provenance only.","category":"external_commands","line_end":525,"severity":"medium","line_start":518},{"id":"external_commands:SKILL.md:525:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- SCIP: `scip:{symbol}`","category":"external_commands","line_end":526,"severity":"medium","line_start":525},{"id":"external_commands:SKILL.md:526:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Kythe: `kythe:{uri}`","category":"external_commands","line_end":527,"severity":"medium","line_start":526},{"id":"external_commands:SKILL.md:527:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- clangd: `clangd:{usr}`","category":"external_commands","line_end":531,"severity":"medium","line_start":527},{"id":"external_commands:SKILL.md:531:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":533,"severity":"medium","line_start":531},{"id":"external_commands:SKILL.md:533:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":542,"severity":"medium","line_start":533},{"id":"external_commands:SKILL.md:542:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `direct` — statically resolved call to a known symbol","category":"external_commands","line_end":543,"severity":"medium","line_start":542},{"id":"external_commands:SKILL.md:543:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `indirect` — function pointer, closure, callback","category":"external_commands","line_end":544,"severity":"medium","line_start":543},{"id":"external_commands:SKILL.md:544:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `virtual` — virtual method dispatch (runtime-resolved)","category":"external_commands","line_end":545,"severity":"medium","line_start":544},{"id":"external_commands:SKILL.md:545:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `macro` — call introduced by macro expansion","category":"external_commands","line_end":546,"severity":"medium","line_start":545},{"id":"external_commands:SKILL.md:546:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `unresolved` — callee name found but no symbol_id resolved","category":"external_commands","line_end":565,"severity":"medium","line_start":546},{"id":"external_commands:SKILL.md:565:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`reused = N-1`).","category":"external_commands","line_end":577,"severity":"medium","line_start":565},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`provider.kind = \"baseline+overlay\"` with baseline manifest reference and","category":"external_commands","line_end":582,"severity":"medium","line_start":577},{"id":"external_commands:SKILL.md:582:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The old `structural_index.jsonl` format is retained as a compatibility export","category":"external_commands","line_end":589,"severity":"medium","line_start":582},{"id":"external_commands:SKILL.md:589:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":591,"severity":"medium","line_start":589},{"id":"external_commands:SKILL.md:591:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":593,"severity":"medium","line_start":591},{"id":"external_commands:SKILL.md:593:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Lines 2+ — structural records (one per line, `_type` discriminator):","category":"external_commands","line_end":595,"severity":"medium","line_start":593},{"id":"external_commands:SKILL.md:595:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":599,"severity":"medium","line_start":595},{"id":"external_commands:SKILL.md:599:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":605,"severity":"medium","line_start":599},{"id":"external_commands:SKILL.md:605:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `_provenance` | bool   | Always `true` — marks this as the provenance header line                 ","category":"external_commands","line_end":605,"severity":"medium","line_start":605},{"id":"external_commands:SKILL.md:606:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `snapshot_id` | string | `SNAPSHOT_ID` the index was built against                                ","category":"external_commands","line_end":606,"severity":"medium","line_start":606},{"id":"external_commands:SKILL.md:607:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `tool`        | string | Backend used (e.g. `\"lsp-clangd\"`, `\"tree-sitter\"`, `\"ctags\"`, `\"regex\"`,","category":"external_commands","line_end":607,"severity":"medium","line_start":607},{"id":"external_commands:SKILL.md:611:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `_type`     | Description                                     | Key fields                        ","category":"external_commands","line_end":613,"severity":"medium","line_start":611},{"id":"external_commands:SKILL.md:613:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `function`  | Function definition with boundary and signature | `key`, `start_line`, `end_line`, `","category":"external_commands","line_end":613,"severity":"medium","line_start":613},{"id":"external_commands:SKILL.md:614:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `call_edge` | A call from caller to callee at file:line       | `caller`, `callee`, `file`, `line`","category":"external_commands","line_end":614,"severity":"medium","line_start":614},{"id":"external_commands:SKILL.md:618:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Build from `CODE_ROOT`, not live tree (when pinned).** When the snapshot is","category":"external_commands","line_end":619,"severity":"medium","line_start":618},{"id":"external_commands:SKILL.md:619:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"pinned, the structural index is built from the pinned `CODE_ROOT`, ensuring","category":"external_commands","line_end":621,"severity":"medium","line_start":619},{"id":"external_commands:SKILL.md:621:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Reuse-on-match.