{"data":{"skill":{"slug":"internet-court-near-intents","name":"near-intents","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/near/near-intents","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"92a59137-4774-469f-a0b4-b5101e5ac247","skill_id":"880ce0dc-3ce4-4551-aa79-093a641bca04","version":2,"content_hash":"v3:3f6e026a3363e0954ede7bef0cfe88d4475de137:37690f4537a952b1b0c1041f6b3842a522b5b61b65a8c7488dbe2c6f217f3214:5064979b684c98380a1d83799f48857176e363830efdee334d13135dba87b55a:736b696c6c732f696e7465726e65742d636f7572742f6e6561722d696e74656e7473:416c189c0815878dacb2e2ee960f1ef7","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Static detections are false positives caused by Markdown and TypeScript syntax, expected API calls, and explicit configuration examples. The skill nevertheless documents an unattended server-side flow that signs and broadcasts live cryptocurrency transfers, so production users need strong transaction controls.","remediation":[{"issue":"The server example creates a committed quote and broadcasts transfers without an approval boundary.","severity":"high","suggestion":"Add explicit transaction confirmation, recipient and asset allowlists, amount limits, quote expiry checks, and a dry-run default before production use."},{"issue":"The server example relies on an environment private key.","severity":"high","suggestion":"Use a managed signer or secret store, restrict key permissions and funded balance, and never place private keys in client-side code or source control."},{"issue":"Remote API quote data directly determines a deposit transfer destination.","severity":"high","suggestion":"Validate the quote response against user-selected assets, recipient, amount, chain, deadline, and trusted service configuration before signing."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/concepts.md","line_end":51,"line_start":50},{"file":"rules/api-any-input-withdrawals.md","line_end":12,"line_start":11},{"file":"rules/api-any-input-withdrawals.md","line_end":15,"line_start":12},{"file":"rules/api-any-input-withdrawals.md","line_end":59,"line_start":58},{"file":"rules/api-any-input-withdrawals.md","line_end":62,"line_start":59},{"file":"rules/api-any-input-withdrawals.md","line_end":67,"line_start":62},{"file":"rules/api-any-input-withdrawals.md","line_end":70,"line_start":67},{"file":"rules/api-any-input-withdrawals.md","line_end":72,"line_start":70},{"file":"rules/api-deposit-submit.md","line_end":21,"line_start":14},{"file":"rules/api-status.md","line_end":12,"line_start":11},{"file":"rules/api-status.md","line_end":15,"line_start":12},{"file":"rules/api-status.md","line_end":64,"line_start":60},{"file":"rules/api-status.md","line_end":78,"line_start":64},{"file":"rules/deposit-evm.md","line_end":20,"line_start":17},{"file":"rules/deposit-evm.md","line_end":34,"line_start":31},{"file":"rules/deposit-evm.md","line_end":36,"line_start":34},{"file":"rules/react-hooks.md","line_end":45,"line_start":26},{"file":"rules/react-hooks.md","line_end":49,"line_start":45},{"file":"rules/react-hooks.md","line_end":68,"line_start":49},{"file":"rules/react-hooks.md","line_end":69,"line_start":68},{"file":"rules/react-hooks.md","line_end":90,"line_start":69},{"file":"rules/react-hooks.md","line_end":94,"line_start":90},{"file":"rules/react-hooks.md","line_end":103,"line_start":94},{"file":"rules/react-hooks.md","line_end":105,"line_start":103},{"file":"rules/react-hooks.md","line_end":113,"line_start":105},{"file":"rules/react-swap-widget.md","line_end":128,"line_start":107},{"file":"rules/react-swap-widget.md","line_end":132,"line_start":128},{"file":"rules/react-swap-widget.md","line_end":153,"line_start":132},{"file":"rules/react-swap-widget.md","line_end":154,"line_start":153},{"file":"rules/react-swap-widget.md","line_end":186,"line_start":154},{"file":"rules/react-swap-widget.md","line_end":190,"line_start":186},{"file":"rules/react-swap-widget.md","line_end":209,"line_start":190},{"file":"rules/react-swap-widget.md","line_end":213,"line_start":209},{"file":"rules/react-swap-widget.md","line_end":322,"line_start":213},{"file":"rules/react-swap-widget.md","line_end":332,"line_start":322},{"file":"rules/react-swap-widget.md","line_end":335,"line_start":332},{"file":"rules/react-swap-widget.md","line_end":340,"line_start":335},{"file":"rules/react-swap-widget.md","line_end":394,"line_start":340},{"file":"rules/react-swap-widget.md","line_end":408,"line_start":394},{"file":"rules/react-swap-widget.md","line_end":462,"line_start":408},{"file":"rules/react-swap-widget.md","line_end":486,"line_start":462},{"file":"rules/server-example.md","line_end":70,"line_start":29},{"file":"rules/server-example.md","line_end":82,"line_start":70},{"file":"rules/server-example.md","line_end":86,"line_start":82},{"file":"rules/server-example.md","line_end":97,"line_start":86},{"file":"rules/server-example.md","line_end":103,"line_start":97},{"file":"rules/server-example.md","line_end":107,"line_start":103},{"file":"rules/server-example.md","line_end":118,"line_start":107},{"file":"rules/server-example.md","line_end":119,"line_start":118},{"file":"rules/server-example.md","line_end":123,"line_start":119}]},{"factor":"network","evidence":[{"file":"rules/api-any-input-withdrawals.md","line_end":10,"line_start":10},{"file":"rules/api-any-input-withdrawals.md","line_end":57,"line_start":57},{"file":"rules/api-any-input-withdrawals.md","line_end":11,"line_start":11},{"file":"rules/api-any-input-withdrawals.md","line_end":58,"line_start":58},{"file":"rules/api-deposit-submit.md","line_end":10,"line_start":10},{"file":"rules/api-deposit-submit.md","line_end":33,"line_start":33},{"file":"rules/api-deposit-submit.md","line_end":47,"line_start":47},{"file":"rules/api-deposit-submit.md","line_end":10,"line_start":10},{"file":"rules/api-deposit-submit.md","line_end":33,"line_start":33},{"file":"rules/api-deposit-submit.md","line_end":47,"line_start":47},{"file":"rules/api-quote.md","line_end":160,"line_start":160},{"file":"rules/api-quote.md","line_end":181,"line_start":181},{"file":"rules/api-quote.md","line_end":208,"line_start":208},{"file":"rules/api-quote.md","line_end":230,"line_start":230},{"file":"rules/api-quote.md","line_end":160,"line_start":160},{"file":"rules/api-quote.md","line_end":181,"line_start":181},{"file":"rules/api-quote.md","line_end":208,"line_start":208},{"file":"rules/api-quote.md","line_end":230,"line_start":230},{"file":"rules/api-status.md","line_end":10,"line_start":10},{"file":"rules/api-status.md","line_end":63,"line_start":63},{"file":"rules/api-status.md","line_end":11,"line_start":11},{"file":"rules/api-status.md","line_end":64,"line_start":64},{"file":"rules/api-tokens.md","line_end":10,"line_start":10},{"file":"rules/api-tokens.md","line_end":10,"line_start":10},{"file":"rules/deposit-stellar.md","line_end":12,"line_start":12},{"file":"rules/deposit-stellar.md","line_end":12,"line_start":12},{"file":"rules/deposit-stellar.md","line_end":34,"line_start":34},{"file":"rules/intents-balance.md","line_end":12,"line_start":12},{"file":"rules/intents-balance.md","line_end":32,"line_start":32},{"file":"rules/intents-balance.md","line_end":12,"line_start":12},{"file":"rules/intents-balance.md","line_end":32,"line_start":32},{"file":"rules/intents-balance.md","line_end":58,"line_start":58},{"file":"rules/passive-deposit.md","line_end":11,"line_start":11},{"file":"rules/passive-deposit.md","line_end":11,"line_start":11},{"file":"rules/react-hooks.md","line_end":26,"line_start":26},{"file":"rules/react-hooks.md","line_end":45,"line_start":45},{"file":"rules/react-hooks.md","line_end":68,"line_start":68},{"file":"rules/react-hooks.md","line_end":90,"line_start":90},{"file":"rules/react-hooks.md","line_end":103,"line_start":103},{"file":"rules/react-hooks.md","line_end":20,"line_start":20},{"file":"rules/react-swap-widget.md","line_end":107,"line_start":107},{"file":"rules/react-swap-widget.md","line_end":128,"line_start":128},{"file":"rules/react-swap-widget.md","line_end":153,"line_start