{"data":{"skill":{"slug":"heygen-com-remotion-to-hyperframes","name":"remotion-to-hyperframes","icon":"📦","repo":"https://github.com/heygen-com/hyperframes/tree/main/skills/remotion-to-hyperframes/","status":"approved","author":"heygen-com","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"1e715bb3-0a27-4c73-8371-b91d939e371c","skill_id":"238a1a51-c9aa-4f90-acd3-0ef5e0894038","version":3,"content_hash":"e8bb08ffb2ea3e4d7f490cd9ebca4314","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are false positives from Markdown backticks, fixture code, quoted validation commands, and local harness scripts. No prompt injection, credential harvesting, or hidden exfiltration intent was found. The main residual risk is the opt-in eval harness, which can install npm dependencies and run local render/media tools.","remediation":[{"issue":"Eval harness performs npm install for fixtures.","severity":"medium","suggestion":"Add lockfiles or use npm ci with --ignore-scripts, and document that validation may access the npm registry."},{"issue":"Fixture HTML loads third-party CDN scripts.","severity":"low","suggestion":"Pin resources with SRI or vendor local copies for offline, reproducible validation."},{"issue":"Render and diff helpers invoke ffmpeg, ffprobe, node, and npx.","severity":"low","suggestion":"Keep these scripts opt-in, validate input paths, and document required local toolchain permissions."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"assets/test-corpus/run.sh","line_end":17,"line_start":17},{"file":"assets/test-corpus/run.sh","line_end":45,"line_start":45},{"file":"assets/test-corpus/run.sh","line_end":209,"line_start":209},{"file":"assets/test-corpus/run.sh","line_end":27,"line_start":27},{"file":"assets/test-corpus/run.sh","line_end":28,"line_start":28},{"file":"assets/test-corpus/run.sh","line_end":29,"line_start":29},{"file":"assets/test-corpus/run.sh","line_end":40,"line_start":40},{"file":"assets/test-corpus/run.sh","line_end":103,"line_start":103},{"file":"assets/test-corpus/run.sh","line_end":113,"line_start":113},{"file":"assets/test-corpus/run.sh","line_end":114,"line_start":114},{"file":"assets/test-corpus/run.sh","line_end":154,"line_start":154},{"file":"assets/test-corpus/run.sh","line_end":159,"line_start":159},{"file":"assets/test-corpus/run.sh","line_end":172,"line_start":172},{"file":"assets/test-corpus/run.sh","line_end":45,"line_start":17},{"file":"assets/test-corpus/run.sh","line_end":209,"line_start":45},{"file":"assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx","line_end":31,"line_start":31},{"file":"assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx","line_end":59,"line_start":59},{"file":"assets/test-corpus/tier-2-multi-scene/setup.sh","line_end":12,"line_start":12},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/AnimatedNumber.tsx","line_end":10,"line_start":10},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx","line_end":33,"line_start":33},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx","line_end":39,"line_start":39},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/UnderlinedText.tsx","line_end":40,"line_start":40},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/TitleScene.tsx","line_end":37,"line_start":37},{"file":"assets/test-corpus/tier-4-escape-hatch/cases/01-use-state.tsx","line_end":25,"line_start":25},{"file":"assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx","line_end":32,"line_start":32},{"file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","line_end":14,"line_start":14},{"file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","line_end":15,"line_start":15},{"file":"references/limitations.md","line_end":69,"line_start":67},{"file":"references/limitations.md","line_end":124,"line_start":123},{"file":"references/limitations.md","line_end":125,"line_start":124},{"file":"references/limitations.md","line_end":127,"line_start":125},{"file":"references/limitations.md","line_end":133,"line_start":127},{"file":"scripts/frame_strip.sh","line_end":52,"line_start":52},{"file":"scripts/frame_strip.sh","line_end":105,"line_start":105},{"file":"scripts/frame_strip.sh","line_end":12,"line_start":12},{"file":"scripts/frame_strip.sh","line_end":36,"line_start":36},{"file":"scripts/frame_strip.sh","line_end":50,"line_start":50},{"file":"scripts/lint_source.py","line_end":80,"line_start":80},{"file":"scripts/lint_source.py","line_end":81,"line_start":81},{"file":"scripts/lint_source.py","line_end":103,"line_start":103},{"file":"scripts/lint_source.py","line_end":126,"line_start":126},{"file":"scripts/lint_source.py","line_end":136,"line_start":136},{"file":"scripts/lint_source.py","line_end":222,"line_start":222},{"file":"scripts/lint_source.py","line_end":235,"line_start":235},{"file":"scripts/lint_source.py","line_end":237,"line_start":237},{"file":"scripts/lint_source.py","line_end":260,"line_start":241},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":5,"line_start":5},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":6,"line_start":6},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":19,"line_start":19},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":32,"line_start":32},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":33,"line_start":33},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":36,"line_start":36},{"file":"scripts/tests/fixtures/clean.tsx","line_end":16,"line_start":16},{"file":"scripts/tests/fixtures/clean.tsx","line_end":33,"line_start":33},{"file":"scripts/tests/smoke.sh","line_end":14,"line_start":14},{"file":"scripts/tests/smoke.sh","line_end":15,"line_start":15},{"file":"scripts/tests/smoke.sh","line_end":16,"line_start":16},{"file":"scripts/tests/smoke.sh","line_end":29,"line_start":29},{"file":"scripts/tests/smoke.sh","line_end":30,"line_start":30},{"file":"scripts/tests/smoke.sh","line_end":52,"line_start":52},{"file":"scripts/tests/smoke.sh","line_end":61,"line_start":61},{"file":"scripts/tests/smoke.sh","line_end":68,"line_start":68},{"file":"scripts/tests/smoke.sh","line_end":73,"line_start":73},{"file":"scripts/tests/smoke.sh","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":86,"line_start":77},{"file":"SKILL.md","line_end":88,"line_start":86},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":109,"line_start":107}]},{"factor":"filesystem","evidence":[{"file":"assets/test-corpus/run.sh","line_end":28,"line_start":28},{"file":"assets/test-corpus/run.sh","line_end":29,"line_start":29},{"file":"assets/test-corpus/run.sh","line_end":52,"line_start":52},{"file":"assets/test-corpus/run.sh","line_end":119,"line_start":119},{"file":"assets/test-corpus/run.sh","line_end":122,"line_start":122},{"file":"assets/test-corpus/run.sh","line_end":130,"line_start":130},{"file":"assets/test-corpus/run.sh","line_end":135,"line_start":135},{"file":"assets/test-corpus/run.sh","line_end":143,"line_start":143},{"file":"assets/test-corpus/run.sh","line_end":152,"line_start":152},{"file":"assets/test-corpus/run.sh","line_end":164,"line_start":164},{"file":"assets/test-corpus/run.sh","line_end":175,"line_start":175},{"file":"assets/test-corpus/run.sh","line_end":40,"line_start":40},{"file":"assets/test-corpus/run.sh","line_end":77,"line_start":77},{"file":"assets/test-corpus/tier-1-title-card/README.md","line_end":34,"line_start":34},{"file":"assets/test-corpus/tier-1-title-card/README.md","line_end":37,"line_start":37},{"file":"assets/test-corpus/tier-2-multi-scene/README.md","line_end":43,"line_start":43},{"file":"assets/test-corpus/tier-2-multi-scene/README.md","line_end":46,"line_start":46},{"file":"assets/test-corpus/tier-2-multi-scene/setup.sh","line_end":14,"line_start":14},{"file":"assets/test-corpus/tier-3-data-driven/README.md","line_end":81,"line_start":81},{"file":"assets/test-corpus/tier-3-data-driven/README.md","line_end":84,"line_start":84},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/OutroScene.tsx","line_end":2,"line_start":2},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/StatsScene.tsx","line_end":2,"line_start":2},{"file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","line_end":15,"line_start":15},{"file":"references/api-map.md","line_end":141,"line_start":141},{"file":"references/api-map.md","line_end":142,"line_start":142},{"file":"references/eval.md","line_end":20,"line_start":20},{"file":"references/eval.md","line_end":30,"line_start":30},{"file":"references/eval.md","line_end":34,"line_start":34},{"file":"references/eval.md","line_end":38,"line_start":38},{"file":"scripts/frame_strip.sh","line_end":28,"line_start":28},{"file":"scripts/lint_source.py","line_end":12,"line_start":12},{"file":"scripts/render_diff.sh","line_end":44,"line_start":44},{"file":"scripts/tests/smoke.sh","line_end":27,"line_start":27},{"file":"scripts/tests/smoke.sh","line_end":45,"line_start":45},{"file":"scripts/tests/smoke.sh","line_end":56,"line_start":56},{"file":"scripts/tests/smoke.sh","line_end":61,"line_start":61},{"file":"scripts/tests