{"data":{"skill":{"slug":"ibrahimhka-configuring-tmux","name":"configuring-tmux","icon":"📦","repo":"https://github.com/ibrahimhka/claude-skill-configuring-tmux/tree/master/","status":"approved","author":"ibrahimhka","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"ae453450-0b61-4cc7-9226-c2107a21adff","skill_id":"722a61e1-63fc-4f86-bcef-d6be7ad86ddf","version":3,"content_hash":"v2:30c73eac2afe762f6aa9c4553158769369d47351:9bf2e516842e3c764f1b54463baf804080af94bb7e0223357a907bc82e4af322:aa3e404bae0a6c5362d1fdc656b2caf866c6553951e293f66bf558b6a74de153:bdf951a521dfe58ca235a0288b3ef3c5","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are false positives from Markdown code fences, tmux syntax, expected dotfile paths, and documented public URLs. The fixed /tmp cache examples and pane-content persistence setting are real local privacy and integrity concerns. No prompt injection or data-exfiltration intent was found.","remediation":[{"issue":"Fixed cache files are placed under /tmp.","severity":"medium","suggestion":"Use a user-owned cache directory such as XDG_CACHE_HOME with private permissions and unique filenames."},{"issue":"tmux-resurrect pane content capture is enabled by default.","severity":"medium","suggestion":"Make pane-content capture opt-in and warn users that saved panes can contain secrets."},{"issue":"Setup commands modify tmux dotfiles and create a symlink.","severity":"low","suggestion":"Ask before changes, back up existing tmux files, and show proposed edits before reload."},{"issue":"The skill installs third-party tmux plugins and frameworks.","severity":"low","suggestion":"Ask for confirmation before cloning, prefer pinned versions, and advise users to review upstream repositories."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"README.md","line_end":15,"line_start":15},{"file":"README.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":138,"line_start":138}]},{"factor":"filesystem","evidence":[{"file":"README.md","line_end":20,"line_start":20},{"file":"README.md","line_end":37,"line_start":37},{"file":"README.md","line_end":38,"line_start":38},{"file":"README.md","line_end":20,"line_start":20},{"file":"README.md","line_end":37,"line_start":37},{"file":"README.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":146,"line_start":146},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":146,"line_start":146},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":147,"line_start":147},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":15,"line_start":15}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":17,"line_start":13},{"file":"SKILL.md","line_end":18,"line_start":17},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":26,"line_start":22},{"file":"SKILL.md","line_end":27,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":31,"line_start":28},{"file":"SKILL.md","line_end":35,"line_start":31},{"file":"SKILL.md","line_end":37,"line_start":35},{"file":"SKILL.md","line_end":46,"line_start":37},{"file":"SKILL.md","line_end":63,"line_start":46},{"file":"SKILL.md","line_end":69,"line_start":63},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":79,"line_start":71},{"file":"SKILL.md","line_end":81,"line_start":79},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":88,"line_start":82},{"file":"SKILL.md","line_end":90,"line_start":88},{"file":"SKILL.md","line_end":97,"line_start":90},{"file":"SKILL.md","line_end":100,"line_start":97},{"file":"SKILL.md","line_end":113,"line_start":100},{"file":"SKILL.md","line_end":116,"line_start":113},{"file":"SKILL.md","line_end":122,"line_start":116},{"file":"SKILL.md","line_end":125,"line_start":122},{"file":"SKILL.md","line_end":132,"line_start":125},{"file":"SKILL.md","line_end":135,"line_start":132},{"file":"SKILL.md","line_end":136,"line_start":135},{"file":"SKILL.md","line_end":139,"line_start":136},{"file":"SKILL.md","line_end":145,"line_start":139},{"file":"SKILL.md","line_end":151,"line_start":145},{"file":"SKILL.md","line_end":159,"line_start":151},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":163,"line_start":161},{"file":"SKILL.md","line_end":163,"line_start":163},{"file":"SKILL.md","line_end":164,"line_start":164},{"file":"SKILL.md","line_end":171,"line_start":168},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":131,"line_start":131},{"file":"SKILL.md","line_end":113,"line_start":100},{"file":"SKILL.md","line_end":132,"line_start":125},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":126,"line_start":126}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Temp directory access","locations":[{"file":"SKILL.md","line_end":102,"line_start":102}],"confidence":0.76,"description":"CACHE=\"/tmp/my-widget-cache\"","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The example uses a fixed cache file under /tmp, which can be read or replaced by other local users on shared systems. Use a user-owned cache directory with private permissions."},{"title":"Temp directory access","locations":[{"file":"SKILL.md","line_end":127,"line_start":127}],"confidence":0.76,"description":"CACHE=\"/tmp/news-cache\"  # one headline per line, refreshed by background fetch","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The example uses a fixed cache file under /tmp, which can be read or replaced by other local users on shared systems. Use a user-owned cache directory with private permissions."},{"title":"Terminal Pane Content Persistence","locations":[{"file":"SKILL.md","line_end":59,"line_start":57}],"confidence":0.84,"description":"The plugin setup enables automatic restore and pane-content capture. This can write terminal output, including tokens or commands, into tmux-resurrect state files.