{"data":{"skill":{"slug":"internet-court-alkahest-developer","name":"alkahest-developer","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/arkhai/alkahest-developer","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"9ace3c03-6930-4bd6-81d8-05d218710cf7","skill_id":"46294dfc-5ae5-45f6-914b-84357f23c092","version":1,"content_hash":"58db09144144f166628f33db04d85bf2","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static findings are markdown or SDK reference false positives, including code fences, TypeScript template literal types, and blockchain UID fields. The audit confirms repeated inline private-key placeholders in setup examples as a real copy-paste safety risk for wallet code. No prompt injection, data-exfiltration intent, or unauthorized command execution evidence was found.","remediation":[{"issue":"Inline private-key placeholders appear in setup examples.","severity":"high","suggestion":"Replace literal private-key arguments with environment-variable or secret-manager examples, and add a warning against committing wallet keys."},{"issue":"RPC URLs are shown as literal placeholders in client setup.","severity":"low","suggestion":"State that RPC endpoints are user-provided configuration values and should not include committed credentials."}],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"references/python-api.md","line_end":21,"line_start":16},{"file":"references/python-api.md","line_end":192,"line_start":183},{"file":"references/python-api.md","line_end":208,"line_start":202},{"file":"references/python-api.md","line_end":241,"line_start":235}]},{"factor":"network","evidence":[{"file":"references/python-api.md","line_end":13,"line_start":13},{"file":"references/python-api.md","line_end":27,"line_start":27},{"file":"references/python-api.md","line_end":252,"line_start":252},{"file":"references/rust-api.md","line_end":11,"line_start":11},{"file":"references/rust-api.md","line_end":19,"line_start":19},{"file":"references/rust-api.md","line_end":24,"line_start":24},{"file":"references/typescript-api.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":90,"line_start":90}]},{"factor":"env_access","evidence":[{"file":"references/python-api.md","line_end":13,"line_start":13},{"file":"references/python-api.md","line_end":27,"line_start":27},{"file":"references/python-api.md","line_end":266,"line_start":266},{"file":"references/rust-api.md","line_end":10,"line_start":10},{"file":"references/rust-api.md","line_end":18,"line_start":18},{"file":"references/rust-api.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":90,"line_start":90}]},{"factor":"external_commands","evidence":[{"file":"references/typescript-api.md","line_end":44,"line_start":43},{"file":"references/typescript-api.md","line_end":45,"line_start":44},{"file":"references/typescript-api.md","line_end":47,"line_start":45},{"file":"references/typescript-api.md","line_end":47,"line_start":47},{"file":"references/typescript-api.md","line_end":49,"line_start":49},{"file":"references/typescript-api.md","line_end":51,"line_start":50},{"file":"references/typescript-api.md","line_end":51,"line_start":51},{"file":"references/typescript-api.md","line_end":54,"line_start":52},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":52,"line_start":29},{"file":"SKILL.md","line_end":56,"line_start":52},{"file":"SKILL.md","line_end":77,"line_start":56},{"file":"SKILL.md","line_end":81,"line_start":77},{"file":"SKILL.md","line_end":91,"line_start":81},{"file":"SKILL.md","line_end":98,"line_start":91},{"file":"SKILL.md","line_end":109,"line_start":98},{"file":"SKILL.md","line_end":112,"line_start":109},{"file":"SKILL.md","line_end":121,"line_start":112},{"file":"SKILL.md","line_end":124,"line_start":121},{"file":"SKILL.md","line_end":134,"line_start":124},{"file":"SKILL.md","line_end":139,"line_start":134},{"file":"SKILL.md","line_end":145,"line_start":139},{"file":"SKILL.md","line_end":148,"line_start":145},{"file":"SKILL.md","line_end":152,"line_start":148},{"file":"SKILL.md","line_end":155,"line_start":152},{"file":"SKILL.md","line_end":160,"line_start":155},{"file":"SKILL.md","line_end":165,"line_start":160},{"file":"SKILL.md","line_end":170,"line_start":165},{"file":"SKILL.md","line_end":173,"line_start":170},{"file":"SKILL.md","line_end":177,"line_start":173},{"file":"SKILL.md","line_end":180,"line_start":177},{"file":"SKILL.md","line_end":182,"line_start":180},{"file":"SKILL.md","line_end":187,"line_start":182},{"file":"SKILL.md","line_end":192,"line_start":187},{"file":"SKILL.md","line_end":195,"line_start":192},{"file":"SKILL.md","line_end":201,"line_start":195},{"file":"SKILL.md","line_end":204,"line_start":201},{"file":"SKILL.md","line_end":209,"line_start":204},{"file":"SKILL.md","line_end":214,"line_start":209},{"file":"SKILL.md","line_end":230,"line_start":214},{"file":"SKILL.md","line_end":233,"line_start":230},{"file":"SKILL.md","line_end":240,"line_start":233},{"file":"SKILL.md","line_end":243,"line_start":240},{"file":"SKILL.md","line_end":252,"line_start":243},{"file":"SKILL.md","line_end":257,"line_start":252},{"file":"SKILL.md","line_end":268,"line_start":257},{"file":"SKILL.md","line_end":271,"line_start":268},{"file":"SKILL.md","line_end":278,"line_start":271}]}],"critical_findings":[],"high_findings":[{"title":"Generic API/secret