/smoke.sh","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":85,"line_start":85}]},{"factor":"network","evidence":[{"file":"assets/test-corpus/tier-1-title-card/hf-src/index.html","line_end":6,"line_start":6},{"file":"assets/test-corpus/tier-2-multi-scene/hf-src/index.html","line_end":6,"line_start":6},{"file":"assets/test-corpus/tier-3-data-driven/hf-src/index.html","line_end":6,"line_start":6},{"file":"assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx","line_end":31,"line_start":31},{"file":"assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx","line_end":32,"line_start":32},{"file":"assets/test-corpus/tier-4-escape-hatch/cases/05-lambda-config.tsx","line_end":34,"line_start":34},{"file":"assets/test-corpus/tier-4-escape-hatch/cases/08-mixed.tsx","line_end":25,"line_start":25},{"file":"references/fonts.md","line_end":19,"line_start":19},{"file":"references/fonts.md","line_end":20,"line_start":20},{"file":"references/fonts.md","line_end":22,"line_start":22},{"file":"references/limitations.md","line_end":55,"line_start":55},{"file":"references/lottie.md","line_end":27,"line_start":27},{"file":"references/lottie.md","line_end":60,"line_start":60},{"file":"references/media.md","line_end":111,"line_start":111},{"file":"references/media.md","line_end":115,"line_start":115},{"file":"references/parameters.md","line_end":45,"line_start":45},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":22,"line_start":22},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":32,"line_start":32},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":35,"line_start":35},{"file":"scripts/tests/fixtures/blocker.tsx","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":99,"line_start":99}]},{"factor":"env_access","evidence":[{"file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","line_end":39,"line_start":39},{"file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","line_end":40,"line_start":40},{"file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","line_end":41,"line_start":41}]},{"factor":"scripts","evidence":[{"file":"references/api-map.md","line_end":131,"line_start":131},{"file":"references/limitations.md","line_end":79,"line_start":79}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Eval Harness Installs External Dependencies","locations":[{"file":"assets/test-corpus/run.sh","line_end":130,"line_start":130}],"confidence":0.9,"description":"The corpus runner invokes npm install inside fixture projects before rendering baselines. This is documented and intended, but it can reach the npm registry and run dependency lifecycle scripts unless constrained.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The cited line directly invokes npm install when fixture node_modules is missing. The risk is supply-chain exposure during opt-in validation, not hidden malicious intent."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":64,"total_lines":4619,"audit_model":"codex","audited_at":"2026-07-06T14:42:48.612+00:00","created_at":"2026-07-06T17:32:32.340227+00:00","static_findings":[{"id":"external_commands:assets/test-corpus/run.sh:17:ruby-shell-backtick-execution","file":"assets/test-corpus/run.sh","pattern":"Ruby/shell backtick execution","snippet":"#   - HF CLI built at packages/cli/dist/cli.js (run `bun run --filter @hyperframes/cli build`","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:assets/test-corpus/run.sh:45:ruby-shell-backtick-execution","file":"assets/test-corpus/run.sh","pattern":"Ruby/shell backtick execution","snippet":"# `./run.sh tier-4-escape-hatch` works on a clean checkout.","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:assets/test-corpus/run.sh:209:ruby-shell-backtick-execution","file":"assets/test-corpus/run.sh","pattern":"Ruby/shell backtick execution","snippet":"# Single-tier mode (`./run.sh tier-N`) only writes a result file for the","category":"external_commands","line_end":209,"severity":"medium","line_start":209},{"id":"external_commands:assets/test-corpus/run.sh:27:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"THIS_DIR=\"$(cd \"$(dirname \"${BASH_SOURCE[0]}\")\" && pwd)\"","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:assets/test-corpus/run.sh:28:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"SKILL_DIR=\"$(cd \"$THIS_DIR/../..\" && pwd)\"","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:assets/test-corpus/run.sh:29:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"REPO_ROOT=\"$(cd \"$SKILL_DIR/../..\" && pwd)\"","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:assets/test-corpus/run.sh:40:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"RESULTS_DIR=\"$(mktemp -d)\"","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:assets/test-corpus/run.sh:103:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"fixture_name=$(basename \"$fixture_dir\")","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:assets/test-corpus/run.sh:113:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"threshold=$(read_json_value \"$expected\" \"ssim_threshold\")","category":"external_commands","line_end":113,"severity":"medium","line_start":113},{"id":"external_commands:assets/test-corpus/run.sh:114:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"composition_id=$(read_json_value \"$expected\" \"composition_id\" \"Composition\")","category":"external_commands","line_end":114,"severity":"medium","line_start":114},{"id":"external_commands:assets/test-corpus/run.sh:154:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"mean=$(read_json_value \"$fixture_dir/diff/summary.json\" \"mean\")","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:assets/test-corpus/run.sh:159:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"mean=$(read_json_value \"$fixture_dir/diff/summary.json\" \"mean\")","category":"external_commands","line_end":159,"severity":"medium","line_start":159},{"id":"external_commands:assets/test-corpus/run.sh:172:shell-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Shell command substitution","snippet":"fixture_name=$(basename \"$fixture_dir\")","category":"external_commands","line_end":172,"severity":"medium","line_start":172},{"id":"external_commands:assets/test-corpus/run.sh:17:template-literal-with-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Template literal with command substitution","snippet":"#   - HF CLI built at packages/cli/dist/cli.js (run `bun run --filter @hyperframes/cli build`","category":"external_commands","line_end":45,"severity":"medium","line_start":17},{"id":"external_commands:assets/test-corpus/run.sh:45:template-literal-with-command-substitution","file":"assets/test-corpus/run.sh","pattern":"Template literal with command substitution","snippet":"# `./run.sh tier-4-escape-hatch` works on a clean checkout.","category":"external_commands","line_end":209,"severity":"medium","line_start":45},{"id":"filesystem:assets/test-corpus/run.sh:28:path-traversal-sequence","file":"assets/test-corpus/run.sh","pattern":"Path traversal sequence","snippet":"SKILL_DIR=\"$(cd \"$THIS_DIR/../..\" && pwd)\"","category":"filesystem","line_end":28,"severity":"high","line_start":28},{"id":"filesystem:assets/test-corpus/run.sh:29:path-traversal-sequence","file":"assets/test-corpus/run.sh","pattern":"Path traversal sequence","snippet":"REPO_ROOT=\"$(cd \"$SKILL_DIR/../..\" && pwd)\"","category":"filesystem","line_end":29,"severity":"high","line_start":29},{"id":"filesystem:assets/test-corpus/run.sh:52:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"if ! command -v ffmpeg >/dev/null 2>&1; then","category":"filesystem","line_end":52,"severity":"low","line_start":52},{"id":"filesystem:assets/test-corpus/run.sh:119:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"\"$fixture_dir/setup.sh\" >/dev/null","category":"filesystem","line_end":119,"severity":"low","line_start":119},{"id":"filesystem:assets/test-corpus/run.sh:122:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"if ! python3 \"$LINT\" \"$fixture_dir/remotion-src/src/\" >/dev/null; then","category":"filesystem","line_end":122,"severity":"low","line_start":122},{"id":"filesystem:assets/test-corpus/run.sh:130:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"(cd \"$fixture_dir/remotion-src\" && npm install --silent --no-progress >/dev/null 2>&1)","category":"filesystem","line_end":130,"severity":"low","line_start":130},{"id":"filesystem:assets/test-corpus/run.sh:135:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"npx --no-install remotion render \"$composition_id\" out/baseline.mp4 >/dev/null 2>&1); then","category":"filesystem","line_end":135,"severity":"low","line_start":135},{"id":"filesystem:assets/test-corpus/run.sh:143:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"node \"$HF_CLI\" render hf-src/ --output hf.mp4 --quiet >/dev/null 