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Line 59 directly enables pane content capture, and lines 57-58 enable automatic restore and periodic saves. This is a clear local privacy risk, although it is not exfiltration."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":227,"audit_model":"codex","audited_at":"2026-07-05T15:01:57.153+00:00","created_at":"2026-07-05T16:56:05.465316+00:00","static_findings":[{"id":"network:README.md:15:hardcoded-url","file":"README.md","pattern":"Hardcoded URL","snippet":"claude skill add https://github.com/ibrahimhka/claude-skill-configuring-tmux","category":"network","line_end":15,"severity":"low","line_start":15},{"id":"network:README.md:20:hardcoded-url","file":"README.md","pattern":"Hardcoded URL","snippet":"git clone https://github.com/ibrahimhka/claude-skill-configuring-tmux ~/.claude/skills/tmux-config","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"filesystem:README.md:20:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"git clone https://github.com/ibrahimhka/claude-skill-configuring-tmux ~/.claude/skills/tmux-config","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:README.md:37:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"set -g status-format[1] \"#[bg=#1a1b26,fg=#c0caf5,align=right]#(~/.config/tmux/scripts/weather.sh)\"","category":"filesystem","line_end":37,"severity":"high","line_start":37},{"id":"filesystem:README.md:38:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"set -g status-format[2] \"#[bg=#16161e,fg=#e0af68,align=right]#(~/.config/tmux/scripts/news-ticker.sh","category":"filesystem","line_end":38,"severity":"high","line_start":38},{"id":"filesystem:README.md:20:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"git clone https://github.com/ibrahimhka/claude-skill-configuring-tmux ~/.claude/skills/tmux-config","category":"filesystem","line_end":20,"severity":"medium","line_start":20},{"id":"filesystem:README.md:37:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"set -g status-format[1] \"#[bg=#1a1b26,fg=#c0caf5,align=right]#(~/.config/tmux/scripts/weather.sh)\"","category":"filesystem","line_end":37,"severity":"medium","line_start":37},{"id":"filesystem:README.md:38:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"set -g status-format[2] \"#[bg=#16161e,fg=#e0af68,align=right]#(~/.config/tmux/scripts/news-ticker.sh","category":"filesystem","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":17,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":18,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Theming via `tmux_conf_theme_*` variables in `~/.tmux.conf.local` — never edit `~/.tmux.conf`","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Gotcha:** its theming layer owns bar 0 and overrides raw `set -g status-right` — use `status-for","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":26,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":27,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Module list controls bar 0 — add custom `#()` calls via `status-right-append`","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Extra bars use `status-format[]` directly","category":"external_commands","line_end":31,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":35,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":37,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Segments live in `~/.config/tmux-powerline/segments/`","category":"external_commands","line_end":46,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":63,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":69,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"tmux 3.2+ supports 2–5 bars. **The correct syntax is `status-format[]` array** — not `status2-right`","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":79,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":81,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"With `status-position top` and `status 3`:","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":88,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":90,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Verify: `tmux show-options -g status` (must equal your total bar count)","category":"external_commands","line_end":97,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Scripts in `#()` must emit **one line**. Multi-line output corrupts the bar.","category":"external_commands","line_end":100,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":113,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":116,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":122,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":125,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":132,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":135,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `-A \"Mozilla/5.0\"` — Yahoo blocks default curl UA:","category":"external_commands","line_end":136,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":139,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":145,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":151,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":159,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `set -g status-right` overridden | Use `tmux_conf_theme_status_right=` (oh-my-tmux) or framework e","category":"external_commands","line_end":159,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `status2-right` → invalid option | Use `set -g status-format[1] \"...