** If `manifest.json` already carries the current","category":"external_commands","line_end":622,"severity":"medium","line_start":621},{"id":"external_commands:SKILL.md:622:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`SNAPSHOT_ID` (and `SNAPSHOT_ID` is NOT `\"unknown\"` — in MODE-OFF, always","category":"external_commands","line_end":622,"severity":"medium","line_start":622},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"rebuild), reuse it — do not rebuild. Rebuild when `SNAPSHOT_ID` differs or is","category":"external_commands","line_end":624,"severity":"medium","line_start":623},{"id":"external_commands:SKILL.md:624:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"unknown\"`. Individual units may still be reused from the content-addressed","category":"external_commands","line_end":627,"severity":"medium","line_start":624},{"id":"external_commands:SKILL.md:627:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`tmp/`. Interrupted builds leave unreferenced temp objects without corrupting","category":"external_commands","line_end":628,"severity":"medium","line_start":627},{"id":"external_commands:SKILL.md:628:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the last published index. On resume, check `manifest.json` status and","category":"external_commands","line_end":629,"severity":"medium","line_start":628},{"id":"external_commands:SKILL.md:629:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`snapshot_id`.","category":"external_commands","line_end":630,"severity":"medium","line_start":629},{"id":"external_commands:SKILL.md:630:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **STALE flag in HALT mode.** When `snapshot_pinned` is false (HALT), the","category":"external_commands","line_end":631,"severity":"medium","line_start":630},{"id":"external_commands:SKILL.md:631:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"index may be built from the unpinned `CODE_ROOT` but is marked as potentially","category":"external_commands","line_end":633,"severity":"medium","line_start":631},{"id":"external_commands:SKILL.md:633:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **MODE-OFF: build, do not skip.** When `active_snapshot` is absent","category":"external_commands","line_end":635,"severity":"medium","line_start":633},{"id":"external_commands:SKILL.md:635:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`snapshot_id` set to `\"unknown\"`. This is the standalone-efficiency case —","category":"external_commands","line_end":635,"severity":"medium","line_start":635},{"id":"external_commands:SKILL.md:648:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`query_structural_index.py` (or a compatible remote endpoint). The JSONL file is","category":"external_commands","line_end":653,"severity":"medium","line_start":648},{"id":"external_commands:SKILL.md:653:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `resolve_symbol(name, language?, file?, namespace?)` →","category":"external_commands","line_end":654,"severity":"medium","line_start":653},{"id":"external_commands:SKILL.md:654:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`{results, total, ambiguous, coverage}`","category":"external_commands","line_end":657,"severity":"medium","line_start":654},{"id":"external_commands:SKILL.md:657:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Caller MUST disambiguate before calling `find_callers` / `find_callees`.","category":"external_commands","line_end":657,"severity":"medium","line_start":657},{"id":"external_commands:SKILL.md:659:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `find_callers(symbol_id, limit=100, offset=0)` →","category":"external_commands","line_end":660,"severity":"medium","line_start":659},{"id":"external_commands:SKILL.md:660:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`{results, total, has_more, coverage}`","category":"external_commands","line_end":663,"severity":"medium","line_start":660},{"id":"external_commands:SKILL.md:663:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Each result carries `precision`, `backend`, `edge_kind`.","category":"external_commands","line_end":663,"severity":"medium","line_start":663},{"id":"external_commands:SKILL.md:664:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Empty results carry `coverage.partition_status`.","category":"external_commands","line_end":666,"severity":"medium","line_start":664},{"id":"external_commands:SKILL.md:666:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `find_callees(symbol_id, limit=100, offset=0)` →","category":"external_commands","line_end":667,"severity":"medium","line_start":666},{"id":"external_commands:SKILL.md:667:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`{results, total, has_more, coverage}`","category":"external_commands","line_end":669,"severity":"medium","line_start":667},{"id":"external_commands:SKILL.md:669:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Same shape as `find_callers`.","category":"external_commands","line_end":671,"severity":"medium","line_start":669},{"id":"external_commands:SKILL.md:671:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `get_function_boundary(file, line)` →","category":"external_commands","line_end":672,"severity":"medium","line_start":671},{"id":"external_commands:SKILL.md:672:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`{symbol_id, start_line, end_line, signature, precision, backend}`","category":"external_commands","line_end":674,"severity":"medium","line_start":672},{"id":"external_commands:SKILL.md:674:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. `get_coverage(file?)