2>&1); then","category":"filesystem","line_end":143,"severity":"low","line_start":143},{"id":"filesystem:assets/test-corpus/run.sh:152:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"\"$fixture_dir/diff\" >/dev/null; then","category":"filesystem","line_end":152,"severity":"low","line_start":152},{"id":"filesystem:assets/test-corpus/run.sh:164:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"\"$fixture_dir/strip\" 8 >/dev/null","category":"filesystem","line_end":164,"severity":"low","line_start":164},{"id":"filesystem:assets/test-corpus/run.sh:175:standard-device-file-access","file":"assets/test-corpus/run.sh","pattern":"Standard device file access","snippet":"if \"$fixture_dir/validate.sh\" >/dev/null 2>&1; then","category":"filesystem","line_end":175,"severity":"low","line_start":175},{"id":"filesystem:assets/test-corpus/run.sh:40:temp-file-creation","file":"assets/test-corpus/run.sh","pattern":"Temp file creation","snippet":"RESULTS_DIR=\"$(mktemp -d)\"","category":"filesystem","line_end":40,"severity":"low","line_start":40},{"id":"filesystem:assets/test-corpus/run.sh:77:python-file-write-append","file":"assets/test-corpus/run.sh","pattern":"Python file write/append","snippet":"with open(out_path, \"w\") as f:","category":"filesystem","line_end":77,"severity":"medium","line_start":77},{"id":"blocker:assets/test-corpus/run.sh:83:system-reconnaissance","file":"assets/test-corpus/run.sh","pattern":"System reconnaissance","snippet":"# key is missing (used to default composition_id for older fixtures).","category":"blocker","line_end":83,"severity":"low","line_start":83},{"id":"blocker:assets/test-corpus/run.sh:112:system-reconnaissance","file":"assets/test-corpus/run.sh","pattern":"System reconnaissance","snippet":"local threshold composition_id","category":"blocker","line_end":113,"severity":"low","line_start":112},{"id":"blocker:assets/test-corpus/tier-1-title-card/expected.json:5:system-reconnaissance","file":"assets/test-corpus/tier-1-title-card/expected.json","pattern":"System reconnaissance","snippet":"\"description\": \"Solid black background, single 'HELLO' element fades in 0-0.5s, holds 0.5-2.5s, fade","category":"blocker","line_end":5,"severity":"low","line_start":5},{"id":"network:assets/test-corpus/tier-1-title-card/hf-src/index.html:6:hardcoded-url","file":"assets/test-corpus/tier-1-title-card/hf-src/index.html","pattern":"Hardcoded URL","snippet":"<script src=\"https://cdnjs.cloudflare.com/ajax/libs/gsap/3.12.5/gsap.min.js\"></script>","category":"network","line_end":6,"severity":"low","line_start":6},{"id":"filesystem:assets/test-corpus/tier-1-title-card/README.md:34:path-traversal-sequence","file":"assets/test-corpus/tier-1-title-card/README.md","pattern":"Path traversal sequence","snippet":"cd ../hf-src && npx hyperframes render --output ../hf.mp4","category":"filesystem","line_end":34,"severity":"high","line_start":34},{"id":"filesystem:assets/test-corpus/tier-1-title-card/README.md:37:path-traversal-sequence","file":"assets/test-corpus/tier-1-title-card/README.md","pattern":"Path traversal sequence","snippet":"../../../scripts/render_diff.sh ./remotion-src/out/baseline.mp4 ./hf.mp4 ./diff","category":"filesystem","line_end":37,"severity":"high","line_start":37},{"id":"network:assets/test-corpus/tier-2-multi-scene/hf-src/index.html:6:hardcoded-url","file":"assets/test-corpus/tier-2-multi-scene/hf-src/index.html","pattern":"Hardcoded URL","snippet":"<script src=\"https://cdnjs.cloudflare.com/ajax/libs/gsap/3.12.5/gsap.min.js\"></script>","category":"network","line_end":6,"severity":"low","line_start":6},{"id":"filesystem:assets/test-corpus/tier-2-multi-scene/README.md:43:path-traversal-sequence","file":"assets/test-corpus/tier-2-multi-scene/README.md","pattern":"Path traversal sequence","snippet":"cd ../hf-src && npx hyperframes render --output ../hf.mp4","category":"filesystem","line_end":43,"severity":"high","line_start":43},{"id":"filesystem:assets/test-corpus/tier-2-multi-scene/README.md:46:path-traversal-sequence","file":"assets/test-corpus/tier-2-multi-scene/README.md","pattern":"Path traversal sequence","snippet":"../../../scripts/render_diff.sh ./remotion-src/out/baseline.mp4 ./hf.mp4 ./diff","category":"filesystem","line_end":46,"severity":"high","line_start":46},{"id":"external_commands:assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx:31:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx","pattern":"Ruby/shell backtick execution","snippet":"transform: `scale(${scale})`,","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx:59:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx","pattern":"Ruby/shell backtick execution","snippet":"transform: `scale(${scale})`,","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:assets/test-corpus/tier-2-multi-scene/setup.sh:12:shell-command-substitution","file":"assets/test-corpus/tier-2-multi-scene/setup.sh","pattern":"Shell command substitution","snippet":"THIS_DIR=\"$(cd \"$(dirname \"${BASH_SOURCE[0]}\")\" && pwd)\"","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"filesystem:assets/test-corpus/tier-2-multi-scene/setup.sh:14:standard-device-file-access","file":"assets/test-corpus/tier-2-multi-scene/setup.sh","pattern":"Standard device file access","snippet":"if ! command -v ffmpeg >/dev/null 2>&1; then","category":"filesystem","line_end":14,"severity":"low","line_start":14},{"id":"blocker:assets/test-corpus/tier-2-multi-scene/setup.sh:21:system-reconnaissance","file":"assets/test-corpus/tier-2-multi-scene/setup.sh","pattern":"System reconnaissance","snippet":"# 200x200 solid blue PNG, ~200 bytes.","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"network:assets/test-corpus/tier-3-data-driven/hf-src/index.html:6:hardcoded-url","file":"assets/test-corpus/tier-3-data-driven/hf-src/index.html","pattern":"Hardcoded URL","snippet":"<script src=\"https://cdnjs.cloudflare.com/ajax/libs/gsap/3.12.5/gsap.min.js\"></script>","category":"network","line_end":6,"severity":"low","line_start":6},{"id":"blocker:assets/test-corpus/tier-3-data-driven/hf-src/index.html:55:system-reconnaissance","file":"assets/test-corpus/tier-3-data-driven/hf-src/index.html","pattern":"System reconnaissance","snippet":"border: 2px solid var(--card-color);","category":"blocker","line_end":55,"severity":"low","line_start":55},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/README.md:81:path-traversal-sequence","file":"assets/test-corpus/tier-3-data-driven/README.md","pattern":"Path traversal sequence","snippet":"cd ../hf-src && npx hyperframes render --output ../hf.mp4","category":"filesystem","line_end":81,"severity":"high","line_start":81},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/README.md:84:path-traversal-sequence","file":"assets/test-corpus/tier-3-data-driven/README.md","pattern":"Path traversal sequence","snippet":"../../../scripts/render_diff.sh ./remotion-src/out/baseline.mp4 ./hf.mp4 ./diff","category":"filesystem","line_end":84,"severity":"high","line_start":84},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/AnimatedNumber.tsx:10:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/AnimatedNumber.tsx","pattern":"Ruby/shell backtick execution","snippet":"* Counts from `from` to `to` over `durationInFrames` with easeOut.","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx:33:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx","pattern":"Ruby/shell backtick execution","snippet":"border: `2px solid ${color}`,","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx:39:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx","pattern":"Ruby/shell backtick execution","snippet":"transform: `scale(${scale})`,","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"blocker:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx:33:system-reconnaissance","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx","pattern":"System reconnaissance","snippet":"border: `2px solid ${color}`,","category":"blocker","line_end":33,"severity":"low","line_start":33},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/UnderlinedText.tsx:40:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/components/UnderlinedText.tsx","pattern":"Ruby/shell backtick execution","snippet":"transform: `scaleX(${underlineScaleX})`,","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/OutroScene.tsx:2:path-traversal-sequence","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/OutroScene.tsx","pattern":"Path traversal sequence","snippet":"import { UnderlinedText } from \"../components/UnderlinedText\";","category":"filesystem","line_end":2,"severity":"high","line_start":2},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/StatsScene.tsx:2:path-traversal-sequence","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/StatsScene.tsx","pattern":"Path traversal sequence","snippet":"import { StatCard } from \"../components/StatCard\";","category":"filesystem","line_end":2,"severity":"high","line_start":2},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/TitleScene.tsx:37:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/TitleScene.tsx","pattern":"Ruby/shell backtick