{"data":{"skill":{"slug":"internet-court-lifi-stablecoin-swap","name":"lifi-stablecoin-swap","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/lifi/lifi-stablecoin-swap","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"dae19503-4f44-4047-9400-d88fd381d185","skill_id":"cdbcec48-cad1-40a4-83cc-3d571f986b08","version":2,"content_hash":"v3:3f6e026a3363e0954ede7bef0cfe88d4475de137:25d340c22329fddc39da2578ba0bd5d58929a3e8340c5c16b13e3a0d4b606bdb:59596a6f998fbcd62bb0834487cf4fdc445da8247713384124cd0383495921f2:736b696c6c732f696e7465726e65742d636f7572742f6c6966692d737461626c65636f696e2d73776170:d94764746c9a35a9f49ece9efd95af9d","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most command, filesystem, and reconnaissance detections are false positives caused by Markdown and TypeScript syntax. The quickstart exposes an integrator credential and performs wallet writes without validating the connected chain. It also hides transaction costs and uses unpinned package installation commands.","remediation":[{"issue":"The quickstart exposes the integrator credential through a NEXT_PUBLIC variable.","severity":"high","suggestion":"Keep the credential in a server-only environment variable, proxy authenticated quote requests, and rotate any credential previously exposed to browsers."},{"issue":"Wallet approval and escrow writes do not verify the connected chain.","severity":"high","suggestion":"Require the wallet chain to match the source token chain, switch explicitly when needed, and verify contract addresses before every signature."},{"issue":"The interface guidance suppresses gas, fee, and solver information.","severity":"high","suggestion":"Show source-chain gas, approval requirements, quote expiry, settlement states, and refund conditions before the user signs a transaction."},{"issue":"The quickstart resolves the latest scaffold and unpinned dependency versions.","severity":"medium","suggestion":"Pin reviewed package versions, commit a lockfile, and document an update process that includes dependency and contract review."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/quickstart.md","line_end":133,"line_start":125},{"file":"references/quickstart.md","line_end":149,"line_start":133},{"file":"references/quickstart.md","line_end":170,"line_start":149},{"file":"references/quickstart.md","line_end":170,"line_start":170},{"file":"references/quickstart.md","line_end":189,"line_start":185},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":53,"line_start":48},{"file":"SKILL.md","line_end":55,"line_start":53},{"file":"SKILL.md","line_end":57,"line_start":55},{"file":"SKILL.md","line_end":63,"line_start":57},{"file":"SKILL.md","line_end":65,"line_start":63},{"file":"SKILL.md","line_end":67,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":98,"line_start":81},{"file":"SKILL.md","line_end":104,"line_start":98},{"file":"SKILL.md","line_end":105,"line_start":104},{"file":"SKILL.md","line_end":106,"line_start":105},{"file":"SKILL.md","line_end":108,"line_start":106},{"file":"SKILL.md","line_end":117,"line_start":108},{"file":"SKILL.md","line_end":126,"line_start":117},{"file":"SKILL.md","line_end":141,"line_start":126},{"file":"SKILL.md","line_end":142,"line_start":141},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":153,"line_start":147},{"file":"SKILL.md","line_end":155,"line_start":153},{"file":"SKILL.md","line_end":157,"line_start":155},{"file":"SKILL.md","line_end":160,"line_start":157},{"file":"SKILL.md","line_end":164,"line_start":160},{"file":"SKILL.md","line_end":165,"line_start":164},{"file":"SKILL.md","line_end":166,"line_start":165},{"file":"SKILL.md","line_end":167,"line_start":166},{"file":"SKILL.md","line_end":179,"line_start":167},{"file":"SKILL.md","line_end":181,"line_start":179},{"file":"SKILL.md","line_end":183,"line_start":181},{"file":"SKILL.md","line_end":187,"line_start":183},{"file":"SKILL.md","line_end":187,"line_start":187},{"file":"SKILL.md","line_end":194,"line_start":188},{"file":"SKILL.md","line_end":195,"line_start":194},{"file":"SKILL.md","line_end":195,"line_start":195},{"file":"SKILL.md","line_end":196,"line_start":196},{"file":"SKILL.md","line_end":198,"line_start":197},{"file":"SKILL.md","line_end":198,"line_start":198},{"file":"SKILL.md","line_end":203,"line_start":201},{"file":"SKILL.md","line_end":214,"line_start":203},{"file":"SKILL.md","line_end":216,"line_start":214}]},{"factor":"network","evidence":[{"file":"references/quickstart.md","line_end":184,"line_start":184},{"file":"references/quickstart.md","line_end":185,"line_start":185},{"file":"SKILL.md","line_end":156,"line_start":156},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":157,"line_start":157},{"file":"SKILL.md","line_end":201,"line_start":201},{"file":"SKILL.md","line_end":252,"line_start":252},{"file":"SKILL.md","line_end":253,"line_start":253},{"file":"SKILL.md","line_end":254,"line_start":254},{"file":"SKILL.md","line_end":255,"line_start":255},{"file":"SKILL.md","line_end":256,"line_start":256}]},{"factor":"filesystem","evidence":[{"file":"references/quickstart.md","line_end":100,"line_start":100},{"file":"references/quickstart.md","line_end":200,"line_start":200},{"file":"references/quickstart.md","line_end":201,"line_start":201}]},{"factor":"env_access","evidence":[{"file":"references/quickstart.md","line_end":122,"line_start":122},{"file":"references/quickstart.md","line_end":122,"line_start":122},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":89,"line_start":89}]}],"critical_findings":[],"high_findings":[{"title":"Environment