{"data":{"skill":{"slug":"jezweb-tanstack-query","name":"tanstack-query","icon":"📦","repo":"https://github.com/jezweb/claude-skills/tree/main/skills/tanstack-query/","status":"approved","author":"jezweb","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"4ab113e1-0284-437e-9068-d3b0129cec8f","skill_id":"4fa325e6-00cb-4303-aabb-ac8c62e0a382","version":3,"content_hash":"v2:a06681402992ceae98ba04d54cfd4ab004862696:6ca5722db5c77989f0023cd1c4a1032a415b34ec9a551fa5de55ec5237f607f9:2c02543f2fce33f236e836491234a105734ef4346e01b0b3c3a8ff9565c022ab:e7ffc38e12c2682da114426113766bfb","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are false positives caused by Markdown backticks, TypeScript template literals, local API examples, and React identifiers. Confirmed issues are low-risk external demo API calls in copy-ready templates, plus medium-risk semantic concerns around production DevTools exposure and visible stack traces.","remediation":[{"issue":"Production DevTools example lacks an enforced auth gate.","severity":"medium","suggestion":"Wrap production DevTools behind role-based authentication and a server-controlled feature flag, or remove the production example from copy-ready templates."},{"issue":"Default error boundary can expose stack traces to users.","severity":"medium","suggestion":"Show generic production errors in the UI and send stack traces only to a trusted error reporting service."},{"issue":"Copy-ready templates use public demo API endpoints.","severity":"low","suggestion":"Use placeholder base URLs or local mock handlers, and clearly require endpoint replacement before using real data."},{"issue":"Placeholder shell script ships with the skill.","severity":"low","suggestion":"Remove the unused script or document that it is nonfunctional, so installers do not see an unnecessary executable artifact."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"README.md","line_end":159,"line_start":159},{"file":"references/common-patterns.md","line_end":177,"line_start":177},{"file":"references/testing.md","line_end":97,"line_start":97},{"file":"references/testing.md","line_end":120,"line_start":120},{"file":"references/top-errors.md","line_end":282,"line_start":282},{"file":"references/typescript-patterns.md","line_end":20,"line_start":20},{"file":"references/typescript-patterns.md","line_end":39,"line_start":39},{"file":"references/typescript-patterns.md","line_end":58,"line_start":58},{"file":"references/typescript-patterns.md","line_end":88,"line_start":88},{"file":"references/typescript-patterns.md","line_end":118,"line_start":118},{"file":"references/typescript-patterns.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":246,"line_start":246},{"file":"SKILL.md","line_end":260,"line_start":260},{"file":"SKILL.md","line_end":662,"line_start":662},{"file":"SKILL.md","line_end":1044,"line_start":1044},{"file":"SKILL.md","line_end":444,"line_start":444},{"file":"SKILL.md","line_end":464,"line_start":464},{"file":"SKILL.md","line_end":491,"line_start":491},{"file":"SKILL.md","line_end":510,"line_start":510},{"file":"SKILL.md","line_end":534,"line_start":534},{"file":"SKILL.md","line_end":569,"line_start":569},{"file":"SKILL.md","line_end":594,"line_start":594},{"file":"SKILL.md","line_end":620,"line_start":620},{"file":"SKILL.md","line_end":660,"line_start":660},{"file":"SKILL.md","line_end":689,"line_start":689},{"file":"SKILL.md","line_end":721,"line_start":721},{"file":"SKILL.md","line_end":752,"line_start":752},{"file":"SKILL.md","line_end":788,"line_start":788},{"file":"SKILL.md","line_end":823,"line_start":823},{"file":"SKILL.md","line_end":857,"line_start":857},{"file":"SKILL.md","line_end":896,"line_start":896},{"file":"SKILL.md","line_end":925,"line_start