execution","snippet":"transform: `scale(${titleScale})`,","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/cases/01-use-state.tsx:25:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-4-escape-hatch/cases/01-use-state.tsx","pattern":"Ruby/shell backtick execution","snippet":"<AbsoluteFill style={{ background: `hsl(${hue}, 80%, 50%)` }}>","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx:32:ruby-shell-backtick-execution","file":"assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx","pattern":"Ruby/shell backtick execution","snippet":"`https://api.example.com/duration?text=${encodeURIComponent(props.text)}`,","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx:31:fetch-api-call","file":"assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":31,"severity":"low","line_start":31},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx:32:hardcoded-url","file":"assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx","pattern":"Hardcoded URL","snippet":"`https://api.example.com/duration?text=${encodeURIComponent(props.text)}`,","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/05-lambda-config.tsx:34:hardcoded-url","file":"assets/test-corpus/tier-4-escape-hatch/cases/05-lambda-config.tsx","pattern":"Hardcoded URL","snippet":"serveUrl: \"https://example.com/bundle\",","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/08-mixed.tsx:25:fetch-api-call","file":"assets/test-corpus/tier-4-escape-hatch/cases/08-mixed.tsx","pattern":"Fetch API call","snippet":"fetch(\"/api/items\")","category":"network","line_end":25,"severity":"low","line_start":25},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/validate.sh:14:shell-command-substitution","file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","pattern":"Shell command substitution","snippet":"THIS_DIR=\"$(cd \"$(dirname \"${BASH_SOURCE[0]}\")\" && pwd)\"","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/validate.sh:15:shell-command-substitution","file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","pattern":"Shell command substitution","snippet":"SCRIPTS_DIR=\"$(cd \"$THIS_DIR/../../../scripts\" && pwd)\"","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"filesystem:assets/test-corpus/tier-4-escape-hatch/validate.sh:15:path-traversal-sequence","file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","pattern":"Path traversal sequence","snippet":"SCRIPTS_DIR=\"$(cd \"$THIS_DIR/../../../scripts\" && pwd)\"","category":"filesystem","line_end":15,"severity":"high","line_start":15},{"id":"env_access:assets/test-corpus/tier-4-escape-hatch/validate.sh:39:python-environment-access","file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","pattern":"Python environment access","snippet":"scripts_dir = Path(os.environ[\"SCRIPTS_DIR\"])","category":"env_access","line_end":39,"severity":"low","line_start":39},{"id":"env_access:assets/test-corpus/tier-4-escape-hatch/validate.sh:40:python-environment-access","file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","pattern":"Python environment access","snippet":"this_dir = Path(os.environ[\"THIS_DIR\"])","category":"env_access","line_end":40,"severity":"low","line_start":40},{"id":"env_access:assets/test-corpus/tier-4-escape-hatch/validate.sh:41:python-environment-access","file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","pattern":"Python environment access","snippet":"expected_path = Path(os.environ[\"EXPECTED\"])","category":"env_access","line_end":41,"severity":"low","line_start":41},{"id":"scripts:references/api-map.md:131:dynamic-import-expression","file":"references/api-map.md","pattern":"Dynamic import() expression","snippet":"| `@remotion/lambda` import  | drop the import (warning `r2hf/lambda-import`)         |","category":"scripts","line_end":131,"severity":"medium","line_start":131},{"id":"filesystem:references/api-map.md:141:path-traversal-sequence","file":"references/api-map.md","pattern":"Path traversal sequence","snippet":"The blockers are documented in [`scripts/lint_source.py`](../scripts/lint_source.py)","category":"filesystem","line_end":141,"severity":"high","line_start":141},{"id":"filesystem:references/api-map.md:142:path-traversal-sequence","file":"references/api-map.md","pattern":"Path traversal sequence","snippet":"and tested by [tier-4-escape-hatch](../assets/test-corpus/tier-4-escape-hatch/).","category":"filesystem","line_end":142,"severity":"high","line_start":142},{"id":"blocker:references/api-map.md:18:system-reconnaissance","file":"references/api-map.md","pattern":"System reconnaissance","snippet":"| `<Composition id durationInFrames fps width height>` | root `<div id=\"stage\" data-composition-id d","category":"blocker","line_end":18,"severity":"low","line_start":18},{"id":"filesystem:references/eval.md:20:path-traversal-sequence","file":"references/eval.md","pattern":"Path traversal sequence","snippet":"python3 ../../scripts/lint_source.py ./remotion-src/src/","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:references/eval.md:30:path-traversal-sequence","file":"references/eval.md","pattern":"Path traversal sequence","snippet":"cd .. && node ../../../packages/cli/dist/cli.js render hf-src/ --output hf.mp4","category":"filesystem","line_end":30,"severity":"high","line_start":30},{"id":"filesystem:references/eval.md:34:path-traversal-sequence","file":"references/eval.md","pattern":"Path traversal sequence","snippet":"../../scripts/render_diff.sh ./remotion-src/out/baseline.mp4 ./hf.mp4 ./diff","category":"filesystem","line_end":34,"severity":"high","line_start":34},{"id":"filesystem:references/eval.md:38:path-traversal-sequence","file":"references/eval.md","pattern":"Path traversal sequence","snippet":"../../scripts/frame_strip.sh ./remotion-src/out/baseline.mp4 ./hf.mp4 ./strip 8","category":"filesystem","line_end":38,"severity":"high","line_start":38},{"id":"network:references/fonts.md:19:hardcoded-url","file":"references/fonts.md","pattern":"Hardcoded URL","snippet":"<link rel=\"preconnect\" href=\"https://fonts.googleapis.com\" />","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:references/fonts.md:20:hardcoded-url","file":"references/fonts.md","pattern":"Hardcoded URL","snippet":"<link rel=\"preconnect\" href=\"https://fonts.gstatic.com\" crossorigin />","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:references/fonts.md:22:hardcoded-url","file":"references/fonts.md","pattern":"Hardcoded URL","snippet":"href=\"https://fonts.googleapis.com/css2?family=Inter:wght@400;800&display=swap\"","category":"network","line_end":22,"severity":"low","line_start":22},{"id":"scripts:references/limitations.md:79:dynamic-import-expression","file":"references/limitations.md","pattern":"Dynamic import() expression","snippet":"const HeavyChart = React.lazy(() => import(\"./HeavyChart\"));","category":"scripts","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:references/limitations.md:67:ruby-shell-backtick-execution","file":"references/limitations.md","pattern":"Ruby/shell backtick execution","snippet":"return <div style={{ filter: `blur(${(1 - presentationProgress) * 20}px)` }}>{children}</div>;","category":"external_commands","line_end":69,"severity":"medium","line_start":67},{"id":"external_commands:references/limitations.md:123:ruby-shell-backtick-execution","file":"references/limitations.md","pattern":"Ruby/shell backtick execution","snippet":"- `<Audio volume={(f) => ...}>` (line 15): volume ramp dropped — added","category":"external_commands","line_end":124,"severity":"medium","line_start":123},{"id":"external_commands:references/limitations.md:124:ruby-shell-backtick-execution","file":"references/limitations.md","pattern":"Ruby/shell backtick execution","snippet":"static `data-volume=\"0.5\"`. To preserve the ramp, run","category":"external_commands","line_end":125,"severity":"medium","line_start":124},{"id":"external_commands:references/limitations.md:125:ruby-shell-backtick-execution","file":"references/limitations.md","pattern":"Ruby/shell backtick execution","snippet":"`ffmpeg -i music.wav -af \"afade=t=in:st=0:d=1\" music.faded.wav` and","category":"external_commands","line_end":127,"severity":"medium","line_start":125},{"id":"external_commands:references/limitations.md:127:ruby-shell-backtick-execution","file":"references/limitations.md","pattern":"Ruby/shell backtick execution","snippet":"- `<HeavyChart>` (line 30): translated as inline HTML. The original","category":"external_commands","line_end":133,"severity":"medium","line_start":127},{"id":"network:references/limitations.md:55:hardcoded-url","file":"references/limitations.md","pattern":"Hardcoded URL","snippet":"<Img src=\"https://other-domain.com/x.png\" crossOrigin=\"anonymous\" />","category":"network","line_end":55,"severity":"low","line_start":55},{"id":"network:references/lottie.md:27:hardcoded-url","file":"references/lottie.md","pattern":"Hardcoded URL","snippet":"<script