variable access (dot notation)","locations":[{"file":"references/quickstart.md","line_end":122,"line_start":122}],"confidence":0.99,"description":"const KEY = process.env.NEXT_PUBLIC_LIFI_INTEGRATOR_KEY!;","review_kind":"capability","source_category":"env_access","source_severity":"low","confidence_reasoning":"The client quickstart reads NEXT_PUBLIC_LIFI_INTEGRATOR_KEY, which is embedded in the browser bundle. This exposes the integrator credential to every application user."},{"title":"Environment variable object","locations":[{"file":"references/quickstart.md","line_end":122,"line_start":122}],"confidence":0.99,"description":"const KEY = process.env.NEXT_PUBLIC_LIFI_INTEGRATOR_KEY!;","review_kind":"capability","source_category":"env_access","source_severity":"low","confidence_reasoning":"The client quickstart reads NEXT_PUBLIC_LIFI_INTEGRATOR_KEY, which is embedded in the browser bundle. This exposes the integrator credential to every application user."},{"title":"Environment file access","locations":[{"file":"references/quickstart.md","line_end":122,"line_start":122}],"confidence":0.99,"description":"const KEY = process.env.NEXT_PUBLIC_LIFI_INTEGRATOR_KEY!;","review_kind":"security","source_category":"sensitive","source_severity":"high","confidence_reasoning":"NEXT_PUBLIC_LIFI_INTEGRATOR_KEY is consumed by client-side code, making the integrator credential visible in the browser bundle. That exposure can enable unauthorized use of the integrator account."},{"title":"Connected Chain Is Not Validated Before Wallet Writes","locations":[{"file":"references/quickstart.md","line_end":178,"line_start":170},{"file":"references/quickstart.md","line_end":228,"line_start":203}],"confidence":0.95,"description":"The Base allowance check is followed by wallet writes using wallet.chain without asserting Base. A different connected chain can target unintended same-address contracts.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The code fixes the read client and token constants to Base but passes the current wallet chain into both transaction writes. No chain assertion or switch appears before approval or order opening."},{"title":"Financial Costs and Settlement Mechanics Are Hidden","locations":[{"file":"SKILL.md","line_end":146,"line_start":139},{"file":"SKILL.md","line_end":180,"line_start":174}],"confidence":0.97,"description":"The guidance says to keep gas, spreads, and solver mechanics off screen and show no fee field. The same flow requires approval and escrow transactions.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The concealment instruction is explicit, while the documented flow includes signed on-chain transactions that can incur source-chain gas and settlement risk."}],"medium_findings":[{"title":"Quickstart Installs Unpinned Packages","locations":[{"file":"references/quickstart.md","line_end":15,"line_start":11}],"confidence":0.96,"description":"The quickstart runs create-next-app at the latest version and installs dependencies without exact versions. Future package changes can alter generated behavior or introduce supply-chain risk.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The commands explicitly use the latest scaffold and omit dependency versions. Reproducing the guide later can therefore resolve different code."}],"low_findings":[{"title":"Fetch API call","locations":[{"file":"references/quickstart.md","line_end":184,"line_start":184}],"confidence":0.98,"description":"const res = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access."},{"title":"Hardcoded URL","locations":[{"file":"references/quickstart.md","line_end":185,"line_start":185}],"confidence":0.98,"description":"`https://order.li.fi/orders/status?onChainOrderId=${orderId}`,","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access."},{"title":"Fetch API call","locations":[{"file":"SKILL.md","line_end":156,"line_start":156}],"confidence":0.98,"description":"const status = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":153,"line_start":153}],"confidence":0.98,"description":"Poll `GET https://order.li.fi/orders/status?onChainOrderId=<orderId>`:","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":157,"line_start":157}],"confidence":0.98,"description":"`https://order.li.fi/orders/status?onChainOrderId=${orderId}`,","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":201,"line_start":201}],"confidence":0.98,"description":"**Quote** — `POST https://order.li.fi/quote/request` (under your integrator key):","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This instruction sends quote requests to the external order.li.fi service under an integrator identity. The request is expected functionality, but it is real network access."