keys","locations":[{"file":"references/python-api.md","line_end":13,"line_start":13}],"confidence":0.78,"description":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\")","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"references/python-api.md","line_end":27,"line_start":27}],"confidence":0.78,"description":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\", config)","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"references/rust-api.md","line_end":10,"line_start":10}],"confidence":0.78,"description":"\"0xPRIVATE_KEY\",","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"references/rust-api.md","line_end":18,"line_start":18}],"confidence":0.78,"description":"\"0xPRIVATE_KEY\",","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"references/rust-api.md","line_end":24,"line_start":24}],"confidence":0.78,"description":"let bare = AlkahestClient::new(\"0xPRIVATE_KEY\", \"https://rpc-url\").await?;","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Crypto seed/private key mention","locations":[{"file":"references/typescript-api.md","line_end":12,"line_start":12}],"confidence":0.78,"description":"account: privateKeyToAccount(\"0xKEY\"),","review_kind":"security","source_category":"sensitive","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"SKILL.md","line_end":36,"line_start":36}],"confidence":0.78,"description":"account: privateKeyToAccount(\"0xPRIVATE_KEY\"),","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"SKILL.md","line_end":61,"line_start":61}],"confidence":0.78,"description":"\"0xPRIVATE_KEY\",","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"SKILL.md","line_end":69,"line_start":69}],"confidence":0.78,"description":"\"0xPRIVATE_KEY\",","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"SKILL.md","line_end":75,"line_start":75}],"confidence":0.78,"description":"let bare = AlkahestClient::new(\"0xPRIVATE_KEY\", \"https://rpc-url\").await?;","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"SKILL.md","line_end":85,"line_start":85}],"confidence":0.78,"description":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\")","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Generic API/secret keys","locations":[{"file":"SKILL.md","line_end":90,"line_start":90}],"confidence":0.78,"description":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\", config)","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."},{"title":"Crypto seed/private key mention","locations":[{"file":"SKILL.md","line_end":36,"line_start":36}],"confidence":0.78,"description":"account: privateKeyToAccount(\"0xPRIVATE_KEY\"),","review_kind":"security","source_category":"sensitive","source_severity":"high","confidence_reasoning":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":5,"total_lines":1327,"audit_model":"codex","audited_at":"2026-07-09T23:39:04.617+00:00","created_at":"2026-07-10T07:43:45.875902+00:00","static_findings":[{"id":"scripts:references/python-api.md:16:dynamic-import-expression","file":"references/python-api.md","pattern":"Dynamic import() expression","snippet":"from alkahest_py import (","category":"scripts","line_end":21,"severity":"medium","line_start":16},{"id":"scripts:references/python-api.md:183:dynamic-import-expression","file":"references/python-api.md","pattern":"Dynamic import() expression","snippet":"from alkahest_py import (","category":"scripts","line_end":192,"severity":"medium","line_start":183},{"id":"scripts:references/python-api.md:202:dynamic-import-expression","file":"references/python-api.md","pattern":"Dynamic import() expression","snippet":"from alkahest_py import (","category":"scripts","line_end":208,"severity":"medium","line_start":202},{"id":"scripts:references/python-api.md:235:dynamic-import-expression","file":"references/python-api.md","pattern":"Dynamic import() expression","snippet":"from alkahest_py import (","category":"scripts","line_end":241,"severity":"medium","line_start":235},{"id":"network:references/python-api.md:13:hardcoded-url","file":"references/python-api.md","pattern":"Hardcoded URL","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\")","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:references/python-api.md:27:hardcoded-url","file":"references/python-api.md","pattern":"Hardcoded URL","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\", config)","category":"network","line_end":27,"severity":"low","line_start":27},{"id":"network:references/python-api.md:252:hardcoded-url","file":"references/python-api.md","pattern":"Hardcoded URL","snippet":"client = PyAlkahestClient(\"0xKEY\", \"https://rpc\")","category":"network","line_end":252,"severity":"low","line_start":252},{"id":"env_access:references/python-api.md:13:generic-api-secret-keys","file":"references/python-api.md","pattern":"Generic API/secret keys","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\")","category":"env_access","line_end":13,"severity":"high","line_start":13},{"id":"env_access:references/python-api.md:27:generic-api-secret-keys","file":"references/python-api.md","pattern":"Generic API/secret keys","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\", config)","category":"env_access","line_end":27,"severity":"high","line_start":27},{"id":"env_access:references/python-api.md:266:generic-api-secret-keys","file":"references/python-api.md","pattern":"Generic API/secret keys","snippet":"# Properties: rpc_url, god, alice, bob, alice_private_key, bob_private_key, addresses","category":"env_access","line_end":266,"severity":"high","line_start":266},{"id":"blocker:references/python-api.md:147:system-reconnaissance","file":"references/python-api.md","pattern":"System reconnaissance","snippet":"│   ├── uid","category":"blocker","line_end":148,"severity":"low","line_start":147},{"id":"blocker:references/python-api.md:148:system-reconnaissance","file":"references/python-api.md","pattern":"System