src=\"https://cdnjs.cloudflare.com/ajax/libs/bodymovin/5.12.2/lottie.min.js\"></script>","category":"network","line_end":27,"severity":"low","line_start":27},{"id":"network:references/lottie.md:60:hardcoded-url","file":"references/lottie.md","pattern":"Hardcoded URL","snippet":"<script src=\"https://unpkg.com/@lottiefiles/dotlottie-web\"></script>","category":"network","line_end":60,"severity":"low","line_start":60},{"id":"network:references/media.md:111:hardcoded-url","file":"references/media.md","pattern":"Hardcoded URL","snippet":"<IFrame src=\"https://example.com\" />","category":"network","line_end":111,"severity":"low","line_start":111},{"id":"network:references/media.md:115:hardcoded-url","file":"references/media.md","pattern":"Hardcoded URL","snippet":"<iframe src=\"https://example.com\"></iframe>","category":"network","line_end":115,"severity":"low","line_start":115},{"id":"network:references/parameters.md:45:fetch-api-call","file":"references/parameters.md","pattern":"Fetch API call","snippet":"const res = await fetch(...);","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"blocker:references/parameters.md:148:system-reconnaissance","file":"references/parameters.md","pattern":"System reconnaissance","snippet":"Validate at translation time instead. If the user passes invalid data,","category":"blocker","line_end":148,"severity":"low","line_start":148},{"id":"external_commands:scripts/frame_strip.sh:52:python-subprocess-run","file":"scripts/frame_strip.sh","pattern":"Python subprocess.run","snippet":"probe = subprocess.run(","category":"external_commands","line_end":52,"severity":"high","line_start":52},{"id":"external_commands:scripts/frame_strip.sh:105:python-subprocess-run","file":"scripts/frame_strip.sh","pattern":"Python subprocess.run","snippet":"subprocess.run(cmd, check=True)","category":"external_commands","line_end":105,"severity":"high","line_start":105},{"id":"external_commands:scripts/frame_strip.sh:12:ruby-shell-backtick-execution","file":"scripts/frame_strip.sh","pattern":"Ruby/shell backtick execution","snippet":"#   strip.png         — single PNG with `samples` rows, each row is","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:scripts/frame_strip.sh:36:ruby-shell-backtick-execution","file":"scripts/frame_strip.sh","pattern":"Ruby/shell backtick execution","snippet":"# translated) are sampled at N evenly-spaced timestamps via the `select`","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:scripts/frame_strip.sh:50:ruby-shell-backtick-execution","file":"scripts/frame_strip.sh","pattern":"Ruby/shell backtick execution","snippet":"# indexes for the `select` filter (frame-accurate, doesn't depend on","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"filesystem:scripts/frame_strip.sh:28:standard-device-file-access","file":"scripts/frame_strip.sh","pattern":"Standard device file access","snippet":"if ! command -v ffmpeg >/dev/null 2>&1 || ! command -v ffprobe >/dev/null 2>&1; then","category":"filesystem","line_end":28,"severity":"low","line_start":28},{"id":"blocker:scripts/frame_strip.sh:5:system-reconnaissance","file":"scripts/frame_strip.sh","pattern":"System reconnaissance","snippet":"# range, extract frames from both videos, lay them out as a grid for review.","category":"blocker","line_end":5,"severity":"low","line_start":5},{"id":"external_commands:scripts/lint_source.py:80:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"A matcher is a function `src -> Iterable[(offset, override_message)]`. If","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:scripts/lint_source.py:81:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"`override_message` is None, the rule's default `message` is used; matchers","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:scripts/lint_source.py:103:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"# ends with `, [<non-empty>])`. Empty `[]` is mount-only, allowed.","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:scripts/lint_source.py:126:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"yield m.start(), f\"Custom hook `{name}` defined locally — may need manual rewrite\"","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"external_commands:scripts/lint_source.py:136:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"yield m.start(), f\"Imports `{pkg}` — third-party React UI library has no HF equivalent\"","category":"external_commands","line_end":136,"severity":"medium","line_start":136},{"id":"external_commands:scripts/lint_source.py:222:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"\"Replace `staticFile(\\\"x.png\\\")` with `\\\"x.png\\\"` and copy the asset alongside the HTML\",","category":"external_commands","line_end":222,"severity":"medium","line_start":222},{"id":"external_commands:scripts/lint_source.py:235:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"\"\"\"Given the index of an open `(`, return the index of its matching `)`.","category":"external_commands","line_end":235,"severity":"medium","line_start":235},{"id":"external_commands:scripts/lint_source.py:237:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"Skips parens that appear inside `'...'`, `\"...\"`, or `` `...` `` string","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:scripts/lint_source.py:241:ruby-shell-backtick-execution","file":"scripts/lint_source.py","pattern":"Ruby/shell backtick execution","snippet":"template-literal interpolations `${...}` recursively or comments — both","category":"external_commands","line_end":260,"severity":"medium","line_start":241},{"id":"filesystem:scripts/lint_source.py:12:hidden-file-access","file":"scripts/lint_source.py","pattern":"Hidden file access","snippet":"For each .ts/.tsx file, a list of findings with:","category":"filesystem","line_end":12,"severity":"medium","line_start":12},{"id":"blocker:scripts/lint_source.py:15:system-reconnaissance","file":"scripts/lint_source.py","pattern":"System reconnaissance","snippet":"- rule id","category":"blocker","line_end":16,"severity":"low","line_start":15},{"id":"filesystem:scripts/render_diff.sh:44:standard-device-file-access","file":"scripts/render_diff.sh","pattern":"Standard device file access","snippet":"if ! command -v ffmpeg >/dev/null 2>&1; then","category":"filesystem","line_end":44,"severity":"low","line_start":44},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:5:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Ruby/shell backtick execution","snippet":"// Custom hook in `export const useFoo = ...` form — earlier custom-hook","category":"external_commands","line_end":5,"severity":"medium","line_start":5},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:6:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Ruby/shell backtick execution","snippet":"// regex anchored to `^\\s*(?:function|const|let)` and missed the `export`","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:19:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Ruby/shell backtick execution","snippet":"// coverage for r2hf/use-effect-deps. An earlier regex `[^,]+` would stop at","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:32:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Ruby/shell backtick execution","snippet":"// Expression-bodied useEffect — the form `useEffect(() => fetch(...), [deps])`","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:33:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Ruby/shell backtick execution","snippet":"// has no closing `}`, which an earlier regex anchored on. This and the","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:36:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Ruby/shell backtick execution","snippet":"useLayoutEffect(() => (document.title = `frame ${frame}`), [frame]);","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"network:scripts/tests/fixtures/blocker.tsx:22:fetch-api-call","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Fetch API call","snippet":"fetch(\"/api/data\")","category":"network","line_end":22,"severity":"low","line_start":22},{"id":"network:scripts/tests/fixtures/blocker.tsx:32:fetch-api-call","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Fetch API call","snippet":"// Expression-bodied useEffect — the form `useEffect(() => fetch(...), [deps])`","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:scripts/tests/fixtures/blocker.tsx:35:fetch-api-call","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Fetch API call","snippet":"useEffect(() => fetch(\"/api/heartbeat\"), [frame]);","category":"network","line_end":35,"severity":"low","line_start":35},{"id":"network:scripts/tests/fixtures/blocker.tsx:47:fetch-api-call","file":"scripts/tests/fixtures/blocker.tsx","pattern":"Fetch API call","snippet":"const res = await fetch(\"/api/duration\");","category":"network","line_end":47,"severity":"low","line_start":47},{"id":"external_commands:scripts/tests/fixtures/clean.tsx:16:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/clean.tsx","pattern":"Ruby/shell backtick execution","snippet":"// the earlier regex spanned past `[]` and matched `[frame]` from `pick(...)