\"` |","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| New bars not visible | `tmux show-options -g status` must equal bar count |","category":"external_commands","line_end":163,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Script works in terminal, blank in bar | tmux `#()` has minimal PATH — use `~/` or absolute paths ","category":"external_commands","line_end":163,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `%%` vs `%` confusion | `%%` in `tmux_conf_theme_*`; `%H:%M` directly in `status-format[]` |","category":"external_commands","line_end":164,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":171,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:106:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"age=$(( $(date +%s) - $(stat -c %Y \"$CACHE\") ))","category":"external_commands","line_end":106,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:129:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"count=$(wc -l < \"$CACHE\")","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:130:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"idx=$(( ($(date +%s) / 20) % count ))   # rotates every 20s","category":"external_commands","line_end":130,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:131:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"sed -n \"$((idx + 1))p\" \"$CACHE\"","category":"external_commands","line_end":131,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:100:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":113,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:125:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":132,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:101:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:126:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"cd ~ && git clone https://github.com/gpakosz/.tmux.git","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"network:SKILL.md:32:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"git clone https://github.com/erikw/tmux-powerline.git ~/.config/tmux-powerline","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:SKILL.md:48:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"git clone https://github.com/tmux-plugins/tpm ~/.config/tmux/plugins/tpm","category":"network","line_end":48,"severity":"low","line_start":48},{"id":"network:SKILL.md:138:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"\"https://query1.finance.yahoo.com/v8/finance/chart/BTC-USD?interval=1d&range=1d\"","category":"network","line_end":138,"severity":"low","line_start":138},{"id":"filesystem:SKILL.md:18:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"- Theming via `tmux_conf_theme_*` variables in `~/.tmux.conf.local` — never edit `~/.tmux.conf`","category":"filesystem","line_end":18,"severity":"high","line_start":18},{"id":"filesystem:SKILL.md:32:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"git clone https://github.com/erikw/tmux-powerline.git ~/.config/tmux-powerline","category":"filesystem","line_end":32,"severity":"high","line_start":32},{"id":"filesystem:SKILL.md:33:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"set-option -g status-left \"#(~/.config/tmux-powerline/powerline.sh left)\"","category":"filesystem","line_end":33,"severity":"high","line_start":33},{"id":"filesystem:SKILL.md:34:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"set-option -g status-right \"#(~/.config/tmux-powerline/powerline.sh right)\"","category":"filesystem","line_end":34,"severity":"high","line_start":34},{"id":"filesystem:SKILL.md:37:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"- Segments live in `~/.config/tmux-powerline/segments/`","category":"filesystem","line_end":37,"severity":"high","line_start":37},{"id":"filesystem:SKILL.md:48:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"git clone https://github.com/tmux-plugins/tpm ~/.config/tmux/plugins/tpm","category":"filesystem","line_end":48,"severity":"high","line_start":48},{"id":"filesystem:SKILL.md:61:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"run '~/.config/tmux/plugins/tpm/tpm'","category":"filesystem","line_end":61,"severity":"high","line_start":61},{"id":"filesystem:SKILL.md:75:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"set -g status-format[1] \"#[bg=#1a1b26,fg=#c0caf5,align=right]#(~/.config/tmux/scripts/weather.sh)  #","category":"filesystem","line_end":75,"severity":"high","line_start":75},{"id":"filesystem:SKILL.md:78:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"set -g status-format[2] \"#[bg=#16161e,fg=#e0af68,align=right]  #(~/.config/tmux/scripts/news-ticker.","category":"filesystem","line_end":78,"severity":"high","line_start":78},{"id":"filesystem:SKILL.md:146:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"# ~/.tmux.conf.local","category":"filesystem","line_end":146,"severity":"high","line_start":146},{"id":"filesystem:SKILL.md:169:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"tmux source-file ~/.tmux.conf        # full reload (re-applies framework theming)","category":"filesystem","line_end":169,"severity":"high","line_start":169},{"id":"filesystem:SKILL.md:170:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"tmux source-file ~/.tmux.conf.local  # local overrides only","category":"filesystem","line_end":170,"severity":"high","line_start":170},{"id":"filesystem:SKILL.md:14:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"cd ~ && git clone https://github.com/gpakosz/.tmux.git","category":"filesystem","line_end":14,"severity":"medium","line_start":14},{"id":"filesystem:SKILL.md:15:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"ln -sf .tmux/.tmux.conf .tmux.conf","category":"filesystem","line_end":15,"severity":"medium","line_start":15},{"id":"filesystem:SKILL.md:16:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"cp .tmux/.tmux.conf.local .tmux.conf.local","category":"filesystem","line_end":16,"severity":"medium","line_start":16},{"id":"filesystem:SKILL.md:18:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- Theming via `tmux_conf_theme_*` variables in `~/.tmux.conf.local` — never edit `~/.tmux.conf`","category":"filesystem","line_end":18,"severity":"medium","line_start":18},{"id":"filesystem:SKILL.md:32:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"git clone https://github.com/erikw/tmux-powerline.git ~/.config/tmux-powerline","category":"filesystem","line_end":32,"severity":"medium","line_start":32},{"id":"filesystem:SKILL.md:33:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"set-option -g status-left \"#(~/.config/tmux-powerline/powerline.sh left)\"","category":"filesystem","line_end":33,"severity":"medium","line_start":33},{"id":"filesystem:SKILL.md:34:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"set-option -g status-right \"#(~/.config/tmux-powerline/powerline.sh right)\"","category":"filesystem","line_end":34,"severity":"medium","line_start":34},{"id":"filesystem:SKILL.md:37:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- Segments live in `~/.config/tmux-powerline/segments/`","category":"filesystem","line_end":37,"severity":"medium","line_start":37},{"id":"filesystem:SKILL.md:48:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"git clone https://github.com/tmux-plugins/tpm ~/.config/tmux/plugins/tpm","category":"filesystem","line_end":48,"severity":"medium","line_start":48},{"id":"filesystem:SKILL.md:61:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"run '~/.config/tmux/plugins/tpm/tpm'","category":"filesystem","line_end":61,"severity":"medium","line_start":61},{"id":"filesystem:SKILL.md:75:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"set -g status-format[1] \"#[bg=#1a1b26,fg=#c0caf5,align=right]#(~/.config/tmux/scripts/weather.sh)  #","category":"filesystem","line_end":75,"severity":"medium","line_start":75},{"id":"filesystem:SKILL.md:78:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"set -g status-format[2] \"#[bg=#16161e,fg=#e0af68,align=right]  #(~/.config/tmux/scripts/news-ticker.","category":"filesystem","line_end":78,"severity":"medium","line_start":78},{"id":"filesystem:SKILL.md:146:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"# ~/.tmux.conf.local","category":"filesystem","line_end":146,"severity":"medium","line_start":146},{"id":"filesystem:SKILL.md:169:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"tmux source-file ~/.tmux.conf        # full reload (re-applies framework theming)","category":"filesystem","line_end":169,"severity":"medium","line_start":169},{"id":"filesystem:SKILL.md:170:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"tmux source-file ~/.tmux.conf.local  # local overrides only","category":"filesystem","line_end":170,"severity":"medium","line_start":170},{"id":"filesystem:SKILL.md:147:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"tmux_conf_theme_status_right=\"#{prefix}#{mouse} 🌿 #[fg=#000,bg=#2ea043,bold]#(git -C #{pane_current","category":"filesystem","line_end":147,"severity":"low","line_start":147},{"id":"filesystem:SKILL.md:102:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"CACHE=\"/tmp/my-widget-cache\"","category":"filesystem","line_end":102,"severity":"medium","line_start":102},{"id":"filesystem:SKILL.md:127:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"CACHE=\"/tmp/news-cache\"  # one headline per line, refreshed by background fetch","category":"filesystem","line_end":127,"severity":"medium","line_start":127},{"id":"filesystem:SKILL.md:15:symlink-creation","file":"SKILL.md","pattern":"Symlink creation","snippet":"ln -sf .tmux/.tmux.conf .tmux.conf","category":"filesystem","line_end":15,"severity":"high","line_start":15},{"id":"blocker:SKILL.md:160:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| `status2-right` → invalid option | Use `set -g status-format[1] \"...\"` |","category":"blocker","line_end":160,"severity":"low","line_start":160}],"finding_verdicts":[{"id":"network:README.md:15:hardcoded-url","reason":"This is the documented skill installation URL for the same public repository being audited. It is not runtime exfiltration or an unexpected network destination.","verdict":"false_positive","confidence":0.93},{"id":"network:README.md:20:hardcoded-url","reason":"This is a manual clone command for the same public skill repository. It does not include secrets or transmit local data beyond a normal git clone request.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:README.md:20:hidden-file-in-home-directory","reason":"The hidden path is the documented Claude skill installation directory. This is expected install guidance, not stealthy filesystem access.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:README.md:37:hidden-file-in-home-directory","reason":"The path refers to user-owned tmux script locations in status bar examples. The repository does not contain code that silently creates or modifies those files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:README.md:38:hidden-file-in-home-directory","reason":"The path refers to user-owned tmux script locations in status bar examples. The repository does not contain code that silently creates or modifies those files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:README.md:20:hidden-file-access","reason":"The hidden path is the documented Claude skill installation directory. This is expected install guidance, not stealthy filesystem access.