` →","category":"external_commands","line_end":675,"severity":"medium","line_start":674},{"id":"external_commands:SKILL.md:675:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`{total_files, indexed_files, failed, deferred, partition_status, backends_used}`","category":"external_commands","line_end":685,"severity":"medium","line_start":675},{"id":"external_commands:SKILL.md:685:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`MANTIS_STRUCTURAL_INDEX_URL` env var or manifest `provider.kind = \"remote\"`).","category":"external_commands","line_end":685,"severity":"medium","line_start":685},{"id":"external_commands:SKILL.md:689:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `partition_status` | Meaning                       | Consumer action                              ","category":"external_commands","line_end":691,"severity":"medium","line_start":689},{"id":"external_commands:SKILL.md:691:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `complete`         | All files indexed             | \"No indexed callers\" (still run grep per HINT","category":"external_commands","line_end":692,"severity":"medium","line_start":691},{"id":"external_commands:SKILL.md:692:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `partial`          | Some files deferred or failed | \"Not fully indexed\" — MUST run grep fallback ","category":"external_commands","line_end":693,"severity":"medium","line_start":692},{"id":"external_commands:SKILL.md:693:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `empty`            | No backend available          | \"Not indexed\" — MUST run grep fallback       ","category":"external_commands","line_end":694,"severity":"medium","line_start":693},{"id":"external_commands:SKILL.md:694:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `failed`           | Backend attempted but failed  | \"Index failed\" — MUST run grep fallback      ","category":"external_commands","line_end":699,"severity":"medium","line_start":694},{"id":"external_commands:SKILL.md:699:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When planning investigations, call `resolve_symbol()` then `find_callers()` to","category":"external_commands","line_end":699,"severity":"medium","line_start":699},{"id":"external_commands:SKILL.md:711:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"use the structural index query helper (`resolve_symbol` then `find_callers`)","category":"external_commands","line_end":711,"severity":"medium","line_start":711},{"id":"external_commands:SKILL.md:716:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Wave 2 (Deep Audit):** Use `get_function_boundary(file, line)` to start with","category":"external_commands","line_end":733,"severity":"medium","line_start":716},{"id":"filesystem:SKILL.md:744:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[mantis-pipeline-adapter/references/mantis-structural-index.md](../mantis-pipeline-adapter/reference","category":"filesystem","line_end":744,"severity":"high","line_start":744},{"id":"filesystem:SKILL.md:41:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- `workspace/.mantis_state.json` (to read `active_snapshot` for provenance","category":"filesystem","line_end":41,"severity":"medium","line_start":41},{"id":"filesystem:SKILL.md:103:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"c. Else read state_root/workspace/.mantis_state.json (state_root from","category":"filesystem","line_end":103,"severity":"medium","line_start":103},{"id":"filesystem:SKILL.md:109:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"verify CODE_ROOT/.mantis_snapshot_id exists and equals SNAPSHOT_ID. If missing","category":"filesystem","line_end":109,"severity":"medium","line_start":109},{"id":"filesystem:SKILL.md:127:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"run in the LIVE repository root (which still has .git/.hg/.repo), NOT CODE_ROOT","category":"filesystem","line_end":127,"severity":"medium","line_start":127},{"id":"filesystem:SKILL.md:129:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"lacks .git/.hg/.repo.","category":"filesystem","line_end":129,"severity":"medium","line_start":129},{"id":"filesystem:SKILL.md:64:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"- `workspace/kb/structural_index/tmp/` (STATE-RELATIVE — temporary objects","category":"filesystem","line_end":64,"severity":"medium","line_start":64},{"id":"filesystem:SKILL.md:312:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"1. Write the manifest to `workspace/kb/structural_index/tmp/manifest.json`","category":"filesystem","line_end":312,"severity":"medium","line_start":312},{"id":"filesystem:SKILL.md:124:temp-file-creation","file":"SKILL.md","pattern":"Temp file creation","snippet":"(mktemp -d from CODE_ROOT), never with cwd=CODE_ROOT. Read-only inspection may","category":"filesystem","line_end":124,"severity":"low","line_start":124},{"id":"sensitive:SKILL.md:56:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"- `workspace/kb/structural_index/catalog.sqlite` (STATE-RELATIVE —","category":"sensitive","line_end":56,"severity":"medium","line_start":56},{"id":"sensitive:SKILL.md:215:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"provenance manifest. If `catalog.sqlite` is NOT populated with symbols from","category":"sensitive","line_end":215,"severity":"medium","line_start":215},{"id":"sensitive:SKILL.md:220:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"ensuring consumers run the mandatory grep fallback. When `catalog.sqlite` IS","category":"sensitive","line_end":220,"severity":"medium","line_start":220},{"id":"sensitive:SKILL.md:275:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"and writes results to `catalog.sqlite`.","category":"sensitive","line_end":275,"severity":"medium","line_start":275},{"id":"sensitive:SKILL.md:303:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"`catalog.sqlite` (or a remote endpoint — identical API). It IS the","category":"sensitive","line_end":303,"severity":"medium","line_start":303},{"id":"sensitive:SKILL.md:305:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"3. If `catalog.sqlite` is absent but `structural_index.jsonl` exists, the query","category":"sensitive","line_end":305,"severity":"medium","line_start":305},{"id":"sensitive:SKILL.md:333:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"1. Return the path to `manifest.json`, `catalog.sqlite`, and the query helper.","category":"sensitive","line_end":333,"severity":"medium","line_start":333},{"id":"sensitive:SKILL.md:348:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"├── catalog.sqlite         # Query-optimized serving store (both directions indexed)","category":"sensitive","line_end":348,"severity":"medium","line_start":348},{"id":"sensitive:SKILL.md:352:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"│   └── shard_0000.sqlite","category":"sensitive","line_end":352,"severity":"medium","line_start":352},{"id":"sensitive:SKILL.md:376:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"\"catalog\": \"catalog.sqlite\",","category":"sensitive","line_end":376,"severity":"medium","line_start":376},{"id":"sensitive:SKILL.md:399:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"### SQLite Catalog Schema (`catalog.sqlite`)","category":"sensitive","line_end":399,"severity":"medium","line_start":399},{"id":"blocker:SKILL.md:105:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"-> active_snapshot.root / .snapshot_id / .snapshot_pinned.","category":"blocker","line_end":105,"severity":"low","line_start":105},{"id":"blocker:SKILL.md:108:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. SENTINEL CHECK (only if snapshot_pinned is true AND you did NOT take path 1a):","category":"blocker","line_end":108,"severity":"low","line_start":108},{"id":"blocker:SKILL.md:109:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"verify CODE_ROOT/.mantis_snapshot_id exists and equals SNAPSHOT_ID. If missing","category":"blocker","line_end":109,"severity":"low","line_start":109},{"id":"blocker:SKILL.md:407:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"symbol_id       TEXT PRIMARY KEY,","category":"blocker","line_end":407,"severity":"low","line_start":407},{"id":"blocker:SKILL.md:426:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"edge_id     INTEGER PRIMARY KEY AUTOINCREMENT,","category":"blocker","line_end":426,"severity":"low","line_start":426},{"id":"blocker:SKILL.md:427:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"caller_id   TEXT NOT NULL,","category":"blocker","line_end":427,"severity":"low","line_start":427},{"id":"blocker:SKILL.md:428:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"callee_id   TEXT,","category":"blocker","line_end":428,"severity":"low","line_start":428},{"id":"blocker:SKILL.md:441:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"symbol_id   TEXT PRIMARY KEY,","category":"blocker","line_end":441,"severity":"low","line_start":441},{"id":"blocker:SKILL.md:464:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"unit_id         TEXT NOT NULL,","category":"blocker","line_end":464,"severity":"low","line_start":464},{"id":"blocker:SKILL.md:473:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"snapshot_id     TEXT NOT NULL","category":"blocker","line_end":473,"severity":"low","line_start":473},{"id":"blocker:SKILL.md:477:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"unit_id     TEXT PRIMARY KEY,","category":"blocker","line_end":477,"severity":"low","line_start":477},{"id":"blocker:SKILL.md:546:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- `unresolved` — callee name found but no symbol_id resolved","category":"blocker","line_end":546,"severity":"low","line_start":546},{"id":"blocker:SKILL.md:709:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Wave 1 (Rapid Triage):** Run a repo-wide grep for the function name to build","category":"blocker","line_end":709,"severity":"low","line_start":709}],"finding_verdicts":[{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"Line 14 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"Line 15 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"Line 21 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"Line 22 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"Line 30 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"Line 32 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"Line 34 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Line 36 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"Line 41 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"Line 43 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"Line 45 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"Line 47 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Line 49 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Line 52 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Line 54 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"Line 56 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"Line 58 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"Line 60 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"Line 62 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"Line 64 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"Line 66 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"Line 68 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"Line 70 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"Line 73 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"Line 74 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"Line 75 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"Line 78 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"Line 82 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"Line 83 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"Line 84 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"Line 93 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"Line 