":925},{"file":"SKILL.md","line_end":965,"line_start":965},{"file":"SKILL.md","line_end":1058,"line_start":1058},{"file":"templates/custom-hooks-pattern.tsx","line_end":22,"line_start":22},{"file":"templates/custom-hooks-pattern.tsx","line_end":28,"line_start":28},{"file":"templates/custom-hooks-pattern.tsx","line_end":34,"line_start":34},{"file":"templates/custom-hooks-pattern.tsx","line_end":44,"line_start":44},{"file":"templates/custom-hooks-pattern.tsx","line_end":54,"line_start":54},{"file":"templates/custom-hooks-pattern.tsx","line_end":22,"line_start":22},{"file":"templates/custom-hooks-pattern.tsx","line_end":28,"line_start":28},{"file":"templates/custom-hooks-pattern.tsx","line_end":34,"line_start":34},{"file":"templates/custom-hooks-pattern.tsx","line_end":44,"line_start":44},{"file":"templates/custom-hooks-pattern.tsx","line_end":54,"line_start":54},{"file":"templates/error-boundary.tsx","line_end":171,"line_start":171},{"file":"templates/error-boundary.tsx","line_end":186,"line_start":186},{"file":"templates/use-infinite-query.tsx","line_end":25,"line_start":25},{"file":"templates/use-infinite-query.tsx","line_end":26,"line_start":26},{"file":"templates/use-mutation-basic.tsx","line_end":23,"line_start":23},{"file":"templates/use-mutation-basic.tsx","line_end":37,"line_start":37},{"file":"templates/use-mutation-basic.tsx","line_end":54,"line_start":54},{"file":"templates/use-mutation-basic.tsx","line_end":23,"line_start":23},{"file":"templates/use-mutation-basic.tsx","line_end":38,"line_start":38},{"file":"templates/use-mutation-basic.tsx","line_end":55,"line_start":55},{"file":"templates/use-mutation-optimistic.tsx","line_end":40,"line_start":40},{"file":"templates/use-mutation-optimistic.tsx","line_end":104,"line_start":104},{"file":"templates/use-mutation-optimistic.tsx","line_end":157,"line_start":157},{"file":"templates/use-mutation-optimistic.tsx","line_end":41,"line_start":41},{"file":"templates/use-mutation-optimistic.tsx","line_end":105,"line_start":105},{"file":"templates/use-mutation-optimistic.tsx","line_end":158,"line_start":158},{"file":"templates/use-query-basic.tsx","line_end":18,"line_start":18},{"file":"templates/use-query-basic.tsx","line_end":55,"line_start":55},{"file":"templates/use-query-basic.tsx","line_end":18,"line_start":18},{"file":"templates/use-query-basic.tsx","line_end":56,"line_start":56}]},{"factor":"external_commands","evidence":[{"file":"references/best-practices.md","line_end":211,"line_start":205},{"file":"references/common-patterns.md","line_end":159,"line_start":153},{"file":"references/common-patterns.md","line_end":181,"line_start":177},{"file":"references/top-errors.md","line_end":291,"line_start":284},{"file":"references/typescript-patterns.md","line_end":48,"line_start":39},{"file":"scripts/example-script.sh","line_end":1,"line_start":1},{"file":"SKILL.md","line_end":42,"line_start":24},{"file":"SKILL.md","line_end":46,"line_start":42},{"file":"SKILL.md","line_end":48,"line_start":46},{"file":"SKILL.md","line_end":71,"line_start":48},{"file":"SKILL.md","line_end":76,"line_start":71},{"file":"SKILL.md","line_end":80,"line_start":76},{"file":"SKILL.md","line_end":82,"line_start":80},{"file":"SKILL.md","line_end":110,"line_start":82},{"file":"SKILL.md","line_end":116,"line_start":110},{"file":"SKILL.md","line_end":131,"line_start":116},{"file":"SKILL.md","line_end":135,"line_start":131},{"file":"SKILL.md","line_end":136,"line_start":135},{"file":"SKILL.md","line_end":137,"line_start":136},{"file":"SKILL.md","line_end":140,"line_start":137},{"file":"SKILL.md","line_end":143,"line_start":140},{"file":"SKILL.md","line_end":149,"line_start":143},{"file":"SKILL.md","line_end":165,"line_start":149},{"file":"SKILL.md","line