":153},{"file":"rules/react-swap-widget.md","line_end":186,"line_start":186},{"file":"rules/react-swap-widget.md","line_end":209,"line_start":209},{"file":"rules/react-swap-widget.md","line_end":40,"line_start":40},{"file":"rules/server-example.md","line_end":70,"line_start":70},{"file":"rules/server-example.md","line_end":82,"line_start":82},{"file":"rules/server-example.md","line_end":103,"line_start":103},{"file":"rules/server-example.md","line_end":117,"line_start":117}]},{"factor":"env_access","evidence":[{"file":"rules/api-quote.md","line_end":185,"line_start":185},{"file":"rules/react-swap-widget.md","line_end":485,"line_start":485},{"file":"rules/react-swap-widget.md","line_end":485,"line_start":485},{"file":"rules/react-swap-widget.md","line_end":485,"line_start":485},{"file":"rules/server-example.md","line_end":29,"line_start":29},{"file":"rules/server-example.md","line_end":30,"line_start":30},{"file":"rules/server-example.md","line_end":29,"line_start":29},{"file":"rules/server-example.md","line_end":30,"line_start":30},{"file":"rules/server-example.md","line_end":29,"line_start":29},{"file":"rules/server-example.md","line_end":30,"line_start":30},{"file":"rules/server-example.md","line_end":86,"line_start":86},{"file":"rules/server-example.md","line_end":107,"line_start":107},{"file":"rules/server-example.md","line_end":119,"line_start":119},{"file":"rules/server-example.md","line_end":150,"line_start":150},{"file":"rules/server-example.md","line_end":252,"line_start":252}]}],"critical_findings":[],"high_findings":[{"title":"Unattended live swap example can sign and transfer funds","locations":[{"file":"rules/server-example.md","line_end":30,"line_start":29},{"file":"rules/server-example.md","line_end":93,"line_start":89},{"file":"rules/server-example.md","line_end":190,"line_start":150}],"confidence":0.96,"description":"The server example obtains a committed quote, creates an account from a private key, and broadcasts a token or native-token deposit without an interactive approval step. Deploying this pattern without transaction controls can transfer funds after compromised or unintended input.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The documented flow explicitly creates a wallet account from an environment private key and calls contract transfer or native transaction methods after requesting a non-preview quote."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":18,"total_lines":2052,"audit_model":"claude","audited_at":"2026-07-21T03:46:56.938+00:00","created_at":"2026-07-21T03:52:37.648662+00:00","static_findings":[{"id":"external_commands:references/concepts.md:50:ruby-shell-backtick-execution","file":"references/concepts.md","pattern":"Ruby/shell backtick execution","snippet":"headers: { Authorization: `Bearer ${apiKey}` }","category":"external_commands","line_end":51,"severity":"medium","line_start":50},{"id":"blocker:references/concepts.md:47:system-reconnaissance","file":"references/concepts.md","pattern":"System reconnaissance","snippet":"Register on the [Partners Portal](https://partners.near-intents.org/) to obtain an API key and avoid","category":"blocker","line_end":47,"severity":"low","line_start":47},{"id":"blocker:references/concepts.md:17:network-reconnaissance","file":"references/concepts.md","pattern":"Network reconnaissance","snippet":"2. **Deposit tokens** - Send tokens to the unique deposit address","category":"blocker","line_end":18,"severity":"low","line_start":17},{"id":"external_commands:rules/api-any-input-withdrawals.md:11:ruby-shell-backtick-execution","file":"rules/api-any-input-withdrawals.md","pattern":"Ruby/shell backtick execution","snippet":"`https://1click.chaindefuser.com/v0/any-input/withdrawals?depositAddress=${depositAddress}`,","category":"external_commands","line_end":12,"severity":"medium","line_start":11},{"id":"external_commands:rules/api-any-input-withdrawals.md:12:ruby-shell-backtick-execution","file":"rules/api-any-input-withdrawals.md","pattern":"Ruby/shell backtick execution","snippet":"{ headers: { Authorization: `Bearer ${apiKey}` } }","category":"external_commands","line_end":15,"severity":"medium","line_start":12},{"id":"external_commands:rules/api-any-input-withdrawals.md:58:ruby-shell-backtick-execution","file":"rules/api-any-input-withdrawals.md","pattern":"Ruby/shell backtick execution","snippet":"`https://1click.chaindefuser.com/v0/any-input/withdrawals?${params}`,","category":"external_commands","line_end":59,"severity":"medium","line_start":58},{"id":"external_commands:rules/api-any-input-withdrawals.md:59:ruby-shell-backtick-execution","file":"rules/api-any-input-withdrawals.md","pattern":"Ruby/shell backtick execution","snippet":"{ headers: apiKey ? { Authorization: `Bearer ${apiKey}` } : {} }","category":"external_commands","line_end":62,"severity":"medium","line_start":59},{"id":"external_commands:rules/api-any-input-withdrawals.md:62:ruby-shell-backtick-execution","file":"rules/api-any-input-withdrawals.md","pattern":"Ruby/shell backtick execution","snippet":"if (!res.ok) throw new Error(`Failed: ${res.status}`);","category":"external_commands","line_end":67,"severity":"medium","line_start":62},{"id":"external_commands:rules/api-any-input-withdrawals.md:67:ruby-shell-backtick-execution","file":"rules/api-any-input-withdrawals.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Total withdrawals: ${data.withdrawals.length}`);","category":"external_commands","line_end":70,"severity":"medium","line_start":67},{"id":"external_commands:rules/api-any-input-withdrawals.md:70:ruby-shell-backtick-execution","file":"rules/api-any-input-withdrawals.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`${w.status}: ${w.amountOutFormatted} (fee: ${w.withdrawFeeFormatted})`);","category":"external_commands","line_end":72,"severity":"medium","line_start":70},{"id":"network:rules/api-any-input-withdrawals.md:10:fetch-api-call","file":"rules/api-any-input-withdrawals.md","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:rules/api-any-input-withdrawals.md:57:fetch-api-call","file":"rules/api-any-input-withdrawals.md","pattern":"Fetch API call","snippet":"const res = await fetch(","category":"network","line_end":57,"severity":"low","line_start":57},{"id":"network:rules/api-any-input-withdrawals.md:11:hardcoded-url","file":"rules/api-any-input-withdrawals.md","pattern":"Hardcoded URL","snippet":"`https://1click.chaindefuser.com/v0/any-input/withdrawals?depositAddress=${depositAddress}`,","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:rules/api-any-input-withdrawals.md:58:hardcoded-url","file":"rules/api-any-input-withdrawals.md","pattern":"Hardcoded URL","snippet":"`https://1click.chaindefuser.com/v0/any-input/withdrawals?${params}`,","category":"network","line_end":58,"severity":"low","line_start":58},{"id":"external_commands:rules/api-deposit-submit.md:14:ruby-shell-backtick-execution","file":"rules/api-deposit-submit.md","pattern":"Ruby/shell backtick execution","snippet":"'Authorization': `Bearer ${apiKey}`,","category":"external_commands","line_end":21,"severity":"medium","line_start":14},{"id":"network:rules/api-deposit-submit.md:10:fetch-api-call","file":"rules/api-deposit-submit.md","pattern":"Fetch API call","snippet":"await fetch('https://1click.chaindefuser.com/v0/deposit/submit', {","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:rules/api-deposit-submit.md:33:fetch-api-call","file":"rules/api-deposit-submit.md","pattern":"Fetch API call","snippet":"await fetch('https://1click.chaindefuser.com/v0/deposit/submit', {","category":"network","line_end":33,"severity":"low","line_start":33},{"id":"network:rules/api-deposit-submit.md:47:fetch-api-call","file":"rules/api-deposit-submit.md","pattern":"Fetch API call","snippet":"await fetch('https://1click.chaindefuser.com/v0/deposit/submit', {","category":"network","line_end":47,"severity":"low","line_start":47},{"id":"network:rules/api-deposit-submit.md:10:hardcoded-url","file":"rules/api-deposit-submit.md","pattern":"Hardcoded URL","snippet":"await