132 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"Line 142 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"Line 143 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"Line 144 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"Line 147 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"Line 148 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"Line 149 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"Line 150 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"Line 153 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"Line 154 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"Line 155 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"Line 157 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"Line 158 formats manifest paths, identifiers, or cache names in Markdown. The context is index freshness checking, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"Line 171 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"Line 172 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"Line 174 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"Line 175 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"Line 177 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"Line 178 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"Line 180 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"Line 181 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"Line 184 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"Line 187 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","reason":"Line 188 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"Line 194 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","reason":"Line 195 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"Line 199 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"Line 200 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"Line 201 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"Line 203 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","reason":"Line 204 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","reason":"Line 205 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"Line 206 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"Line 208 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","reason":"Line 213 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"Line 214 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","reason":"Line 215 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","reason":"Line 217 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"Line 218 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"Line 219 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","reason":"Line 220 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"Line 221 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","reason":"Line 222 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"Line 227 formats backend names, provenance, or coverage metadata in Markdown. It does not execute a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"Line 236 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","reason":"Line 244 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","reason":"Line 250 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","reason":"Line 252 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"Line 266 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"Line 268 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","reason":"Line 269 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","reason":"Line 270 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","reason":"Line 273 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","reason":"Line 275 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","reason":"Line 277 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"Line 278 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","reason":"Line 279 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","reason":"Line 280 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","reason":"Line 281 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","reason":"Line 282 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","reason":"Line 283 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","reason":"Line 284 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","reason":"Line 285 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","reason":"Line 288 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"Line 289 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"Line 290 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"Line 291 documents backend output redirection into the state directory. Backticks format examples; this is not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:292:ruby-shell-backtick-execution","reason":"Line 292 documents backend output redirection into the state directory. Backticks format examples; this is not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"Line 293 documents backend output redirection into the state directory. Backticks format examples; this is not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"Line 296 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"Line 298 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","reason":"Line 299 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","reason":"Line 300 formats helper filenames or version markers in Markdown. Helper integrity is assessed separately; the reported backtick-execution pattern is absent.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"Line 303 formats provider configuration in Markdown, not shell substitution. Optional remote-provider trust is assessed separately as a semantic finding.