}],"dangerous_patterns":[],"files_scanned":2,"total_lines":526,"audit_model":"codex","audited_at":"2026-07-19T10:53:00.699+00:00","created_at":"2026-07-19T11:17:09.515223+00:00","static_findings":[{"id":"external_commands:references/quickstart.md:125:ruby-shell-backtick-execution","file":"references/quickstart.md","pattern":"Ruby/shell backtick execution","snippet":"export type Tok = { address: `0x${string}`; chainId: number; decimals: number; name: string };","category":"external_commands","line_end":133,"severity":"medium","line_start":125},{"id":"external_commands:references/quickstart.md:133:ruby-shell-backtick-execution","file":"references/quickstart.md","pattern":"Ruby/shell backtick execution","snippet":"export async function getQuote(from: Tok, to: Tok, amount: bigint, user: `0x${string}`) {","category":"external_commands","line_end":149,"severity":"medium","line_start":133},{"id":"external_commands:references/quickstart.md:149:ruby-shell-backtick-execution","file":"references/quickstart.md","pattern":"Ruby/shell backtick execution","snippet":"user: `0x${string}`, wallet: WalletClient,","category":"external_commands","line_end":170,"severity":"medium","line_start":149},{"id":"external_commands:references/quickstart.md:170:ruby-shell-backtick-execution","file":"references/quickstart.md","pattern":"Ruby/shell backtick execution","snippet":"// writeContract needs `account` + `chain` when the wallet client has none bound.","category":"external_commands","line_end":170,"severity":"medium","line_start":170},{"id":"external_commands:references/quickstart.md:185:ruby-shell-backtick-execution","file":"references/quickstart.md","pattern":"Ruby/shell backtick execution","snippet":"`https://order.li.fi/orders/status?onChainOrderId=${orderId}`,","category":"external_commands","line_end":189,"severity":"medium","line_start":185},{"id":"network:references/quickstart.md:184:fetch-api-call","file":"references/quickstart.md","pattern":"Fetch API call","snippet":"const res = await fetch(","category":"network","line_end":184,"severity":"low","line_start":184},{"id":"network:references/quickstart.md:185:hardcoded-url","file":"references/quickstart.md","pattern":"Hardcoded URL","snippet":"`https://order.li.fi/orders/status?onChainOrderId=${orderId}`,","category":"network","line_end":185,"severity":"low","line_start":185},{"id":"filesystem:references/quickstart.md:100:path-traversal-sequence","file":"references/quickstart.md","pattern":"Path traversal sequence","snippet":"import { wagmiConfig } from \"../lib/wagmi\";","category":"filesystem","line_end":100,"severity":"high","line_start":100},{"id":"filesystem:references/quickstart.md:200:path-traversal-sequence","file":"references/quickstart.md","pattern":"Path traversal sequence","snippet":"import { getQuote, openSwap, trackOrder, type Tok } from \"../lib/swap\";","category":"filesystem","line_end":200,"severity":"high","line_start":200},{"id":"filesystem:references/quickstart.md:201:path-traversal-sequence","file":"references/quickstart.md","pattern":"Path traversal sequence","snippet":"import { ERC20_ABI } from \"../lib/abi\";","category":"filesystem","line_end":201,"severity":"high","line_start":201},{"id":"env_access:references/quickstart.md:122:environment-variable-access-dot-notation","file":"references/quickstart.md","pattern":"Environment variable access (dot notation)","snippet":"const KEY = process.env.NEXT_PUBLIC_LIFI_INTEGRATOR_KEY!;","category":"env_access","line_end":122,"severity":"low","line_start":122},{"id":"env_access:references/quickstart.md:122:environment-variable-object","file":"references/quickstart.md","pattern":"Environment variable object","snippet":"const KEY = process.env.NEXT_PUBLIC_LIFI_INTEGRATOR_KEY!;","category":"env_access","line_end":122,"severity":"low","line_start":122},{"id":"sensitive:references/quickstart.md:18:environment-file-access","file":"references/quickstart.md","pattern":"Environment file access","snippet":"# .env.local","category":"sensitive","line_end":18,"severity":"high","line_start":18},{"id":"sensitive:references/quickstart.md:122:environment-file-access","file":"references/quickstart.md","pattern":"Environment file access","snippet":"const KEY = process.env.NEXT_PUBLIC_LIFI_INTEGRATOR_KEY!;","category":"sensitive","line_end":122,"severity":"high","line_start":122},{"id":"sensitive:references/quickstart.md:18:environment-variant-files","file":"references/quickstart.md","pattern":"Environment variant files","snippet":"# .env.local","category":"sensitive","line_end":18,"severity":"high","line_start":18},{"id":"blocker:references/quickstart.md:212:system-reconnaissance","file":"references/quickstart.md","pattern":"System reconnaissance","snippet":"const publicClient = usePublicClient({ chainId: 8453 }); // Base — a literal configured chain id","category":"blocker","line_end":213,"severity":"low","line_start":212},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The primary integration is the **`@lifi/intent` TypeScript SDK** — it requests the quote, builds","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`order.li.fi` is the Intents API. The escrow flow is the recommended default and takes four steps:","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":55,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Opening the order emits `Open(bytes32 indexed orderId, ...)