fetch('https://1click.chaindefuser.com/v0/deposit/submit', {","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:rules/api-deposit-submit.md:33:hardcoded-url","file":"rules/api-deposit-submit.md","pattern":"Hardcoded URL","snippet":"await fetch('https://1click.chaindefuser.com/v0/deposit/submit', {","category":"network","line_end":33,"severity":"low","line_start":33},{"id":"network:rules/api-deposit-submit.md:47:hardcoded-url","file":"rules/api-deposit-submit.md","pattern":"Hardcoded URL","snippet":"await fetch('https://1click.chaindefuser.com/v0/deposit/submit', {","category":"network","line_end":47,"severity":"low","line_start":47},{"id":"network:rules/api-quote.md:160:fetch-api-call","file":"rules/api-quote.md","pattern":"Fetch API call","snippet":"const preview = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":160,"severity":"low","line_start":160},{"id":"network:rules/api-quote.md:181:fetch-api-call","file":"rules/api-quote.md","pattern":"Fetch API call","snippet":"const committed = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":181,"severity":"low","line_start":181},{"id":"network:rules/api-quote.md:208:fetch-api-call","file":"rules/api-quote.md","pattern":"Fetch API call","snippet":"const stellarQuote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":208,"severity":"low","line_start":208},{"id":"network:rules/api-quote.md:230:fetch-api-call","file":"rules/api-quote.md","pattern":"Fetch API call","snippet":"const toIntents = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":230,"severity":"low","line_start":230},{"id":"network:rules/api-quote.md:160:hardcoded-url","file":"rules/api-quote.md","pattern":"Hardcoded URL","snippet":"const preview = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":160,"severity":"low","line_start":160},{"id":"network:rules/api-quote.md:181:hardcoded-url","file":"rules/api-quote.md","pattern":"Hardcoded URL","snippet":"const committed = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":181,"severity":"low","line_start":181},{"id":"network:rules/api-quote.md:208:hardcoded-url","file":"rules/api-quote.md","pattern":"Hardcoded URL","snippet":"const stellarQuote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":208,"severity":"low","line_start":208},{"id":"network:rules/api-quote.md:230:hardcoded-url","file":"rules/api-quote.md","pattern":"Hardcoded URL","snippet":"const toIntents = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":230,"severity":"low","line_start":230},{"id":"env_access:rules/api-quote.md:185:generic-api-secret-keys","file":"rules/api-quote.md","pattern":"Generic API/secret keys","snippet":"'Authorization': 'Bearer YOUR_API_KEY' // Avoid 0.1% fee","category":"env_access","line_end":185,"severity":"high","line_start":185},{"id":"blocker:rules/api-quote.md:17:system-reconnaissance","file":"rules/api-quote.md","pattern":"System reconnaissance","snippet":"| `dry` | boolean | `true` = preview only (no deposit address generated). `false` = commit quote, re","category":"blocker","line_end":17,"severity":"low","line_start":17},{"id":"blocker:rules/api-quote.md:23:system-reconnaissance","file":"rules/api-quote.md","pattern":"System reconnaissance","snippet":"| `refundTo` | string | Address for refunds if swap fails. Must be valid for origin chain |","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"blocker:rules/api-quote.md:185:system-reconnaissance","file":"rules/api-quote.md","pattern":"System reconnaissance","snippet":"'Authorization': 'Bearer YOUR_API_KEY' // Avoid 0.1% fee","category":"blocker","line_end":185,"severity":"low","line_start":185},{"id":"external_commands:rules/api-status.md:11:ruby-shell-backtick-execution","file":"rules/api-status.md","pattern":"Ruby/shell backtick execution","snippet":"`https://1click.chaindefuser.com/v0/status?depositAddress=${depositAddress}`,","category":"external_commands","line_end":12,"severity":"medium","line_start":11},{"id":"external_commands:rules/api-status.md:12:ruby-shell-backtick-execution","file":"rules/api-status.md","pattern":"Ruby/shell backtick execution","snippet":"{ headers: { Authorization: `Bearer ${apiKey}` } }","category":"external_commands","line_end":15,"severity":"medium","line_start":12},{"id":"external_commands:rules/api-status.md:60:ruby-shell-backtick-execution","file":"rules/api-status.md","pattern":"Ruby/shell backtick execution","snippet":"const headers = apiKey ? { Authorization: `Bearer ${apiKey}` } : {};","category":"external_commands","line_end":64,"severity":"medium","line_start":60},{"id":"external_commands:rules/api-status.md:64:ruby-shell-backtick-execution","file":"rules/api-status.md","pattern":"Ruby/shell backtick execution","snippet":"`https://1click.chaindefuser.com/v0/status?depositAddress=${depositAddress}`,","category":"external_commands","line_end":78,"severity":"medium","line_start":64},{"id":"network:rules/api-status.md:10:fetch-api-call","file":"rules/api-status.md","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:rules/api-status.md:63:fetch-api-call","file":"rules/api-status.md","pattern":"Fetch API call","snippet":"const res = await fetch(","category":"network","line_end":63,"severity":"low","line_start":63},{"id":"network:rules/api-status.md:11:hardcoded-url","file":"rules/api-status.md","pattern":"Hardcoded URL","snippet":"`https://1click.chaindefuser.com/v0/status?depositAddress=${depositAddress}`,","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:rules/api-status.md:64:hardcoded-url","file":"rules/api-status.md","pattern":"Hardcoded URL","snippet":"`https://1click.chaindefuser.com/v0/status?depositAddress=${depositAddress}`,","category":"network","line_end":64,"severity":"low","line_start":64},{"id":"network:rules/api-tokens.md:10:fetch-api-call","file":"rules/api-tokens.md","pattern":"Fetch API call","snippet":"const response = await fetch('https://1click.chaindefuser.com/v0/tokens');","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:rules/api-tokens.md:10:hardcoded-url","file":"rules/api-tokens.md","pattern":"Hardcoded URL","snippet":"const response = await fetch('https://1click.chaindefuser.com/v0/tokens');","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"external_commands:rules/deposit-evm.md:17:ruby-shell-backtick-execution","file":"rules/deposit-evm.md","pattern":"Ruby/shell backtick execution","snippet":"to: depositAddress as `0x${string}`,","category":"external_commands","line_end":20,"severity":"medium","line_start":17},{"id":"external_commands:rules/deposit-evm.md:31:ruby-shell-backtick-execution","file":"rules/deposit-evm.md","pattern":"Ruby/shell backtick execution","snippet":"address: tokenAddress as `0x${string}`,","category":"external_commands","line_end":34,"severity":"medium","line_start":31},{"id":"external_commands:rules/deposit-evm.md:34:ruby-shell-backtick-execution","file":"rules/deposit-evm.md","pattern":"Ruby/shell backtick execution","snippet":"args: [depositAddress as `0x${string}`, BigInt(amountIn)],","category":"external_commands","line_end":36,"severity":"medium","line_start":34},{"id":"network:rules/deposit-stellar.md:12:fetch-api-call","file":"rules/deposit-stellar.md","pattern":"Fetch API call","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:rules/deposit-stellar.md:12:hardcoded-url","file":"rules/deposit-stellar.md","pattern":"Hardcoded URL","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:rules/deposit-stellar.md:34:hardcoded-url","file":"rules/deposit-stellar.md","pattern":"Hardcoded URL","snippet":"const server = new Horizon.Server('https://horizon.stellar.org');","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"blocker:rules/deposit-ton.md:37:system-reconnaissance","file":"rules/deposit-ton.md","pattern":"System reconnaissance","snippet":".storeUint(0, 64)          // query_id","category":"blocker","line_end":38,"severity":"low","line_start":37},{"id":"network:rules/intents-balance.md:12:fetch-api-call","file":"rules/intents-balance.md","pattern":"Fetch API