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"Line 305 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"Line 308 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"Line 312 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","reason":"Line 314 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"Line 317 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"Line 318 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"Line 321 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"Line 323 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"Line 325 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","reason":"Line 327 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","reason":"Line 328 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","reason":"Line 329 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"Line 333 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"Line 345 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","reason":"Line 364 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","reason":"Line 366 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","reason":"Line 368 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:393:ruby-shell-backtick-execution","reason":"Line 393 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","reason":"Line 395 formats index artifacts or manifest fields in Markdown. This describes local index publication, not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","reason":"Line 399 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:401:ruby-shell-backtick-execution","reason":"Line 401 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:498:ruby-shell-backtick-execution","reason":"Line 498 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:501:ruby-shell-backtick-execution","reason":"Line 501 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:507:ruby-shell-backtick-execution","reason":"Line 507 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:516:ruby-shell-backtick-execution","reason":"Line 516 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:518:ruby-shell-backtick-execution","reason":"Line 518 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:525:ruby-shell-backtick-execution","reason":"Line 525 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:526:ruby-shell-backtick-execution","reason":"Line 526 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:527:ruby-shell-backtick-execution","reason":"Line 527 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:531:ruby-shell-backtick-execution","reason":"Line 531 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:533:ruby-shell-backtick-execution","reason":"Line 533 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:542:ruby-shell-backtick-execution","reason":"Line 542 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:543:ruby-shell-backtick-execution","reason":"Line 543 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:544:ruby-shell-backtick-execution","reason":"Line 544 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:545:ruby-shell-backtick-execution","reason":"Line 545 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:546:ruby-shell-backtick-execution","reason":"Line 546 uses Markdown formatting for catalog, cache, symbol, or edge specifications. No Ruby or shell command substitution is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:565:ruby-shell-backtick-execution","reason":"Line 565 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","reason":"Line 577 uses inline Markdown to name indexing inputs, paths, or metadata. No executable Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:582:ruby-shell-backtick-execution","reason":"Line 582 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:589:ruby-shell-backtick-execution","reason":"Line 589 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:591:ruby-shell-backtick-execution","reason":"Line 591 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:593:ruby-shell-backtick-execution","reason":"Line 593 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:595:ruby-shell-backtick-execution","reason":"Line 595 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:599:ruby-shell-backtick-execution","reason":"Line 599 is a Markdown code fence, not Ruby or shell command substitution. The enclosed specification does not execute through backticks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:605:ruby-shell-backtick-execution","reason":"Line 605 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:606:ruby-shell-backtick-execution","reason":"Line 606 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:607:ruby-shell-backtick-execution","reason":"Line 607 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:611:ruby-shell-backtick-execution","reason":"Line 611 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:613:ruby-shell-backtick-execution","reason":"Line 613 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:614:ruby-shell-backtick-execution","reason":"Line 614 describes the compatibility export using Markdown formatting. JSON examples and field names are data, not shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:618:ruby-shell-backtick-execution","reason":"Line 618 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:619:ruby-shell-backtick-execution","reason":"Line 619 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:621:ruby-shell-backtick-execution","reason":"Line 621 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:622:ruby-shell-backtick-execution","reason":"Line 622 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","reason":"Line 623 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:624:ruby-shell-backtick-execution","reason":"Line 624 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:627:ruby-shell-backtick-execution","reason":"Line 627 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:628:ruby-shell-backtick-execution","reason":"Line 