`; solvers watch for that event and fill","category":"external_commands","line_end":57,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"until the funds land, then show the user the destination transaction. The `orderId` is the","category":"external_commands","line_end":63,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":65,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":67,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(The runnable interface in the quickstart also uses `wagmi` + `@tanstack/react-query` for the","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Setup note: the SDK uses `bigint` literals (`100_000_000n`). `create-next-app` defaults","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> `tsconfig.json` to `\"target\": \"ES2017\"`, which rejects them — set `\"target\": \"ES2020\"` (or higher)","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`getQuotes` with your integrator key. `IntentApi(true)` targets mainnet / the production solver","category":"external_commands","line_end":77,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"network. Amounts are `bigint` in the token's smallest units (100 USDC = `100_000_000n`, 6 decimals).","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```ts","category":"external_commands","line_end":98,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":104,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The SDK builds the `StandardOrder` for you — pass plain token addresses + chain ids; it computes","category":"external_commands","line_end":105,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the nonce, deadlines, oracle, and EIP-7930 encoding. `getOracle` supplies the verifier oracle","category":"external_commands","line_end":106,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(Polymer addresses below). Then call `open(order)` on the escrow settler the SDK gives you.","category":"external_commands","line_end":108,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```ts","category":"external_commands","line_end":117,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"type Tok = { address: `0x${string}`; chainId: number; decimals: number; name: string };","category":"external_commands","line_end":126,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"outputTokens: [ctx(toToken, received)],   // `received` from the quote","category":"external_commands","line_end":141,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"// 2) Open the order (full `open` ABI is in references/quickstart.md). viem's writeContract","category":"external_commands","line_end":142,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"//    needs `account` and `chain` when the wallet client has none bound:","category":"external_commands","line_end":142,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":153,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Poll `GET https://order.li.fi/orders/status?onChainOrderId=<orderId>`:","category":"external_commands","line_end":155,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```ts","category":"external_commands","line_end":157,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`https://order.li.fi/orders/status?onChainOrderId=${orderId}`,","category":"external_commands","line_end":160,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":164,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Signed` | Order opened and broadcast to the solver network |","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Delivered` | Solver has delivered the assets on the destination chain |","category":"external_commands","line_end":166,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Settled` | Oracle verified delivery; the user's locked funds released to the solver (terminal) |","category":"external_commands","line_end":167,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Expired` | No solver filled before the deadline — the user can claim a refund |","category":"external_commands","line_end":179,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`getQuotes` and display the received amount; for a 1:1-enabled integrator it reads back equal","category":"external_commands","line_end":181,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **In progress** — after approve + open, show a simple status from `/orders/status`","category":"external_commands","line_end":183,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Done** — show \"Delivered\" with the destination transaction link and the `orderId` as a","category":"external_commands","line_end":187,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[`references/quickstart.md`](references/quickstart.md) — including the full `open` ABI, the ERC-20","category":"external_commands","line_end":187,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"approve/allowance step, and the wagmi `createConfig` + provider wiring the wallet hooks need.","category":"external_commands","line_end":194,"severity":"medium","line_start":188},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"No SDK needed; call `order.li.fi` directly. The Intents API uses **EIP-7930 