call","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:rules/intents-balance.md:32:fetch-api-call","file":"rules/intents-balance.md","pattern":"Fetch API call","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:rules/intents-balance.md:12:hardcoded-url","file":"rules/intents-balance.md","pattern":"Hardcoded URL","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:rules/intents-balance.md:32:hardcoded-url","file":"rules/intents-balance.md","pattern":"Hardcoded URL","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:rules/intents-balance.md:58:hardcoded-url","file":"rules/intents-balance.md","pattern":"Hardcoded URL","snippet":"nodeUrl: 'https://rpc.mainnet.near.org',","category":"network","line_end":58,"severity":"low","line_start":58},{"id":"network:rules/passive-deposit.md:11:fetch-api-call","file":"rules/passive-deposit.md","pattern":"Fetch API call","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:rules/passive-deposit.md:11:hardcoded-url","file":"rules/passive-deposit.md","pattern":"Hardcoded URL","snippet":"const quote = await fetch('https://1click.chaindefuser.com/v0/quote', {","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"external_commands:rules/react-hooks.md:26:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"queryFn: () => fetch(`${API}/v0/tokens`).then((r) => r.json()),","category":"external_commands","line_end":45,"severity":"medium","line_start":26},{"id":"external_commands:rules/react-hooks.md:45:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"fetch(`${API}/v0/quote`, {","category":"external_commands","line_end":49,"severity":"medium","line_start":45},{"id":"external_commands:rules/react-hooks.md:49:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"...(apiKey && { Authorization: `Bearer ${apiKey}` }),","category":"external_commands","line_end":68,"severity":"medium","line_start":49},{"id":"external_commands:rules/react-hooks.md:68:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"fetch(`${API}/v0/status?depositAddress=${depositAddress}`, {","category":"external_commands","line_end":69,"severity":"medium","line_start":68},{"id":"external_commands:rules/react-hooks.md:69:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"headers: apiKey ? { Authorization: `Bearer ${apiKey}` } : {},","category":"external_commands","line_end":90,"severity":"medium","line_start":69},{"id":"external_commands:rules/react-hooks.md:90:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"const quote = await fetch(`${API}/v0/quote`, {","category":"external_commands","line_end":94,"severity":"medium","line_start":90},{"id":"external_commands:rules/react-hooks.md:94:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"...(apiKey && { Authorization: `Bearer ${apiKey}` }),","category":"external_commands","line_end":103,"severity":"medium","line_start":94},{"id":"external_commands:rules/react-hooks.md:103:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"fetch(`${API}/v0/deposit/submit`, {","category":"external_commands","line_end":105,"severity":"medium","line_start":103},{"id":"external_commands:rules/react-hooks.md:105:ruby-shell-backtick-execution","file":"rules/react-hooks.md","pattern":"Ruby/shell backtick execution","snippet":"headers: { 'Content-Type': 'application/json', ...(apiKey && { Authorization: `Bearer ${apiKey}` }) ","category":"external_commands","line_end":113,"severity":"medium","line_start":105},{"id":"network:rules/react-hooks.md:26:fetch-api-call","file":"rules/react-hooks.md","pattern":"Fetch API call","snippet":"queryFn: () => fetch(`${API}/v0/tokens`).then((r) => r.json()),","category":"network","line_end":26,"severity":"low","line_start":26},{"id":"network:rules/react-hooks.md:45:fetch-api-call","file":"rules/react-hooks.md","pattern":"Fetch API call","snippet":"fetch(`${API}/v0/quote`, {","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:rules/react-hooks.md:68:fetch-api-call","file":"rules/react-hooks.md","pattern":"Fetch API call","snippet":"fetch(`${API}/v0/status?depositAddress=${depositAddress}`, {","category":"network","line_end":68,"severity":"low","line_start":68},{"id":"network:rules/react-hooks.md:90:fetch-api-call","file":"rules/react-hooks.md","pattern":"Fetch API call","snippet":"const quote = await fetch(`${API}/v0/quote`, {","category":"network","line_end":90,"severity":"low","line_start":90},{"id":"network:rules/react-hooks.md:103:fetch-api-call","file":"rules/react-hooks.md","pattern":"Fetch API call","snippet":"fetch(`${API}/v0/deposit/submit`, {","category":"network","line_end":103,"severity":"low","line_start":103},{"id":"network:rules/react-hooks.md:20:hardcoded-url","file":"rules/react-hooks.md","pattern":"Hardcoded URL","snippet":"const API = 'https://1click.chaindefuser.com';","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"external_commands:rules/react-swap-widget.md:107:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"const res = await fetch(`${API_BASE}/v0/tokens`);","category":"external_commands","line_end":128,"severity":"medium","line_start":107},{"id":"external_commands:rules/react-swap-widget.md:128:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"const res = await fetch(`${API_BASE}/v0/quote`, {","category":"external_commands","line_end":132,"severity":"medium","line_start":128},{"id":"external_commands:rules/react-swap-widget.md:132:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"...(apiKey && { Authorization: `Bearer ${apiKey}` }),","category":"external_commands","line_end":153,"severity":"medium","line_start":132},{"id":"external_commands:rules/react-swap-widget.md:153:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"const res = await fetch(`${API_BASE}/v0/status?depositAddress=${depositAddress}`, {","category":"external_commands","line_end":154,"severity":"medium","line_start":153},{"id":"external_commands:rules/react-swap-widget.md:154:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"headers: apiKey ? { Authorization: `Bearer ${apiKey}` } : {},","category":"external_commands","line_end":186,"severity":"medium","line_start":154},{"id":"external_commands:rules/react-swap-widget.md:186:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"const quoteRes = await fetch(`${API_BASE}/v0/quote`, {","category":"external_commands","line_end":190,"severity":"medium","line_start":186},{"id":"external_commands:rules/react-swap-widget.md:190:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"...(apiKey && { Authorization: `Bearer ${apiKey}` }),","category":"external_commands","line_end":209,"severity":"medium","line_start":190},{"id":"external_commands:rules/react-swap-widget.md:209:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"await fetch(`${API_BASE}/v0/deposit/submit`, {","category":"external_commands","line_end":213,"severity":"medium","line_start":209},{"id":"external_commands:rules/react-swap-widget.md:213:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"...(apiKey && { Authorization: `Bearer ${apiKey}` }),","category":"external_commands","line_end":322,"severity":"medium","line_start":213},{"id":"external_commands:rules/react-swap-widget.md:322:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"alert(`Please switch to ${fromToken.blockchain} network`);","category":"external_commands","line_end":332,"severity":"medium","line_start":322},{"id":"external_commands:rules/react-swap-widget.md:332:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"address: fromToken.contractAddress as `0x${string}`,","category":"external_commands","line_end":335,"severity":"medium","line_start":332},{"id":"external_commands:rules/react-swap-widget.md:335:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"args: [depositAddr as `0x${string}`, BigInt(depositAmount)],","category":"external_commands","line_end":340,"severity":"medium","line_start":335},{"id":"external_commands:rules/react-swap-widget.md:340:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"to: depositAddr as `0x${string}`,","category":"external_commands","line_end":394,"severity":"medium","line_start":340},{"id":"external_commands:rules/react-swap-widget.md:394:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"Amount {fromToken && `(${fromToken.symbol})`}","category":"external_commands","line_end":408,"severity":"medium","line_start":394},{"id":"external_commands:rules/react-swap-widget.md:408:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"Recipient {toToken && `(${toToken.blockchain} address)`}","category":"external_commands","line_end":462,"severity":"medium","line_start":408},{"id":"external_commands:rules/react-swap-widget.md:462:ruby-shell-backtick-execution","file":"rules/react-swap-widget.md","pattern":"Ruby/shell backtick execution","snippet":"? `${statusData?.status || 'Processing'}...