reconnaissance","snippet":"│   ├── ref_uid","category":"blocker","line_end":149,"severity":"low","line_start":148},{"id":"blocker:references/python-api.md:216:system-reconnaissance","file":"references/python-api.md","pattern":"System reconnaissance","snippet":"attestation.uid           # str","category":"blocker","line_end":216,"severity":"low","line_start":216},{"id":"blocker:references/python-api.md:221:system-reconnaissance","file":"references/python-api.md","pattern":"System reconnaissance","snippet":"attestation.ref_uid       # str","category":"blocker","line_end":221,"severity":"low","line_start":221},{"id":"blocker:references/python-api.md:239:system-reconnaissance","file":"references/python-api.md","pattern":"System reconnaissance","snippet":"AttestedLog,                 # recipient, attester, uid, schema_uid","category":"blocker","line_end":240,"severity":"low","line_start":239},{"id":"blocker:references/python-api.md:253:system-reconnaissance","file":"references/python-api.md","pattern":"System reconnaissance","snippet":"uid = await client.string_obligation.do_obligation(\"hello\", ref_uid=escrow_uid)","category":"blocker","line_end":253,"severity":"low","line_start":253},{"id":"network:references/rust-api.md:11:hardcoded-url","file":"references/rust-api.md","pattern":"Hardcoded URL","snippet":"\"https://rpc-url\",","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:references/rust-api.md:19:hardcoded-url","file":"references/rust-api.md","pattern":"Hardcoded URL","snippet":"\"https://rpc-url\",","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:references/rust-api.md:24:hardcoded-url","file":"references/rust-api.md","pattern":"Hardcoded URL","snippet":"let bare = AlkahestClient::new(\"0xPRIVATE_KEY\", \"https://rpc-url\").await?;","category":"network","line_end":24,"severity":"low","line_start":24},{"id":"env_access:references/rust-api.md:10:generic-api-secret-keys","file":"references/rust-api.md","pattern":"Generic API/secret keys","snippet":"\"0xPRIVATE_KEY\",","category":"env_access","line_end":10,"severity":"high","line_start":10},{"id":"env_access:references/rust-api.md:18:generic-api-secret-keys","file":"references/rust-api.md","pattern":"Generic API/secret keys","snippet":"\"0xPRIVATE_KEY\",","category":"env_access","line_end":18,"severity":"high","line_start":18},{"id":"env_access:references/rust-api.md:24:generic-api-secret-keys","file":"references/rust-api.md","pattern":"Generic API/secret keys","snippet":"let bare = AlkahestClient::new(\"0xPRIVATE_KEY\", \"https://rpc-url\").await?;","category":"env_access","line_end":24,"severity":"high","line_start":24},{"id":"blocker:references/rust-api.md:201:system-reconnaissance","file":"references/rust-api.md","pattern":"System reconnaissance","snippet":"let uid = attested_event.inner.uid;","category":"blocker","line_end":201,"severity":"low","line_start":201},{"id":"external_commands:references/typescript-api.md:43:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"type Erc20 = { address: `0x${string}`; value: bigint };","category":"external_commands","line_end":44,"severity":"medium","line_start":43},{"id":"external_commands:references/typescript-api.md:44:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"type Erc721 = { address: `0x${string}`; id: bigint };","category":"external_commands","line_end":45,"severity":"medium","line_start":44},{"id":"external_commands:references/typescript-api.md:45:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"type Erc1155 = { address: `0x${string}`; id: bigint; value: bigint };","category":"external_commands","line_end":47,"severity":"medium","line_start":45},{"id":"external_commands:references/typescript-api.md:47:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"type Demand = { arbiter: `0x${string}`; demand: `0x${string}` };","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:references/typescript-api.md:49:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"uid: `0x${string}`; schema: `0x${string}`; time: bigint;","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:references/typescript-api.md:50:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"expirationTime: bigint; revocationTime: bigint; refUID: `0x${string}`;","category":"external_commands","line_end":51,"severity":"medium","line_start":50},{"id":"external_commands:references/typescript-api.md:51:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"recipient: `0x${string}`; attester: `0x${string}`; revocable: boolean;","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:references/typescript-api.md:52:ruby-shell-backtick-execution","file":"references/typescript-api.md","pattern":"Ruby/shell backtick execution","snippet":"data: `0x${string}`;","category":"external_commands","line_end":54,"severity":"medium","line_start":52},{"id":"network:references/typescript-api.md:14:hardcoded-url","file":"references/typescript-api.md","pattern":"Hardcoded URL","snippet":"transport: http(\"https://rpc\"),","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"sensitive:references/typescript-api.md:8:crypto-seed-private-key-mention","file":"references/typescript-api.md","pattern":"Crypto seed/private key mention","snippet":"import { privateKeyToAccount } from \"viem/accounts\";","category":"sensitive","line_end":8,"severity":"high","line_start":8},{"id":"sensitive:references/typescript-api.md:12:crypto-seed-private-key-mention","file":"references/typescript-api.md","pattern":"Crypto seed/private key mention","snippet":"account: privateKeyToAccount(\"0xKEY\"),","category":"sensitive","line_end":12,"severity":"high","line_start":12},{"id":"blocker:references/typescript-api.md:92:system-reconnaissance","file":"references/typescript-api.md","pattern":"System reconnaissance","snippet":"│   │   ├── uid          .encodeDemand({ uid }) / .decodeDemand(bytes)","category":"blocker","line_end":92,"severity":"low","line_start":92},{"id":"blocker:references/typescript-api.md:93:system-reconnaissance","file":"references/typescript-api.md","pattern":"System reconnaissance","snippet":"│   │   ├── refUid       .encodeDemand({ refUID }) / .decodeDemand(bytes)","category":"blocker","line_end":93,"severity":"low","line_start":93},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| TypeScript | TypeScript/JavaScript | `@alkahest/ts-sdk` | viem |","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Rust | Rust | `alkahest-rs` | alloy |","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Python | Python | `alkahest-py` | PyO3 wrapper around Rust SDK |","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":52,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":56,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":77,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":81,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":91,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":98,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":109,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":112,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":121,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":124,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":134,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":139,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":145,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":148,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":152,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":155,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":160,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":165,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":170,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":173,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":177,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":180,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":182,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":187,"severity":"medium","line_start":182},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":192,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":195,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":201,"severity":"medium","line_start":195},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":204,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":209,"severity":"medium","line_start":204},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":214,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":230,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":233,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":240,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":243,"severity":"medium","line_start":240},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":252,"severity":"medium","line_start":243},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":257,"severity":"medium","line_start":252},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":268,"severity":"medium","line_start":257},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":271,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":278,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":281,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":288,"severity":"medium","line_start":281},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":295,"severity":"medium","line_start":288},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":297,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":300,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```rust","category":"external_commands","line_end":302,"severity":"medium","line_start":300},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":308,"severity":"medium","line_start":302},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Addresses | `` `0x${string}` `` | `Address` | `str` (hex) |","category":"external_commands","line_end":308,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Big integers | `bigint` | `U256` | `str` (decimal) |","category":"external_commands","line_end":309,"severity":"medium","line_start":309},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Bytes | `` `0x${string}` `` | `Bytes` / `FixedBytes<32>` | `bytes` / `str` (hex) |","category":"external_commands","line_end":310,"severity":"medium","line_start":310},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Receipts | `{ hash, attested }` | `TransactionReceipt` | `str` (tx hash or uid) |","category":"external_commands","line_end":311,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Attestations | `Attestation` object | `IEAS::Attestation` | `PyAttestation` |","category":"external_commands","line_end":312,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/typescript-api.md` — full TS SDK API tree","category":"external_commands","line_end":317,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/rust-api.md` — full Rust SDK API tree","category":"external_commands","line_end":318,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/python-api.md` — full Python SDK API tree","category":"external_commands","line_end":319,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/contracts.md` — contract addresses and data