interoperable","category":"external_commands","line_end":195,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"addresses** for `user`/`asset`/`receiver` (chain embedded in the address) — e.g. USDC on Base","category":"external_commands","line_end":195,"severity":"medium","line_start":195},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(chain id 8453 = `0x2105`, token `0x833589...02913`) encodes as","category":"external_commands","line_end":196,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`0x0001000002210514833589fCD6eDb6E08f4c7C32D4f71b54bdA02913`","category":"external_commands","line_end":198,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`0001`=version, `0000`=EVM, `02`=chain-ref len, `2105`=chain id, `14`=addr len, then the 20-byte","category":"external_commands","line_end":198,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Quote** — `POST https://order.li.fi/quote/request` (under your integrator key):","category":"external_commands","line_end":203,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```jsonc","category":"external_commands","line_end":214,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":216,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read `quotes[0].preview.outputs[0].amount` (and `quoteId`, `validUntil`). Then build the","category":"external_commands","line_end":216,"severity":"medium","line_start":216},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`StandardOrder`, ABI-encode it, and call `open(order)` on `InputSettlerEscrow`. The struct:","category":"external_commands","line_end":217,"severity":"medium","line_start":217},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":229,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":231,"severity":"medium","line_start":229},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`outputs[].settler` is the Output Settler; `recipient`/`token` are bytes32-padded addresses;","category":"external_commands","line_end":231,"severity":"medium","line_start":231},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`callbackData`/`context` are `0x` for a plain transfer. Track via the same","category":"external_commands","line_end":232,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`GET /orders/status?onChainOrderId=...`.","category":"external_commands","line_end":241,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| InputSettlerEscrow | `0x000025c3226C00B2Cdc200005a1600509f4e00C0` |","category":"external_commands","line_end":242,"severity":"medium","line_start":241},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Output Settler | `0x0000000000eC36B683C2E6AC89e9A75989C22a2e` |","category":"external_commands","line_end":243,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Polymer Oracle (mainnet) | `0x0000003E06000007A224AeE90052fA6bb46d43C9` |","category":"external_commands","line_end":245,"severity":"medium","line_start":243},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Supported chains and live routes are solver-driven and dynamic — query `GET /chains/supported`","category":"external_commands","line_end":246,"severity":"medium","line_start":245},{"id":"network:SKILL.md:156:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"const status = await fetch(","category":"network","line_end":156,"severity":"low","line_start":156},{"id":"network:SKILL.md:33:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"1. Register an integrator ID on the **LI.FI Partner Portal** — https://portal.li.fi","category":"network","line_end":33,"severity":"low","line_start":33},{"id":"network:SKILL.md:40:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"onboarded integrator. See https://docs.li.fi/lifi-intents/introduction or contact LI.FI to enable it","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"network:SKILL.md:153:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Poll `GET https://order.li.fi/orders/status?onChainOrderId=<orderId>`:","category":"network","line_end":153,"severity":"low","line_start":153},{"id":"network:SKILL.md:157:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"`https://order.li.fi/orders/status?onChainOrderId=${orderId}`,","category":"network","line_end":157,"severity":"low","line_start":157},{"id":"network:SKILL.md:201:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Quote** — `POST https://order.li.fi/quote/request` (under your integrator key):","category":"network","line_end":201,"severity":"low","line_start":201},{"id":"network:SKILL.md:252:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- LI.FI Intents — https://docs.li.fi/lifi-intents/introduction","category":"network","line_end":252,"severity":"low","line_start":252},{"id":"network:SKILL.md:253:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Intents quickstart — https://docs.li.fi/lifi-intents/quickstart","category":"network","line_end":253,"severity":"low","line_start":253},{"id":"network:SKILL.md:254:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Intents API overview — https://docs.li.fi/lifi-intents/intents-api/api-overview","category":"network","line_end":254,"severity":"low","line_start":254},{"id":"network:SKILL.md:255:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Partner