`","category":"external_commands","line_end":486,"severity":"medium","line_start":462},{"id":"network:rules/react-swap-widget.md:107:fetch-api-call","file":"rules/react-swap-widget.md","pattern":"Fetch API call","snippet":"const res = await fetch(`${API_BASE}/v0/tokens`);","category":"network","line_end":107,"severity":"low","line_start":107},{"id":"network:rules/react-swap-widget.md:128:fetch-api-call","file":"rules/react-swap-widget.md","pattern":"Fetch API call","snippet":"const res = await fetch(`${API_BASE}/v0/quote`, {","category":"network","line_end":128,"severity":"low","line_start":128},{"id":"network:rules/react-swap-widget.md:153:fetch-api-call","file":"rules/react-swap-widget.md","pattern":"Fetch API call","snippet":"const res = await fetch(`${API_BASE}/v0/status?depositAddress=${depositAddress}`, {","category":"network","line_end":153,"severity":"low","line_start":153},{"id":"network:rules/react-swap-widget.md:186:fetch-api-call","file":"rules/react-swap-widget.md","pattern":"Fetch API call","snippet":"const quoteRes = await fetch(`${API_BASE}/v0/quote`, {","category":"network","line_end":186,"severity":"low","line_start":186},{"id":"network:rules/react-swap-widget.md:209:fetch-api-call","file":"rules/react-swap-widget.md","pattern":"Fetch API call","snippet":"await fetch(`${API_BASE}/v0/deposit/submit`, {","category":"network","line_end":209,"severity":"low","line_start":209},{"id":"network:rules/react-swap-widget.md:40:hardcoded-url","file":"rules/react-swap-widget.md","pattern":"Hardcoded URL","snippet":"const API_BASE = 'https://1click.chaindefuser.com';","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"env_access:rules/react-swap-widget.md:485:environment-variable-access-dot-notation","file":"rules/react-swap-widget.md","pattern":"Environment variable access (dot notation)","snippet":"// <SwapWidget apiKey={process.env.NEXT_PUBLIC_ONE_CLICK_API_KEY} />","category":"env_access","line_end":485,"severity":"low","line_start":485},{"id":"env_access:rules/react-swap-widget.md:485:environment-variable-object","file":"rules/react-swap-widget.md","pattern":"Environment variable object","snippet":"// <SwapWidget apiKey={process.env.NEXT_PUBLIC_ONE_CLICK_API_KEY} />","category":"env_access","line_end":485,"severity":"low","line_start":485},{"id":"env_access:rules/react-swap-widget.md:485:generic-api-secret-keys","file":"rules/react-swap-widget.md","pattern":"Generic API/secret keys","snippet":"// <SwapWidget apiKey={process.env.NEXT_PUBLIC_ONE_CLICK_API_KEY} />","category":"env_access","line_end":485,"severity":"high","line_start":485},{"id":"sensitive:rules/react-swap-widget.md:485:environment-file-access","file":"rules/react-swap-widget.md","pattern":"Environment file access","snippet":"// <SwapWidget apiKey={process.env.NEXT_PUBLIC_ONE_CLICK_API_KEY} />","category":"sensitive","line_end":485,"severity":"high","line_start":485},{"id":"blocker:rules/react-swap-widget.md:321:system-reconnaissance","file":"rules/react-swap-widget.md","pattern":"System reconnaissance","snippet":"if (chain?.id !== targetChainId) {","category":"blocker","line_end":321,"severity":"low","line_start":321},{"id":"external_commands:rules/server-example.md:29:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"const PRIVATE_KEY = process.env.PRIVATE_KEY as `0x${string}`;","category":"external_commands","line_end":70,"severity":"medium","line_start":29},{"id":"external_commands:rules/server-example.md:70:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"const res = await fetch(`${API_BASE}/v0/tokens`);","category":"external_commands","line_end":82,"severity":"medium","line_start":70},{"id":"external_commands:rules/server-example.md:82:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"const res = await fetch(`${API_BASE}/v0/quote`, {","category":"external_commands","line_end":86,"severity":"medium","line_start":82},{"id":"external_commands:rules/server-example.md:86:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"...(API_KEY && { Authorization: `Bearer ${API_KEY}` }),","category":"external_commands","line_end":97,"severity":"medium","line_start":86},{"id":"external_commands:rules/server-example.md:97:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"throw new Error(`Quote failed: ${error}`);","category":"external_commands","line_end":103,"severity":"medium","line_start":97},{"id":"external_commands:rules/server-example.md:103:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"await fetch(`${API_BASE}/v0/deposit/submit`, {","category":"external_commands","line_end":107,"severity":"medium","line_start":103},{"id":"external_commands:rules/server-example.md:107:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"...(API_KEY && { Authorization: `Bearer ${API_KEY}` }),","category":"external_commands","line_end":118,"severity":"medium","line_start":107},{"id":"external_commands:rules/server-example.md:118:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"`${API_BASE}/v0/status?depositAddress=${depositAddress}`,","category":"external_commands","line_end":119,"severity":"medium","line_start":118},{"id":"external_commands:rules/server-example.md:119:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"{ headers: API_KEY ? { Authorization: `Bearer ${API_KEY}` } : {} }","category":"external_commands","line_end":123,"severity":"medium","line_start":119},{"id":"external_commands:rules/server-example.md:123:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Status: ${status.status}`);","category":"external_commands","line_end":147,"severity":"medium","line_start":123},{"id":"external_commands:rules/server-example.md:147:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"if (!chain) throw new Error(`Unsupported chain: ${fromToken.blockchain}`);","category":"external_commands","line_end":160,"severity":"medium","line_start":147},{"id":"external_commands:rules/server-example.md:160:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Swapping ${amount} ${fromToken.symbol} → ${toToken.symbol}`);","category":"external_commands","line_end":171,"severity":"medium","line_start":160},{"id":"external_commands:rules/server-example.md:171:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Deposit ${quote.quote.amountIn} to ${quote.quote.depositAddress}`);","category":"external_commands","line_end":172,"severity":"medium","line_start":171},{"id":"external_commands:rules/server-example.md:172:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Expected output: ${quote.quote.amountOutFormatted} ${toToken.symbol}`);","category":"external_commands","line_end":180,"severity":"medium","line_start":172},{"id":"external_commands:rules/server-example.md:180:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"address: fromToken.contractAddress as `0x${string}`,","category":"external_commands","line_end":183,"severity":"medium","line_start":180},{"id":"external_commands:rules/server-example.md:183:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"args: [quote.quote.depositAddress as `0x${string}`, BigInt(quote.quote.amountIn)],","category":"external_commands","line_end":188,"severity":"medium","line_start":183},{"id":"external_commands:rules/server-example.md:188:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"to: quote.quote.depositAddress as `0x${string}`,","category":"external_commands","line_end":193,"severity":"medium","line_start":188},{"id":"external_commands:rules/server-example.md:193:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Deposit