628 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:629:ruby-shell-backtick-execution","reason":"Line 629 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:630:ruby-shell-backtick-execution","reason":"Line 630 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:631:ruby-shell-backtick-execution","reason":"Line 631 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:633:ruby-shell-backtick-execution","reason":"Line 633 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:635:ruby-shell-backtick-execution","reason":"Line 635 formats snapshot identifiers or index paths in Markdown. The context is provenance and freshness checking, not executable backtick syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:648:ruby-shell-backtick-execution","reason":"Line 648 formats provider configuration in Markdown, not shell substitution. Optional remote-provider trust is assessed separately as a semantic finding.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:653:ruby-shell-backtick-execution","reason":"Line 653 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:654:ruby-shell-backtick-execution","reason":"Line 654 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:657:ruby-shell-backtick-execution","reason":"Line 657 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:659:ruby-shell-backtick-execution","reason":"Line 659 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:660:ruby-shell-backtick-execution","reason":"Line 660 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:663:ruby-shell-backtick-execution","reason":"Line 663 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:664:ruby-shell-backtick-execution","reason":"Line 664 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:666:ruby-shell-backtick-execution","reason":"Line 666 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:667:ruby-shell-backtick-execution","reason":"Line 667 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:669:ruby-shell-backtick-execution","reason":"Line 669 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:671:ruby-shell-backtick-execution","reason":"Line 671 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:672:ruby-shell-backtick-execution","reason":"Line 672 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:674:ruby-shell-backtick-execution","reason":"Line 674 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:675:ruby-shell-backtick-execution","reason":"Line 675 documents query operations or result fields in inline Markdown. It contains no executable Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:685:ruby-shell-backtick-execution","reason":"Line 685 formats provider configuration in Markdown, not shell substitution. Optional remote-provider trust is assessed separately as a semantic finding.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:689:ruby-shell-backtick-execution","reason":"Line 689 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:691:ruby-shell-backtick-execution","reason":"Line 691 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:692:ruby-shell-backtick-execution","reason":"Line 692 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:693:ruby-shell-backtick-execution","reason":"Line 693 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:694:ruby-shell-backtick-execution","reason":"Line 694 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:699:ruby-shell-backtick-execution","reason":"Line 699 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:711:ruby-shell-backtick-execution","reason":"Line 711 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:716:ruby-shell-backtick-execution","reason":"Line 716 formats coverage states or advisory query calls in Markdown. These instructions preserve lexical discovery and contain no shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:744:path-traversal-sequence","reason":"The parent-directory sequence is a fixed Markdown reference link to a sibling blueprint. No attacker-controlled path or filesystem traversal operation appears.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:41:hidden-file-access","reason":"The hidden file is declared workspace state containing snapshot provenance. No credential harvesting or unrelated hidden-file access is specified.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:103:hidden-file-access","reason":"The state-file read resolves the active snapshot within the configured workspace. This is legitimate provenance lookup, not access to hidden secrets.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:109:hidden-file-access","reason":"The hidden sentinel verifies snapshot identity and stops processing on mismatch. This protects provenance rather than harvesting sensitive hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:127:hidden-file-access","reason":"The instruction uses live repository metadata for history, diff, and blame inspection. It does not request credential files or unrelated hidden data.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:129:hidden-file-access","reason":"The line explains that snapshots omit version-control metadata. It is not an instruction to collect secrets from hidden directories.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:64:temp-directory-access","reason":"The temporary directory belongs to the declared state-relative index outputs. It supports local builds rather than unrelated system temporary-file access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:312:temp-directory-access","reason":"The manifest is staged in the index temporary directory before atomic publication. This is scoped index output, not arbitrary temporary-directory access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:124:temp-file-creation","reason":"The private temporary shadow protects pinned source files from build writes. Temporary-directory creation is legitimate; it does not itself isolate executable code.