Portal (register your integrator) — https://portal.li.fi","category":"network","line_end":255,"severity":"low","line_start":255},{"id":"network:SKILL.md:256:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Interactive API spec — https://order.li.fi/docs","category":"network","line_end":256,"severity":"low","line_start":256},{"id":"env_access:SKILL.md:89:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"integratorKey: process.env.LIFI_INTEGRATOR_KEY,    // your onboarded integrator key","category":"env_access","line_end":89,"severity":"low","line_start":89},{"id":"env_access:SKILL.md:89:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"integratorKey: process.env.LIFI_INTEGRATOR_KEY,    // your onboarded integrator key","category":"env_access","line_end":89,"severity":"low","line_start":89},{"id":"sensitive:SKILL.md:89:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"integratorKey: process.env.LIFI_INTEGRATOR_KEY,    // your onboarded integrator key","category":"sensitive","line_end":89,"severity":"high","line_start":89},{"id":"blocker:SKILL.md:196:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"(chain id 8453 = `0x2105`, token `0x833589...02913`) encodes as","category":"blocker","line_end":196,"severity":"low","line_start":196}],"finding_verdicts":[{"id":"external_commands:references/quickstart.md:125:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/quickstart.md:133:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/quickstart.md:149:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/quickstart.md:170:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/quickstart.md:185:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"network:references/quickstart.md:184:fetch-api-call","reason":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"network:references/quickstart.md:185:hardcoded-url","reason":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"filesystem:references/quickstart.md:100:path-traversal-sequence","reason":"The parent-directory sequence appears in a fixed relative TypeScript import. It does not process user-controlled paths or access files at runtime.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/quickstart.md:200:path-traversal-sequence","reason":"The parent-directory sequence appears in a fixed relative TypeScript import. It does not process user-controlled paths or access files at runtime.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/quickstart.md:201:path-traversal-sequence","reason":"The parent-directory sequence appears in a fixed relative TypeScript import. It does not process user-controlled paths or access files at runtime.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/quickstart.md:122:environment-variable-access-dot-notation","reason":"The client quickstart reads NEXT_PUBLIC_LIFI_INTEGRATOR_KEY, which is embedded in the browser bundle. This exposes the integrator credential to every application user.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"env_access:references/quickstart.md:122:environment-variable-object","reason":"The client quickstart reads NEXT_PUBLIC_LIFI_INTEGRATOR_KEY, which is embedded in the browser bundle. This exposes the integrator credential to every application user.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"sensitive:references/quickstart.md:18:environment-file-access","reason":"This is a Markdown label for a sample .env.local entry containing only a placeholder. The skill does not read an environment file at this location.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/quickstart.md:122:environment-file-access","reason":"NEXT_PUBLIC_LIFI_INTEGRATOR_KEY is consumed by client-side code, making the integrator credential visible in the browser bundle. That exposure can enable unauthorized use of the integrator account.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"sensitive:references/quickstart.md:18:environment-variant-files","reason":"This is a Markdown label for a sample .env.local entry containing only a placeholder. The skill does not read an environment file at this location.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/quickstart.md:212:system-reconnaissance","reason":"The cited value is a configured blockchain chain identifier or token-address encoding example. It does not inspect the host system or collect reconnaissance data.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code markers or TypeScript template and type syntax. The cited text does not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:156:fetch-api-call","reason":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"network:SKILL.md:33:hardcoded-url","reason":"The URL is a LI.FI documentation or onboarding hyperlink in prose. No runtime network request occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:40:hardcoded-url","reason":"The URL is a LI.FI documentation or onboarding hyperlink in prose. No runtime network request occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:153:hardcoded-url","reason":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"network:SKILL.md:157:hardcoded-url","reason":"This code or instruction contacts the external order.li.fi status service with an order identifier. The request is expected functionality, but it is real network access.