TX: ${txHash}`);","category":"external_commands","line_end":202,"severity":"medium","line_start":193},{"id":"external_commands:rules/server-example.md:202:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Swap complete! Received: ${result.swapDetails?.amountOut}`);","category":"external_commands","line_end":204,"severity":"medium","line_start":202},{"id":"external_commands:rules/server-example.md:204:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`TX: ${result.swapDetails.destinationChainTxHashes[0].explorerUrl}`);","category":"external_commands","line_end":207,"severity":"medium","line_start":204},{"id":"external_commands:rules/server-example.md:207:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Swap ended with status: ${result.status}`);","category":"external_commands","line_end":221,"severity":"medium","line_start":207},{"id":"external_commands:rules/server-example.md:221:ruby-shell-backtick-execution","file":"rules/server-example.md","pattern":"Ruby/shell backtick execution","snippet":"if (!token) throw new Error(`Token not found: ${symbol} on ${blockchain}`);","category":"external_commands","line_end":247,"severity":"medium","line_start":221},{"id":"network:rules/server-example.md:70:fetch-api-call","file":"rules/server-example.md","pattern":"Fetch API call","snippet":"const res = await fetch(`${API_BASE}/v0/tokens`);","category":"network","line_end":70,"severity":"low","line_start":70},{"id":"network:rules/server-example.md:82:fetch-api-call","file":"rules/server-example.md","pattern":"Fetch API call","snippet":"const res = await fetch(`${API_BASE}/v0/quote`, {","category":"network","line_end":82,"severity":"low","line_start":82},{"id":"network:rules/server-example.md:103:fetch-api-call","file":"rules/server-example.md","pattern":"Fetch API call","snippet":"await fetch(`${API_BASE}/v0/deposit/submit`, {","category":"network","line_end":103,"severity":"low","line_start":103},{"id":"network:rules/server-example.md:117:fetch-api-call","file":"rules/server-example.md","pattern":"Fetch API call","snippet":"const res = await fetch(","category":"network","line_end":117,"severity":"low","line_start":117},{"id":"network:rules/server-example.md:28:hardcoded-url","file":"rules/server-example.md","pattern":"Hardcoded URL","snippet":"const API_BASE = 'https://1click.chaindefuser.com';","category":"network","line_end":28,"severity":"low","line_start":28},{"id":"network:rules/server-example.md:281:hardcoded-url","file":"rules/server-example.md","pattern":"Hardcoded URL","snippet":"const connection = new Connection('https://api.mainnet-beta.solana.com');","category":"network","line_end":281,"severity":"low","line_start":281},{"id":"env_access:rules/server-example.md:29:environment-variable-access-dot-notation","file":"rules/server-example.md","pattern":"Environment variable access (dot notation)","snippet":"const PRIVATE_KEY = process.env.PRIVATE_KEY as `0x${string}`;","category":"env_access","line_end":29,"severity":"low","line_start":29},{"id":"env_access:rules/server-example.md:30:environment-variable-access-dot-notation","file":"rules/server-example.md","pattern":"Environment variable access (dot notation)","snippet":"const API_KEY = process.env.ONE_CLICK_API_KEY; // Optional, avoids 0.1% fee","category":"env_access","line_end":30,"severity":"low","line_start":30},{"id":"env_access:rules/server-example.md:29:environment-variable-object","file":"rules/server-example.md","pattern":"Environment variable object","snippet":"const PRIVATE_KEY = process.env.PRIVATE_KEY as `0x${string}`;","category":"env_access","line_end":29,"severity":"low","line_start":29},{"id":"env_access:rules/server-example.md:30:environment-variable-object","file":"rules/server-example.md","pattern":"Environment variable object","snippet":"const API_KEY = process.env.ONE_CLICK_API_KEY; // Optional, avoids 0.1% fee","category":"env_access","line_end":30,"severity":"low","line_start":30},{"id":"env_access:rules/server-example.md:29:generic-api-secret-keys","file":"rules/server-example.md","pattern":"Generic API/secret keys","snippet":"const PRIVATE_KEY = process.env.PRIVATE_KEY as `0x${string}`;","category":"env_access","line_end":29,"severity":"high","line_start":29},{"id":"env_access:rules/server-example.md:30:generic-api-secret-keys","file":"rules/server-example.md","pattern":"Generic API/secret keys","snippet":"const API_KEY = process.env.ONE_CLICK_API_KEY; // Optional, avoids 0.1% fee","category":"env_access","line_end":30,"severity":"high","line_start":30},{"id":"env_access:rules/server-example.md:86:generic-api-secret-keys","file":"rules/server-example.md","pattern":"Generic API/secret keys","snippet":"...(API_KEY && { Authorization: `Bearer ${API_KEY}` }),","category":"env_access","line_end":86,"severity":"high","line_start":86},{"id":"env_access:rules/server-example.md:107:generic-api-secret-keys","file":"rules/server-example.md","pattern":"Generic API/secret keys","snippet":"...(API_KEY && { Authorization: `Bearer ${API_KEY}` }),","category":"env_access","line_end":107,"severity":"high","line_start":107},{"id":"env_access:rules/server-example.md:119:generic-api-secret-keys","file":"rules/server-example.md","pattern":"Generic API/secret keys","snippet":"{ headers: API_KEY ? { Authorization: `Bearer ${API_KEY}` } : {} }","category":"env_access","line_end":119,"severity":"high","line_start":119},{"id":"env_access:rules/server-example.md:150:generic-api-secret-keys","file":"rules/server-example.md","pattern":"Generic API/secret keys","snippet":"const account = privateKeyToAccount(PRIVATE_KEY);","category":"env_access","line_end":150,"severity":"high","line_start":150},{"id":"env_access:rules/server-example.md:252:generic-api-secret-keys","file":"rules/server-example.md","pattern":"Generic API/secret keys","snippet":"PRIVATE_KEY=0x... ONE_CLICK_API_KEY=... npx tsx bot.ts","category":"env_access","line_end":252,"severity":"high","line_start":252},{"id":"sensitive:rules/server-example.md:29:environment-file-access","file":"rules/server-example.md","pattern":"Environment file access","snippet":"const PRIVATE_KEY = process.env.PRIVATE_KEY as `0x${string}`;","category":"sensitive","line_end":29,"severity":"high","line_start":29},{"id":"sensitive:rules/server-example.md:30:environment-file-access","file":"rules/server-example.md","pattern":"Environment file access","snippet":"const API_KEY = process.env.ONE_CLICK_API_KEY; // Optional, avoids 0.1% fee","category":"sensitive","line_end":30,"severity":"high","line_start":30},{"id":"sensitive:rules/server-example.md:21:crypto-seed-private-key-mention","file":"rules/server-example.md","pattern":"Crypto seed/private key mention","snippet":"import { privateKeyToAccount } from 'viem/accounts';","category":"sensitive","line_end":21,"severity":"high","line_start":21},{"id":"sensitive:rules/server-example.md:150:crypto-seed-private-key-mention","file":"rules/server-example.md","pattern":"Crypto seed/private key mention","snippet":"const account = privateKeyToAccount(PRIVATE_KEY);","category":"sensitive","line_end":150,"severity":"high","line_start":150},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **React App** | `react-swap-widget.md` - Example showing the pattern |","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Node.js / Script** | `server-example.md` - Example showing the pattern |","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **API Reference** | `api-quote.md` → `api-tokens.md` → `api-status.md` |","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Chain-specific Deposits** | `deposit-{chain}.md` |","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":23,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":29,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 1 | **Examples** | `react-swap-widget.md`, `server-example.md` |","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 2 | **API** | `api-quote.md`, `api-tokens.md`, `api-status.md`, `api-deposit-submit.md` |","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 3 | **Deposits** | `deposit-evm.md`, `deposit-solana.md`, `deposit-near.md`, `deposit-ton.md`, `de","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 4 | **React Hooks** | `react-hooks.md` |","category":"external_commands","line_end":33,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 5 | **Advanced** | `intents-balance.md`, `passive-deposit.md` |","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Use `assetId` from /v0/tokens** - never construct manually","category":"external_commands","line_end":38,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **`dry: true`** = preview only, **`dry: false`** = get deposit address (valid ~10 min)","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Poll status** until terminal: `SUCCESS`, `FAILED`, `REFUNDED`, `INCOMPLETE_DEPOSIT`","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Chain-to-chain is default** - `depositType` and `recipientType` default to chain endpoints","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"network:SKILL.md:75:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Docs: https://docs.near-intents.org/near-intents/integration/distribution-channels/1click-api","category":"network","line_end":75,"severity":"low","line_start":75},{"id":"network:SKILL.md:76:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- API Keys: https://partners.near-intents.org/","category":"network","line_end":76,"severity":"low","line_start":76},{"id":"network:SKILL.md:77:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- OpenAPI: https://1click.chaindefuser.com/docs/v0/openapi.yaml","category":"network","line_end":77,"severity":"low","line_start":77},{"id":"blocker:SKILL.md:38:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. **`dry: true`** = preview only, **`dry: false`** = get deposit address (valid ~10 min)","category":"blocker","line_end":38,"severity":"low","line_start":38},{"id":"blocker:SKILL.md:50:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- [api-quote](rules/api-quote.md) - Get swap quote, dry=true for preview, dry=false for deposit addr","category":"blocker","line_end":51,"severity":"low","line_start":50}],"finding_verdicts":[{"id":"external_commands:references/concepts.md:50:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/concepts.md:47:system-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/concepts.md:17:network-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-any-input-withdrawals.md:11:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-any-input-withdrawals.md:12:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-any-input-withdrawals.md:58:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-any-input-withdrawals.md:59:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-any-input-withdrawals.md:62:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-any-input-withdrawals.md:67:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-any-input-withdrawals.md:70:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/api-any-input-withdrawals.md:10:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-any-input-withdrawals.md:57:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-any-input-withdrawals.md:11:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-any-input-withdrawals.md:58:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:rules/api-deposit-submit.md:14:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/api-deposit-submit.md:10:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-deposit-submit.md:33:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-deposit-submit.md:47:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-deposit-submit.md:10:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-deposit-submit.md:33:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-deposit-submit.md:47:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:160:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:181:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:208:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:230:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:160:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:181:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:208:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-quote.md:230:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"env_access:rules/api-quote.md:185:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"blocker:rules/api-quote.md:17:system-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:rules/api-quote.md:23:system-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:rules/api-quote.md:185:system-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-status.md:11:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-status.md:12:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-status.md:60:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/api-status.md:64:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/api-status.md:10:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-status.md:63:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-status.md:11:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-status.md:64:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-tokens.md:10:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/api-tokens.md:10:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:rules/deposit-evm.md:17:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/deposit-evm.md:31:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/deposit-evm.md:34:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/deposit-stellar.md:12:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/deposit-stellar.md:12:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/deposit-stellar.md:34:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"blocker:rules/deposit-ton.md:37:system-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/intents-balance.md:12:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/intents-balance.md:32:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/intents-balance.md:12:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/intents-balance.md:32:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/intents-balance.md:58:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/passive-deposit.md:11:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/passive-deposit.md:11:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:rules/react-hooks.md:26:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:45:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:49:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:68:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:69:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:90:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:94:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:103:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-hooks.md:105:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/react-hooks.md:26:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-hooks.md:45:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-hooks.md:68:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-hooks.md:90:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-hooks.md:103:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-hooks.md:20:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:rules/react-swap-widget.md:107:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:128:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:132:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:153:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:154:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:186:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:190:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:209:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:213:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:322:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