_end":169,"line_start":165},{"file":"SKILL.md","line_end":171,"line_start":169},{"file":"SKILL.md","line_end":185,"line_start":171},{"file":"SKILL.md","line_end":191,"line_start":185},{"file":"SKILL.md","line_end":200,"line_start":191},{"file":"SKILL.md","line_end":202,"line_start":200},{"file":"SKILL.md","line_end":202,"line_start":202},{"file":"SKILL.md","line_end":211,"line_start":208},{"file":"SKILL.md","line_end":215,"line_start":211},{"file":"SKILL.md","line_end":234,"line_start":215},{"file":"SKILL.md","line_end":238,"line_start":234},{"file":"SKILL.md","line_end":283,"line_start":238},{"file":"SKILL.md","line_end":292,"line_start":283},{"file":"SKILL.md","line_end":296,"line_start":292},{"file":"SKILL.md","line_end":299,"line_start":296},{"file":"SKILL.md","line_end":303,"line_start":299},{"file":"SKILL.md","line_end":306,"line_start":303},{"file":"SKILL.md","line_end":308,"line_start":306},{"file":"SKILL.md","line_end":311,"line_start":308},{"file":"SKILL.md","line_end":314,"line_start":311},{"file":"SKILL.md","line_end":317,"line_start":314},{"file":"SKILL.md","line_end":319,"line_start":317},{"file":"SKILL.md","line_end":322,"line_start":319},{"file":"SKILL.md","line_end":326,"line_start":322},{"file":"SKILL.md","line_end":329,"line_start":326},{"file":"SKILL.md","line_end":334,"line_start":329},{"file":"SKILL.md","line_end":337,"line_start":334},{"file":"SKILL.md","line_end":339,"line_start":337},{"file":"SKILL.md","line_end":344,"line_start":339},{"file":"SKILL.md","line_end":350,"line_start":344},{"file":"SKILL.md","line_end":353,"line_start":350},{"file":"SKILL.md","line_end":374,"line_start":353},{"file":"SKILL.md","line_end":377,"line_start":374},{"file":"SKILL.md","line_end":384,"line_start":377},{"file":"SKILL.md","line_end":387,"line_start":384},{"file":"SKILL.md","line_end":391,"line_start":387},{"file":"SKILL.md","line_end":394,"line_start":391},{"file":"SKILL.md","line_end":402,"line_start":394},{"file":"SKILL.md","line_end":405,"line_start":402},{"file":"SKILL.md","line_end":415,"line_start":405},{"file":"SKILL.md","line_end":418,"line_start":415},{"file":"SKILL.md","line_end":434,"line_start":418},{"file":"SKILL.md","line_end":443,"line_start":434},{"file":"SKILL.md","line_end":446,"line_start":443},{"file":"SKILL.md","line_end":449,"line_start":446},{"file":"SKILL.md","line_end":451,"line_start":449},{"file":"SKILL.md","line_end":454,"line_start":451},{"file":"SKILL.md","line_end":460,"line_start":454},{"file":"SKILL.md","line_end":466,"line_start":460},{"file":"SKILL.md","line_end":469,"line_start":466},{"file":"SKILL.md","line_end":477,"line_start":469},{"file":"SKILL.md","line_end":480,"line_start":477},{"file":"SKILL.md","line_end":487,"line_start":480},{"file":"SKILL.md","line_end":492,"line_start":487},{"file":"SKILL.md","line_end":492,"line_start":492},{"file":"SKILL.md","line_end":493,"line_start":493},{"file":"SKILL.md","line_end":499,"line_start":496},{"file":"SKILL.md","line_end":502,"line_start":499},{"file":"SKILL.md","line_end":506,"line_start":502},{"file":"SKILL.md","line_end":509,"line_start":506},{"file":"SKILL.md","line_end":512,"line_start":509},{"file":"SKILL.md","line_end":512,"line_start":512},{"file":"SKILL.md","line_end":521,"line_start":515},{"file":"SKILL.md","line_end":524,"line_start":521},{"file":"SKILL.md","line_end":530,"line_start":524},{"file":"SKILL.md","line_end":536,"line_start":530},{"file":"SKILL.md","line_end":539,"line_start":536},{"file":"SKILL.md","line_end":545,"line_start":539},{"file":"SKILL.md","line_end":548,"line_start":545},{"file":"SKILL.md","line_end":565,"line_start":548},{"file":"SKILL.md","line_end":568,"line_start":565},{"file":"SKILL.md","line_end":570,"line_start":568},{"file":"SKILL.md