schemas","category":"external_commands","line_end":320,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `docs/website/Escrow Flow/Token Trading.mdx` — token trading walkthrough","category":"external_commands","line_end":321,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `docs/website/Escrow Flow/Job Trading.mdx` — oracle arbitration walkthrough","category":"external_commands","line_end":322,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `docs/drafts/Escrow Flow (pt 2b - Frontrunning Protection).md` — commit-reveal frontrunning protec","category":"external_commands","line_end":323,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `docs/website/Escrow Flow/Composing Demands.mdx` — composing demands with logical arbiters","category":"external_commands","line_end":324,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `docs/website/Writing Arbiters/` — custom arbiter development","category":"external_commands","line_end":325,"severity":"medium","line_start":324},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `docs/website/Writing Escrow Contracts.md` and `docs/website/Writing Fulfillment Contracts.md` — c","category":"external_commands","line_end":325,"severity":"medium","line_start":325},{"id":"network:SKILL.md:38:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"transport: http(\"https://rpc-url\"),","category":"network","line_end":38,"severity":"low","line_start":38},{"id":"network:SKILL.md:62:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"\"https://rpc-url\",","category":"network","line_end":62,"severity":"low","line_start":62},{"id":"network:SKILL.md:70:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"\"https://rpc-url\",","category":"network","line_end":70,"severity":"low","line_start":70},{"id":"network:SKILL.md:75:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"let bare = AlkahestClient::new(\"0xPRIVATE_KEY\", \"https://rpc-url\").await?;","category":"network","line_end":75,"severity":"low","line_start":75},{"id":"network:SKILL.md:85:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\")","category":"network","line_end":85,"severity":"low","line_start":85},{"id":"network:SKILL.md:90:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\", config)","category":"network","line_end":90,"severity":"low","line_start":90},{"id":"env_access:SKILL.md:36:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"account: privateKeyToAccount(\"0xPRIVATE_KEY\"),","category":"env_access","line_end":36,"severity":"high","line_start":36},{"id":"env_access:SKILL.md:61:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"\"0xPRIVATE_KEY\",","category":"env_access","line_end":61,"severity":"high","line_start":61},{"id":"env_access:SKILL.md:69:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"\"0xPRIVATE_KEY\",","category":"env_access","line_end":69,"severity":"high","line_start":69},{"id":"env_access:SKILL.md:75:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"let bare = AlkahestClient::new(\"0xPRIVATE_KEY\", \"https://rpc-url\").await?;","category":"env_access","line_end":75,"severity":"high","line_start":75},{"id":"env_access:SKILL.md:85:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\")","category":"env_access","line_end":85,"severity":"high","line_start":85},{"id":"env_access:SKILL.md:90:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"client = PyAlkahestClient(\"0xPRIVATE_KEY\", \"https://rpc-url\", config)","category":"env_access","line_end":90,"severity":"high","line_start":90},{"id":"sensitive:SKILL.md:31:crypto-seed-private-key-mention","file":"SKILL.md","pattern":"Crypto seed/private key mention","snippet":"import { privateKeyToAccount } from \"viem/accounts\";","category":"sensitive","line_end":31,"severity":"high","line_start":31},{"id":"sensitive:SKILL.md:36:crypto-seed-private-key-mention","file":"SKILL.md","pattern":"Crypto seed/private key mention","snippet":"account: privateKeyToAccount(\"0xPRIVATE_KEY\"),","category":"sensitive","line_end":36,"severity":"high","line_start":36},{"id":"blocker:SKILL.md:108:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"const escrowUid = attested.uid;","category":"blocker","line_end":108,"severity":"low","line_start":108},{"id":"blocker:SKILL.md:129:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"uid = await client.erc20.escrow.default.create(","category":"blocker","line_end":129,"severity":"low","line_start":129},{"id":"blocker:SKILL.md:156:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"uid = await client.string_obligation.do_obligation(","category":"blocker","line_end":156,"severity":"low","line_start":156},{"id":"blocker:SKILL.md:287:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"uid = await client.commit_reveal.do_obligation(payload, salt, schema, ref_uid=escrow_uid)","category":"blocker","line_end":287,"severity":"low","line_start":287}],"finding_verdicts":[{"id":"scripts:references/python-api.md:16:dynamic-import-expression","reason":"This is a normal Python import statement in an SDK reference, not dynamic import or runtime code loading. No untrusted module path or execution path appears.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/python-api.md:183:dynamic-import-expression","reason":"This is a normal Python import statement in an SDK reference, not dynamic import or runtime code loading. No untrusted module path or execution path appears.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/python-api.md:202:dynamic-import-expression","reason":"This is a normal Python import statement in an SDK reference, not dynamic import or runtime code loading. No untrusted module path or execution path appears.