`,","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:scripts/tests/fixtures/clean.tsx:33:ruby-shell-backtick-execution","file":"scripts/tests/fixtures/clean.tsx","pattern":"Ruby/shell backtick execution","snippet":"<div style={{ fontSize: 72, opacity, transform: `scale(${scale})` }}>Hello</div>","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:scripts/tests/smoke.sh:14:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"THIS_DIR=\"$(cd \"$(dirname \"${BASH_SOURCE[0]}\")\" && pwd)\"","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:scripts/tests/smoke.sh:15:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"SCRIPTS_DIR=\"$(cd \"$THIS_DIR/..\" && pwd)\"","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:scripts/tests/smoke.sh:16:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"WORK=\"$(mktemp -d)\"","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:scripts/tests/smoke.sh:29:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"MEAN=$(python3 -c \"import json,sys; print(json.load(open('$WORK/diff/summary.json'))['mean'])\")","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:scripts/tests/smoke.sh:30:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"PASS=$(python3 -c \"import json,sys; print(json.load(open('$WORK/diff/summary.json'))['pass'])\")","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:scripts/tests/smoke.sh:52:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"DIFF_MEAN=$(python3 -c \"import json; print(json.load(open('$WORK/diff2/summary.json'))['mean'])\")","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:scripts/tests/smoke.sh:61:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"echo \"    strip.png written ($(stat -c%s \"$WORK/strip/strip.png\" 2>/dev/null || stat -f%z \"$WORK/str","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:scripts/tests/smoke.sh:68:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"BLOCKERS=$(python3 -c \"import json; print(json.load(open('$WORK/clean.json'))['blockers'])\")","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:scripts/tests/smoke.sh:73:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"INFOS=$(python3 -c \"import json; print(json.load(open('$WORK/clean.json'))['infos'])\")","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:scripts/tests/smoke.sh:81:shell-command-substitution","file":"scripts/tests/smoke.sh","pattern":"Shell command substitution","snippet":"BLOCKERS=$(python3 -c \"import json; print(json.load(open('$WORK/blocker.json'))['blockers'])\")","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"filesystem:scripts/tests/smoke.sh:27:standard-device-file-access","file":"scripts/tests/smoke.sh","pattern":"Standard device file access","snippet":"\"$WORK/baseline.mp4\" \"$WORK/translated.mp4\" \"$WORK/diff\" >/dev/null","category":"filesystem","line_end":27,"severity":"low","line_start":27},{"id":"filesystem:scripts/tests/smoke.sh:45:standard-device-file-access","file":"scripts/tests/smoke.sh","pattern":"Standard device file access","snippet":"\"$WORK/baseline.mp4\" \"$WORK/different.mp4\" \"$WORK/diff2\" >/dev/null","category":"filesystem","line_end":45,"severity":"low","line_start":45},{"id":"filesystem:scripts/tests/smoke.sh:56:standard-device-file-access","file":"scripts/tests/smoke.sh","pattern":"Standard device file access","snippet":"\"$SCRIPTS_DIR/frame_strip.sh\" \"$WORK/baseline.mp4\" \"$WORK/different.mp4\" \"$WORK/strip\" 4 >/dev/null","category":"filesystem","line_end":56,"severity":"low","line_start":56},{"id":"filesystem:scripts/tests/smoke.sh:61:standard-device-file-access","file":"scripts/tests/smoke.sh","pattern":"Standard device file access","snippet":"echo \"    strip.png written ($(stat -c%s \"$WORK/strip/strip.png\" 2>/dev/null || stat -f%z \"$WORK/str","category":"filesystem","line_end":61,"severity":"low","line_start":61},{"id":"filesystem:scripts/tests/smoke.sh:16:temp-file-creation","file":"scripts/tests/smoke.sh","pattern":"Temp file creation","snippet":"WORK=\"$(mktemp -d)\"","category":"filesystem","line_end":16,"severity":"low","line_start":16},{"id":"blocker:scripts/tests/smoke.sh:58:system-reconnaissance","file":"scripts/tests/smoke.sh","pattern":"System reconnaissance","snippet":"echo \"FAIL: frame_strip.sh did not produce strip.png\"","category":"blocker","line_end":58,"severity":"low","line_start":58},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"description: Translate an existing Remotion (React-based) video composition into a HyperFrames HTML ","category":"external_commands","line_end":3,"severity":"medium","line_start":3},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When in doubt, default to authoring a native HyperFrames composition with the `hyperframes` skill in","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run [`scripts/lint_source.py`](scripts/lint_source.py) over the Remotion source directory. The lint ","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Blockers** (refuse + recommend interop): `useState`, `useReducer`, `useEffect`/`useLayoutEffect`","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Warnings** (translate after dropping the construct): `@remotion/lambda` config, `delayRender`, `","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Info** (translate with note): `staticFile`, `interpolateColors`.","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If any blocker fires, **stop**. Read [`references/escape-hatch.md`](references/escape-hatch.md) and ","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read [`references/api-map.md`](references/api-map.md) — the index of every Remotion API and its HF e","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Composition`, `defaultProps`, `schema`, `calculateMetadata`              | [`parameters.md`](refe","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Sequence`, `Series`, `Loop`, `AbsoluteFill`, `Freeze`                    | [`sequencing.md`](refe","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `useCurrentFrame`, `interpolate`, `spring`, `Easing`, `interpolateColors` | [`timing.md`](referenc","category":"external_commands","line_end":53,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Audio`, `Video`, `Img`, `IFrame`, `staticFile`, `delayRender`            | [`media.md`](reference","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `TransitionSeries`, `@remotion/transitions`                               | [`transitions.md`](ref","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `@remotion/lottie`                                                        | [`lottie.md`](referenc","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `@remotion/google-fonts/<Family>`, `Font.loadFont`, `@font-face`          | [`fonts.md`](reference","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Emit `index.html` with:","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Root `<div id=\"stage\">` carrying the composition's `data-composition-id`, `data-start=\"0\"`, `data-","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- A flat list of scene divs with `data-start` / `data-duration` / `data-track-index`.","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Inline `<style>` for layout; CSS sets the `from` state of every animated property.","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- A single `<script>` tag at the bottom containing one paused `gsap.timeline({paused: true})`. Every","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `window.__timelines[\"<composition-id>\"] = tl;` registers the timeline with HF's runtime.","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Custom React subcomponents inline as repeated HTML using the prop interface as the template (see [`p","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run the eval harness — [`references/eval.md`](references/eval.md) for the full guide. Quick path:","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":86,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":88,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Threshold: ~0.02 below `p05` of the source's complexity tier (see `eval.md`'s validated thresholds t","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Critical**: both renders must use matching pixel format. Set `Config.setVideoImageFormat(\"png\")` +","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Anything that didn't translate cleanly (volume ramps dropped, custom presentations approximated, fon","category":"external_commands","line_end":94,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Translate React state machines.