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:56:sqlite-database-file","reason":"Line 56 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:215:sqlite-database-file","reason":"Line 215 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:220:sqlite-database-file","reason":"Line 220 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:275:sqlite-database-file","reason":"Line 275 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:303:sqlite-database-file","reason":"Line 303 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:305:sqlite-database-file","reason":"Line 305 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:333:sqlite-database-file","reason":"Line 333 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:348:sqlite-database-file","reason":"Line 348 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:352:sqlite-database-file","reason":"Line 352 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:376:sqlite-database-file","reason":"Line 376 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:399:sqlite-database-file","reason":"Line 399 references the generated structural-index SQLite catalog or shard. This stores source cross-references, not credentials or an unrelated sensitive database.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:105:system-reconnaissance","reason":"Line 105 describes snapshot provenance or sentinel validation. It does not enumerate the host, users, processes, or privileged system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:108:system-reconnaissance","reason":"Line 108 describes snapshot provenance or sentinel validation. It does not enumerate the host, users, processes, or privileged system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:109:system-reconnaissance","reason":"Line 109 describes snapshot provenance or sentinel validation. It does not enumerate the host, users, processes, or privileged system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:407:system-reconnaissance","reason":"Line 407 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:426:system-reconnaissance","reason":"Line 426 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:427:system-reconnaissance","reason":"Line 427 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:428:system-reconnaissance","reason":"Line 428 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:441:system-reconnaissance","reason":"Line 441 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:464:system-reconnaissance","reason":"Line 464 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:473:system-reconnaissance","reason":"Line 473 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:477:system-reconnaissance","reason":"Line 477 declares an identifier column in the example SQLite schema. SQL identifier names are not system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:546:system-reconnaissance","reason":"The line defines an unresolved call-edge label and symbol identifier. These are source-index metadata, not host reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:709:system-reconnaissance","reason":"Repository-wide grep discovers source call sites for the requested research workflow. It does not inspect unrelated host resources or collect system information.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Helper Reuse Relies on a Forgeable Version Marker","severity":"high","locations":[{"file":"SKILL.md","line_end":271,"line_start":260},{"file":"SKILL.md","line_end":301,"line_start":296}],"confidence":0.86,"description":"Existing executable helpers are reused after checking only the marker '# MANTIS_HELPER_VERSION = 5'. An attacker who can modify workspace helpers can retain that marker and substitute code executed during indexing or queries.","confidence_reasoning":"The instructions explicitly permit helper reuse based on a public version comment without requiring content integrity or trusted ownership. Exploitation requires workspace write access; no actual substituted helper was supplied."},{"title":"Remote Queries Lack an Explicit Data-Disclosure Boundary","severity":"medium","locations":[{"file":"SKILL.md","line_end":304,"line_start":302},{"file":"SKILL.md","line_end":675,"line_start":647},{"file":"SKILL.md","line_end":685,"line_start":677}],"confidence":0.73,"description":"Remote query providers can be selected through MANTIS_STRUCTURAL_INDEX_URL or manifest configuration. Symbol and file queries may disclose repository metadata without required endpoint approval, transport protection, or a data-sharing policy.","confidence_reasoning":"The specification offers remote access to operations accepting symbol names and file paths but states no explicit endpoint or disclosure restrictions. No evidence found of a malicious destination or implemented transfer; this is a conditional design risk."}],"subject_marketplace_commit_sha":"0bd3c12a7023af664e0537d6e6f74414f1b538f3","subject_content_hash":"5a65e55890846a1592a044bd9c117579305030f4c442daf79f3b6a9b3befe9bc","subject_tree_hash":"88d39712415df7ead48c304bb2ac088f1219e94288840141a88d63e65d969788","subject_plugin_path":"skills/google/mantis-structural-index","audit_payload_hash":"4286bf659dea151026dc68ba6f1afde4","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"0bd3c12a7023af664e0537d6e6f74414f1b538f3","contentHash":"5a65e55890846a1592a044bd9c117579305030f4c442daf79f3b6a9b3befe9bc","treeHash":"88d39712415df7ead48c304bb2ac088f1219e94288840141a88d63e65d969788","pluginPath":"skills/google/mantis-structural-index","auditPayloadHash":"4286bf659dea151026dc68ba6f1afde4"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/google-mantis-structural-index/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}