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/python-api.md:235:dynamic-import-expression","reason":"This is a normal Python import statement in an SDK reference, not dynamic import or runtime code loading. No untrusted module path or execution path appears.","verdict":"false_positive","confidence":0.96},{"id":"network:references/python-api.md:13:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:references/python-api.md:27:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:references/python-api.md:252:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"env_access:references/python-api.md:13:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:references/python-api.md:27:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:references/python-api.md:266:generic-api-secret-keys","reason":"This line names local test utility properties, including private key fields. No credential value is present and no access to environment secrets is shown.","verdict":"false_positive","confidence":0.88},{"id":"blocker:references/python-api.md:147:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/python-api.md:148:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/python-api.md:216:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/python-api.md:221:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/python-api.md:239:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/python-api.md:253:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"network:references/rust-api.md:11:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:references/rust-api.md:19:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:references/rust-api.md:24:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"env_access:references/rust-api.md:10:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:references/rust-api.md:18:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:references/rust-api.md:24:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"blocker:references/rust-api.md:201:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/typescript-api.md:43:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/typescript-api.md:44:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/typescript-api.md:45:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/typescript-api.md:47:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/typescript-api.md:49:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/typescript-api.md:50:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/typescript-api.md:51:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/typescript-api.md:52:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"network:references/typescript-api.md:14:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"sensitive:references/typescript-api.md:8:crypto-seed-private-key-mention","reason":"This line imports a wallet helper and does not contain a seed phrase or secret value. The risky inline key usage is represented by the separate placeholder-key finding.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:references/typescript-api.md:12:crypto-seed-private-key-mention","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"blocker:references/typescript-api.md:92:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/typescript-api.md:93:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"The backticks are markdown fences, inline code, or TypeScript template literal types. They do not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:38:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:62:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:70:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:75:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:85:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:90:hardcoded-url","reason":"This is a placeholder RPC endpoint used to configure an Alkahest blockchain client. Network access is expected for this SDK and no exfiltration target is shown.","verdict":"false_positive","confidence":0.91},{"id":"env_access:SKILL.md:36:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:SKILL.md:61:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:SKILL.md:69:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:SKILL.md:75:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:SKILL.md:85:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:SKILL.md:90:generic-api-secret-keys","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"sensitive:SKILL.md:31:crypto-seed-private-key-mention","reason":"This line imports a wallet helper and does not contain a seed phrase or secret value. The risky inline key usage is represented by the separate placeholder-key finding.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:SKILL.md:36:crypto-seed-private-key-mention","reason":"The example passes private-key material as an inline string during wallet or client setup. The value is a placeholder, not a leaked key, but the copy-paste pattern is unsafe for blockchain wallet code.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"blocker:SKILL.md:108:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:129:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:156:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:287:system-reconnaissance","reason":"The uid or ref_uid text is an Ethereum Attestation Service identifier in API documentation. It is not host user-id discovery or system reconnaissance.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":11,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}