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"network:SKILL.md:201:hardcoded-url","reason":"This instruction sends quote requests to the external order.li.fi service under an integrator identity. The request is expected functionality, but it is real network access.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"network:SKILL.md:252:hardcoded-url","reason":"The URL is a LI.FI documentation or onboarding hyperlink in prose. No runtime network request occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:253:hardcoded-url","reason":"The URL is a LI.FI documentation or onboarding hyperlink in prose. No runtime network request occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:254:hardcoded-url","reason":"The URL is a LI.FI documentation or onboarding hyperlink in prose. No runtime network request occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:255:hardcoded-url","reason":"The URL is a LI.FI documentation or onboarding hyperlink in prose. No runtime network request occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:256:hardcoded-url","reason":"The URL is a LI.FI documentation or onboarding hyperlink in prose. No runtime network request occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:89:environment-variable-access-dot-notation","reason":"The example reads only the named LIFI_INTEGRATOR_KEY for expected API configuration. It does not enumerate, log, or otherwise disclose the process environment.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:89:environment-variable-object","reason":"The example reads only the named LIFI_INTEGRATOR_KEY for expected API configuration. It does not enumerate, log, or otherwise disclose the process environment.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:SKILL.md:89:environment-file-access","reason":"The example obtains a named integrator key from the process environment, which is conventional secret handling. It does not access an environment file or print the value.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:196:system-reconnaissance","reason":"The cited value is a configured blockchain chain identifier or token-address encoding example. It does not inspect the host system or collect reconnaissance data.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Connected Chain Is Not Validated Before Wallet Writes","severity":"high","locations":[{"file":"references/quickstart.md","line_end":178,"line_start":170},{"file":"references/quickstart.md","line_end":228,"line_start":203}],"confidence":0.95,"description":"The Base allowance check is followed by wallet writes using wallet.chain without asserting Base. A different connected chain can target unintended same-address contracts.","confidence_reasoning":"The code fixes the read client and token constants to Base but passes the current wallet chain into both transaction writes. No chain assertion or switch appears before approval or order opening."},{"title":"Financial Costs and Settlement Mechanics Are Hidden","severity":"high","locations":[{"file":"SKILL.md","line_end":146,"line_start":139},{"file":"SKILL.md","line_end":180,"line_start":174}],"confidence":0.97,"description":"The guidance says to keep gas, spreads, and solver mechanics off screen and show no fee field. The same flow requires approval and escrow transactions.","confidence_reasoning":"The concealment instruction is explicit, while the documented flow includes signed on-chain transactions that can incur source-chain gas and settlement risk."},{"title":"Quickstart Installs Unpinned Packages","severity":"medium","locations":[{"file":"references/quickstart.md","line_end":15,"line_start":11}],"confidence":0.96,"description":"The quickstart runs create-next-app at the latest version and installs dependencies without exact versions. Future package changes can alter generated behavior or introduce supply-chain risk.","confidence_reasoning":"The commands explicitly use the latest scaffold and omit dependency versions. Reproducing the guide later can therefore resolve different code."}],"subject_marketplace_commit_sha":"3f6e026a3363e0954ede7bef0cfe88d4475de137","subject_content_hash":"25d340c22329fddc39da2578ba0bd5d58929a3e8340c5c16b13e3a0d4b606bdb","subject_tree_hash":"59596a6f998fbcd62bb0834487cf4fdc445da8247713384124cd0383495921f2","subject_plugin_path":"skills/internet-court/lifi-stablecoin-swap","audit_payload_hash":"d94764746c9a35a9f49ece9efd95af9d","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"3f6e026a3363e0954ede7bef0cfe88d4475de137","contentHash":"25d340c22329fddc39da2578ba0bd5d58929a3e8340c5c16b13e3a0d4b606bdb","treeHash":"59596a6f998fbcd62bb0834487cf4fdc445da8247713384124cd0383495921f2","pluginPath":"skills/internet-court/lifi-stablecoin-swap","auditPayloadHash":"d94764746c9a35a9f49ece9efd95af9d"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"unavailable","url":null,"status":null},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":4,"capabilityReviewCount":8,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"unavailable","verificationState":"not_verified"},"isLatest":true}}