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:README.md:37:hidden-file-access","reason":"The path refers to user-owned tmux script locations in status bar examples. The repository does not contain code that silently creates or modifies those files.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:README.md:38:hidden-file-access","reason":"The path refers to user-owned tmux script locations in status bar examples. The repository does not contain code that silently creates or modifies those files.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The match comes from Markdown fences, inline backticks, or tmux status syntax, not Ruby backtick execution by the skill. Any shell snippets are visible setup examples with fixed commands.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:106:shell-command-substitution","reason":"The command substitutions call fixed utilities such as date, stat, wc, or sed inside widget examples. There is no user-controlled command construction or shell injection path.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:SKILL.md:129:shell-command-substitution","reason":"The command substitutions call fixed utilities such as date, stat, wc, or sed inside widget examples. There is no user-controlled command construction or shell injection path.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:SKILL.md:130:shell-command-substitution","reason":"The command substitutions call fixed utilities such as date, stat, wc, or sed inside widget examples. There is no user-controlled command construction or shell injection path.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:SKILL.md:131:shell-command-substitution","reason":"The command substitutions call fixed utilities such as date, stat, wc, or sed inside widget examples. There is no user-controlled command construction or shell injection path.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:SKILL.md:100:template-literal-with-command-substitution","reason":"The match is a Markdown code block containing Bash and tmux syntax, not a JavaScript template literal being executed. It is documentation for user-reviewed configuration.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:125:template-literal-with-command-substitution","reason":"The match is a Markdown code block containing Bash and tmux syntax, not a JavaScript template literal being executed. It is documentation for user-reviewed configuration.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:101:unix-shell-invocation","reason":"The shebang appears in an example widget script and is not executed when the skill is loaded. It is visible user-authored shell script guidance.","verdict":"false_positive","confidence":0.83},{"id":"external_commands:SKILL.md:126:unix-shell-invocation","reason":"The shebang appears in an example widget script and is not executed when the skill is loaded. It is visible user-authored shell script guidance.","verdict":"false_positive","confidence":0.83},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL points to a public tmux framework or plugin source used only during user-approved setup. No sensitive local data is embedded in the request.","verdict":"false_positive","confidence":0.87},{"id":"network:SKILL.md:32:hardcoded-url","reason":"The URL points to a public tmux framework or plugin source used only during user-approved setup. No sensitive local data is embedded in the request.","verdict":"false_positive","confidence":0.87},{"id":"network:SKILL.md:48:hardcoded-url","reason":"The URL points to a public tmux framework or plugin source used only during user-approved setup. No sensitive local data is embedded in the request.","verdict":"false_positive","confidence":0.87},{"id":"network:SKILL.md:138:hardcoded-url","reason":"The Yahoo Finance URL is an optional public price-data endpoint for a finance widget. The URL contains no local data or credential material.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:18:hidden-file-in-home-directory","reason":"The dotfile paths are part of the documented oh-my-tmux setup after the user chooses that framework. They affect tmux configuration, not unrelated hidden files.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:32:hidden-file-in-home-directory","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:33:hidden-file-in-home-directory","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:34:hidden-file-in-home-directory","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:37:hidden-file-in-home-directory","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:48:hidden-file-in-home-directory","reason":"The hidden path is the standard TPM plugin directory used by tmux. It is documented setup guidance and not unrelated filesystem access.","verdict":"false_positive","confidence":0.87},{"id":"filesystem:SKILL.md:61:hidden-file-in-home-directory","reason":"The hidden path is the standard TPM plugin directory used by tmux. It is documented setup guidance and not unrelated filesystem access.","verdict":"false_positive","confidence":0.87},{"id":"filesystem:SKILL.md:75:hidden-file-in-home-directory","reason":"The status examples reference user-owned tmux widget script paths. They are expected configuration references, not hidden data collection.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:78:hidden-file-in-home-directory","reason":"The status examples reference user-owned tmux widget script paths. They are expected configuration references, not hidden data collection.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:146:hidden-file-in-home-directory","reason":"The match is a tmux configuration file path used for local reload instructions. It is expected for a tmux setup skill and not stealthy access.