:332:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:335:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:340:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:394:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:408:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/react-swap-widget.md:462:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/react-swap-widget.md:107:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-swap-widget.md:128:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-swap-widget.md:153:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-swap-widget.md:186:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-swap-widget.md:209:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/react-swap-widget.md:40:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"env_access:rules/react-swap-widget.md:485:environment-variable-access-dot-notation","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/react-swap-widget.md:485:environment-variable-object","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/react-swap-widget.md:485:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"sensitive:rules/react-swap-widget.md:485:environment-file-access","reason":"This is a documented wallet-signing or configuration example, not access to a local environment file or embedded secret. No private key value is included.","verdict":"false_positive","confidence":0.93},{"id":"blocker:rules/react-swap-widget.md:321:system-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:29:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:70:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:82:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:86:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:97:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:103:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:107:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:118:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:119:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:123:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:147:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:160:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:171:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:172:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:180:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:183:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:188:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:193:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:202:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:204:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:207:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:rules/server-example.md:221:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:rules/server-example.md:70:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/server-example.md:82:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/server-example.md:103:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/server-example.md:117:fetch-api-call","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/server-example.md:28:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/server-example.md:281:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"env_access:rules/server-example.md:29:environment-variable-access-dot-notation","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:30:environment-variable-access-dot-notation","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:29:environment-variable-object","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:30:environment-variable-object","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:29:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:30:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:86:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:107:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:119:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:150:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"env_access:rules/server-example.md:252:generic-api-secret-keys","reason":"The snippet documents explicit configuration variables for an API key or wallet key. It does not enumerate the environment or transmit secrets to an unrelated destination.","verdict":"false_positive","confidence":0.92},{"id":"sensitive:rules/server-example.md:29:environment-file-access","reason":"This is a documented wallet-signing or configuration example, not access to a local environment file or embedded secret. No private key value is included.","verdict":"false_positive","confidence":0.93},{"id":"sensitive:rules/server-example.md:30:environment-file-access","reason":"This is a documented wallet-signing or configuration example, not access to a local environment file or embedded secret. No private key value is included.","verdict":"false_positive","confidence":0.93},{"id":"sensitive:rules/server-example.md:21:crypto-seed-private-key-mention","reason":"This is a documented wallet-signing or configuration example, not access to a local environment file or embedded secret. No private key value is included.","verdict":"false_positive","confidence":0.93},{"id":"sensitive:rules/server-example.md:150:crypto-seed-private-key-mention","reason":"This is a documented wallet-signing or configuration example, not access to a local environment file or embedded secret. No private key value is included.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code fences, TypeScript template literals, or type syntax in documentation. No shell or Ruby command execution is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:75:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:76:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:77:hardcoded-url","reason":"This is a documented request or URL for the declared NEAR Intents and blockchain integration flow. The snippet does not show covert collection or exfiltration.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:38:system-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:50:network-reconnaissance","reason":"The match is ordinary API, blockchain, or status terminology and does not perform host or network reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Unattended live swap example can sign and transfer funds","severity":"high","locations":[{"file":"rules/server-example.md","line_end":30,"line_start":29},{"file":"rules/server-example.md","line_end":93,"line_start":89},{"file":"rules/server-example.md","line_end":190,"line_start":150}],"confidence":0.96,"description":"The server example obtains a committed quote, creates an account from a private key, and broadcasts a token or native-token deposit without an interactive approval step. Deploying this pattern without transaction controls can transfer funds after compromised or unintended input.","confidence_reasoning":"The documented flow explicitly creates a wallet account from an environment private key and calls contract transfer or native transaction methods after requesting a non-preview quote."}],"subject_marketplace_commit_sha":"3f6e026a3363e0954ede7bef0cfe88d4475de137","subject_content_hash":"37690f4537a952b1b0c1041f6b3842a522b5b61b65a8c7488dbe2c6f217f3214","subject_tree_hash":"5064979b684c98380a1d83799f48857176e363830efdee334d13135dba87b55a","subject_plugin_path":"skills/internet-court/near-intents","audit_payload_hash":"416c189c0815878dacb2e2ee960f1ef7","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"3f6e026a3363e0954ede7bef0cfe88d4475de137","contentHash":"37690f4537a952b1b0c1041f6b3842a522b5b61b65a8c7488dbe2c6f217f3214","treeHash":"5064979b684c98380a1d83799f48857176e363830efdee334d13135dba87b55a","pluginPath":"skills/internet-court/near-intents","auditPayloadHash":"416c189c0815878dacb2e2ee960f1ef7"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"unavailable","url":null,"status":null},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"unavailable","verificationState":"not_verified"},"isLatest":true}}