** Compositions that drive animation via `useState` + `useEffect`","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`@remotion/lambda` is _not_ a blocker — Lambda config is deployment, not animation. The skill drops","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":109,"severity":"medium","line_start":107},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Translate Remotion (React-based) video compositions into HyperFrames (HTML + GSAP) compositions. Mos","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:99:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Run Remotion's render pipeline alongside HyperFrames.** That's the runtime interop pattern from ","category":"network","line_end":99,"severity":"low","line_start":99},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"cd ../hf-src && npx hyperframes render --output ../hf.mp4","category":"filesystem","line_end":82,"severity":"high","line_start":82},{"id":"filesystem:SKILL.md:85:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../../scripts/render_diff.sh ./remotion-src/out/baseline.mp4 ./hf.mp4 ./diff","category":"filesystem","line_end":85,"severity":"high","line_start":85}],"finding_verdicts":[{"id":"external_commands:assets/test-corpus/run.sh:17:ruby-shell-backtick-execution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/test-corpus/run.sh:45:ruby-shell-backtick-execution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/test-corpus/run.sh:209:ruby-shell-backtick-execution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/test-corpus/run.sh:27:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:28:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:29:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:40:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:103:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:113:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:114:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:154:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:159:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:172:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/run.sh:17:template-literal-with-command-substitution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/test-corpus/run.sh:45:template-literal-with-command-substitution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:assets/test-corpus/run.sh:28:path-traversal-sequence","reason":"The relative traversal resolves the skill or repository root from the script location with quoted variables. It is bounded local path setup, not user-controlled traversal.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:assets/test-corpus/run.sh:29:path-traversal-sequence","reason":"The relative traversal resolves the skill or repository root from the script location with quoted variables. It is bounded local path setup, not user-controlled traversal.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:assets/test-corpus/run.sh:52:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:119:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:122:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:130:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:135:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:143:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:152:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:164:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:175:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:assets/test-corpus/run.sh:40:temp-file-creation","reason":"mktemp creates an isolated temporary working directory and the script registers cleanup with trap. This is standard safe test harness behavior.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:assets/test-corpus/run.sh:77:python-file-write-append","reason":"The Python write creates a per-fixture JSON result in a temporary results directory. The output path is constructed by the harness, not supplied as shell code.","verdict":"false_positive","confidence":0.9},{"id":"blocker:assets/test-corpus/run.sh:83:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"blocker:assets/test-corpus/run.sh:112:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"blocker:assets/test-corpus/tier-1-title-card/expected.json:5:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"network:assets/test-corpus/tier-1-title-card/hf-src/index.html:6:hardcoded-url","reason":"The hardcoded URL loads a public animation library in a test fixture HTML file. It is a visible render dependency, not hidden data exfiltration.","verdict":"false_positive","confidence":0.78},{"id":"filesystem:assets/test-corpus/tier-1-title-card/README.md:34:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:assets/test-corpus/tier-1-title-card/README.md:37:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"network:assets/test-corpus/tier-2-multi-scene/hf-src/index.html:6:hardcoded-url","reason":"The hardcoded URL loads a public animation library in a test fixture HTML file. It is a visible render dependency, not hidden data exfiltration.","verdict":"false_positive","confidence":0.78},{"id":"filesystem:assets/test-corpus/tier-2-multi-scene/README.md:43:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:assets/test-corpus/tier-2-multi-scene/README.md:46:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx:31:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-2-multi-scene/remotion-src/src/MultiScene.tsx:59:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-2-multi-scene/setup.sh:12:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"filesystem:assets/test-corpus/tier-2-multi-scene/setup.sh:14:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"blocker:assets/test-corpus/tier-2-multi-scene/setup.sh:21:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"network:assets/test-corpus/tier-3-data-driven/hf-src/index.html:6:hardcoded-url","reason":"The hardcoded URL loads a public animation library in a test fixture HTML file. It is a visible render dependency, not hidden data exfiltration.","verdict":"false_positive","confidence":0.78},{"id":"blocker:assets/test-corpus/tier-3-data-driven/hf-src/index.html:55:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/README.md:81:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/README.md:84:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/AnimatedNumber.tsx:10:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx:33:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx:39:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"blocker:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/StatCard.tsx:33:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/components/UnderlinedText.tsx:40:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/OutroScene.tsx:2:path-traversal-sequence","reason":"The ../ sequence is a normal relative import inside a TypeScript fixture. It does not read arbitrary filesystem paths.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/StatsScene.tsx:2:path-traversal-sequence","reason":"The ../ sequence is a normal relative import inside a TypeScript fixture. It does not read arbitrary filesystem paths.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/TitleScene.tsx:37:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/cases/01-use-state.tsx:25:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx:32:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx:31:fetch-api-call","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/03-async-metadata.tsx:32:hardcoded-url","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/05-lambda-config.tsx:34:hardcoded-url","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"network:assets/test-corpus/tier-4-escape-hatch/cases/08-mixed.tsx:25:fetch-api-call","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/validate.sh:14:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:assets/test-corpus/tier-4-escape-hatch/validate.sh:15:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"filesystem:assets/test-corpus/tier-4-escape-hatch/validate.sh:15:path-traversal-sequence","reason":"The relative traversal resolves the skill or repository root from the script location with quoted variables. It is bounded local path setup, not user-controlled traversal.","verdict":"false_positive","confidence":0.9},{"id":"env_access:assets/test-corpus/tier-4-escape-hatch/validate.sh:39:python-environment-access","reason":"The script reads environment variables that it sets immediately before launching Python. They carry local fixture paths, not secrets or external configuration.","verdict":"false_positive","confidence":0.91},{"id":"env_access:assets/test-corpus/tier-4-escape-hatch/validate.sh:40:python-environment-access","reason":"The script reads environment variables that it sets immediately before launching Python. They carry local fixture paths, not secrets or external configuration.","verdict":"false_positive","confidence":0.91},{"id":"env_access:assets/test-corpus/tier-4-escape-hatch/validate.sh:41:python-environment-access","reason":"The script reads environment variables that it sets immediately before launching Python. They carry local fixture paths, not secrets or external configuration.","verdict":"false_positive","confidence":0.91},{"id":"scripts:references/api-map.md:131:dynamic-import-expression","reason":"The dynamic import text appears in documentation that explains unsupported Remotion patterns. It is not executable code in the skill runtime.