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:169:hidden-file-in-home-directory","reason":"The match is a tmux configuration file path used for local reload instructions. It is expected for a tmux setup skill and not stealthy access.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:170:hidden-file-in-home-directory","reason":"The match is a tmux configuration file path used for local reload instructions. It is expected for a tmux setup skill and not stealthy access.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:14:hidden-file-access","reason":"The dotfile paths are part of the documented oh-my-tmux setup after the user chooses that framework. They affect tmux configuration, not unrelated hidden files.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:15:hidden-file-access","reason":"The dotfile paths are part of the documented oh-my-tmux setup after the user chooses that framework. They affect tmux configuration, not unrelated hidden files.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:16:hidden-file-access","reason":"The dotfile paths are part of the documented oh-my-tmux setup after the user chooses that framework. They affect tmux configuration, not unrelated hidden files.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:18:hidden-file-access","reason":"The dotfile paths are part of the documented oh-my-tmux setup after the user chooses that framework. They affect tmux configuration, not unrelated hidden files.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:32:hidden-file-access","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:33:hidden-file-access","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:34:hidden-file-access","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:37:hidden-file-access","reason":"The hidden path is the expected user-owned tmux-powerline configuration location. It is directly related to the skill purpose and is not concealed persistence.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:48:hidden-file-access","reason":"The hidden path is the standard TPM plugin directory used by tmux. It is documented setup guidance and not unrelated filesystem access.","verdict":"false_positive","confidence":0.87},{"id":"filesystem:SKILL.md:61:hidden-file-access","reason":"The hidden path is the standard TPM plugin directory used by tmux. It is documented setup guidance and not unrelated filesystem access.","verdict":"false_positive","confidence":0.87},{"id":"filesystem:SKILL.md:75:hidden-file-access","reason":"The status examples reference user-owned tmux widget script paths. They are expected configuration references, not hidden data collection.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:78:hidden-file-access","reason":"The status examples reference user-owned tmux widget script paths. They are expected configuration references, not hidden data collection.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:146:hidden-file-access","reason":"The match is a tmux configuration file path used for local reload instructions. It is expected for a tmux setup skill and not stealthy access.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:169:hidden-file-access","reason":"The match is a tmux configuration file path used for local reload instructions. It is expected for a tmux setup skill and not stealthy access.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:170:hidden-file-access","reason":"The match is a tmux configuration file path used for local reload instructions. It is expected for a tmux setup skill and not stealthy access.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:147:standard-device-file-access","reason":"The /dev/null redirection only suppresses expected git errors in a status bar command. It does not read sensitive files or transmit data.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:102:temp-directory-access","reason":"The example uses a fixed cache file under /tmp, which can be read or replaced by other local users on shared systems. Use a user-owned cache directory with private permissions.","verdict":"confirmed","severity":"medium","confidence":0.76},{"id":"filesystem:SKILL.md:127:temp-directory-access","reason":"The example uses a fixed cache file under /tmp, which can be read or replaced by other local users on shared systems. Use a user-owned cache directory with private permissions.","verdict":"confirmed","severity":"medium","confidence":0.76},{"id":"filesystem:SKILL.md:15:symlink-creation","reason":"The symlink is a standard oh-my-tmux installation step after framework selection. It can affect user config, but it is explicit setup guidance rather than stealthy persistence.","verdict":"false_positive","confidence":0.8},{"id":"blocker:SKILL.md:160:system-reconnaissance","reason":"The line is a troubleshooting table entry about an invalid tmux option. It does not gather host, account, process, or environment information.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Terminal Pane Content Persistence","severity":"medium","locations":[{"file":"SKILL.md","line_end":59,"line_start":57}],"confidence":0.84,"description":"The plugin setup enables automatic restore and pane-content capture. This can write terminal output, including tokens or commands, into tmux-resurrect state files.","confidence_reasoning":"Line 59 directly enables pane content capture, and lines 57-58 enable automatic restore and periodic saves. This is a clear local privacy risk, although it is not exfiltration."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}