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:references/api-map.md:141:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/api-map.md:142:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"blocker:references/api-map.md:18:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/eval.md:20:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/eval.md:30:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/eval.md:34:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/eval.md:38:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"network:references/fonts.md:19:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:references/fonts.md:20:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:references/fonts.md:22:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"scripts:references/limitations.md:79:dynamic-import-expression","reason":"The dynamic import text appears in documentation that explains unsupported Remotion patterns. It is not executable code in the skill runtime.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:references/limitations.md:67:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/limitations.md:123:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/limitations.md:124:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/limitations.md:125:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/limitations.md:127:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"network:references/limitations.md:55:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:references/lottie.md:27:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:references/lottie.md:60:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:references/media.md:111:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:references/media.md:115:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:references/parameters.md:45:fetch-api-call","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/parameters.md:148:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/frame_strip.sh:52:python-subprocess-run","reason":"subprocess.run invokes hardcoded ffprobe or ffmpeg with argv lists and no shell interpolation. User video paths are passed as arguments for local visual diff output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:scripts/frame_strip.sh:105:python-subprocess-run","reason":"subprocess.run invokes hardcoded ffprobe or ffmpeg with argv lists and no shell interpolation. User video paths are passed as arguments for local visual diff output.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:scripts/frame_strip.sh:12:ruby-shell-backtick-execution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:scripts/frame_strip.sh:36:ruby-shell-backtick-execution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:scripts/frame_strip.sh:50:ruby-shell-backtick-execution","reason":"The match is in a shell comment or usage note. Comment text cannot execute commands.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:scripts/frame_strip.sh:28:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"blocker:scripts/frame_strip.sh:5:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:80:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:81:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:103:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:126:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:136:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:222:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:235:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:237:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/lint_source.py:241:ruby-shell-backtick-execution","reason":"The backticks are inside docstrings, comments, or user-facing lint messages. They are not Python command execution.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:scripts/lint_source.py:12:hidden-file-access","reason":"The match is from documentation text describing .ts and .tsx files. It is not hidden-file access.","verdict":"false_positive","confidence":0.96},{"id":"blocker:scripts/lint_source.py:15:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:scripts/render_diff.sh:44:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:5:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:6:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:19:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:32:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:33:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/tests/fixtures/blocker.tsx:36:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"network:scripts/tests/fixtures/blocker.tsx:22:fetch-api-call","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"network:scripts/tests/fixtures/blocker.tsx:32:fetch-api-call","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"network:scripts/tests/fixtures/blocker.tsx:35:fetch-api-call","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"network:scripts/tests/fixtures/blocker.tsx:47:fetch-api-call","reason":"This network call is fixture source used to verify lint warnings and blockers. The validation script reads the file as text and does not execute the fetch.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/tests/fixtures/clean.tsx:16:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/tests/fixtures/clean.tsx:33:ruby-shell-backtick-execution","reason":"The flagged backticks are TypeScript template literals used for CSS or fixture comments. They do not invoke a shell or execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:scripts/tests/smoke.sh:14:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:15:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:16:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:29:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:30:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:52:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:61:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:68:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:73:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:scripts/tests/smoke.sh:81:shell-command-substitution","reason":"The command substitution resolves local paths, temporary directories, or parsed fixture metrics with quoted variables. It does not evaluate attacker-controlled shell text.","verdict":"false_positive","confidence":0.89},{"id":"filesystem:scripts/tests/smoke.sh:27:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:scripts/tests/smoke.sh:45:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:scripts/tests/smoke.sh:56:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:scripts/tests/smoke.sh:61:standard-device-file-access","reason":"The device-file pattern is output redirection to /dev/null or a local tool check. It suppresses command noise and does not access sensitive files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:scripts/tests/smoke.sh:16:temp-file-creation","reason":"mktemp creates an isolated temporary working directory and the script registers cleanup with trap. This is standard safe test harness behavior.","verdict":"false_positive","confidence":0.94},{"id":"blocker:scripts/tests/smoke.sh:58:system-reconnaissance","reason":"The scanner matched descriptive words in comments, fixtures, or reference text. There is no system reconnaissance behavior at this location.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The backtick syntax appears in Markdown documentation or fenced command examples. It is not executed by the skill itself.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"network:SKILL.md:99:hardcoded-url","reason":"The URL appears in reference documentation or illustrative translation output. It documents expected media or font handling and is not covert network behavior.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:85:path-traversal-sequence","reason":"The ../ path appears in Markdown instructions for running local validation commands. It is documentation, not unchecked path traversal logic.","verdict":"false_positive","confidence":0.95}],"semantic_findings":[{"title":"Eval Harness Installs External Dependencies","severity":"medium","locations":[{"file":"assets/test-corpus/run.sh","line_end":130,"line_start":130}],"confidence":0.9,"description":"The corpus runner invokes npm install inside fixture projects before rendering baselines. This is documented and intended, but it can reach the npm registry and run dependency lifecycle scripts unless constrained.","confidence_reasoning":"The cited line directly invokes npm install when fixture node_modules is missing. The risk is supply-chain exposure during opt-in validation, not hidden malicious intent."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}