","line_end":571,"line_start":570},{"file":"SKILL.md","line_end":574,"line_start":571},{"file":"SKILL.md","line_end":580,"line_start":574},{"file":"SKILL.md","line_end":583,"line_start":580},{"file":"SKILL.md","line_end":590,"line_start":583},{"file":"SKILL.md","line_end":593,"line_start":590},{"file":"SKILL.md","line_end":595,"line_start":593},{"file":"SKILL.md","line_end":596,"line_start":595},{"file":"SKILL.md","line_end":599,"line_start":596},{"file":"SKILL.md","line_end":605,"line_start":599},{"file":"SKILL.md","line_end":608,"line_start":605},{"file":"SKILL.md","line_end":616,"line_start":608},{"file":"SKILL.md","line_end":621,"line_start":616},{"file":"SKILL.md","line_end":621,"line_start":621},{"file":"SKILL.md","line_end":634,"line_start":625},{"file":"SKILL.md","line_end":637,"line_start":634},{"file":"SKILL.md","line_end":656,"line_start":637},{"file":"SKILL.md","line_end":659,"line_start":656},{"file":"SKILL.md","line_end":662,"line_start":659},{"file":"SKILL.md","line_end":662,"line_start":662},{"file":"SKILL.md","line_end":663,"line_start":663},{"file":"SKILL.md","line_end":673,"line_start":666},{"file":"SKILL.md","line_end":676,"line_start":673},{"file":"SKILL.md","line_end":683,"line_start":676},{"file":"SKILL.md","line_end":685,"line_start":683},{"file":"SKILL.md","line_end":691,"line_start":685},{"file":"SKILL.md","line_end":692,"line_start":691},{"file":"SKILL.md","line_end":692,"line_start":692},{"file":"SKILL.md","line_end":706,"line_start":695},{"file":"SKILL.md","line_end":709,"line_start":706},{"file":"SKILL.md","line_end":715,"line_start":709},{"file":"SKILL.md","line_end":717,"line_start":715},{"file":"SKILL.md","line_end":720,"line_start":717},{"file":"SKILL.md","line_end":724,"line_start":720},{"file":"SKILL.md","line_end":724,"line_start":724},{"file":"SKILL.md","line_end":735,"line_start":727},{"file":"SKILL.md","line_end":738,"line_start":735},{"file":"SKILL.md","line_end":746,"line_start":738},{"file":"SKILL.md","line_end":748,"line_start":746},{"file":"SKILL.md","line_end":754,"line_start":748},{"file":"SKILL.md","line_end":754,"line_start":754},{"file":"SKILL.md","line_end":768,"line_start":758},{"file":"SKILL.md","line_end":771,"line_start":768},{"file":"SKILL.md","line_end":782,"line_start":771},{"file":"SKILL.md","line_end":784,"line_start":782},{"file":"SKILL.md","line_end":784,"line_start":784},{"file":"SKILL.md","line_end":790,"line_start":787},{"file":"SKILL.md","line_end":794,"line_start":790},{"file":"SKILL.md","line_end":809,"line_start":794},{"file":"SKILL.md","line_end":812,"line_start":809},{"file":"SKILL.md","line_end":817,"line_start":812},{"file":"SKILL.md","line_end":819,"line_start":817},{"file":"SKILL.md","line_end":822,"line_start":819},{"file":"SKILL.md","line_end":822,"line_start":822},{"file":"SKILL.md","line_end":826,"line_start":825},{"file":"SKILL.md","line_end":829,"line_start":826},{"file":"SKILL.md","line_end":841,"line_start":829},{"file":"SKILL.md","line_end":844,"line_start":841},{"file":"SKILL.md","line_end":851,"line_start":844},{"file":"SKILL.md","line_end":856,"line_start":851},{"file":"SKILL.md","line_end":856,"line_start":856},{"file":"SKILL.md","line_end":859,"line_start":859},{"file":"SKILL.md","line_end":880,"line_start":863},{"file":"SKILL.md","line_end":883,"line_start":880},{"file":"SKILL.md","line_end":890,"line_start":883},{"file":"SKILL.md","line_end":895,"line_start":890},{"file":"SKILL.md","line_end":898,"line_start":895},{"file":"SKILL.md","line_end":899,"line_start":898},{"file":"SKILL.md","line_end":902,"line_start":899},{"file":"SKILL.md","line_end":905,"line_start":902},{"file":"SKILL.md","line_end":908,"line_start":905},{"file":"SKILL.md","line_end":913,"line_start":908},{"file":"SKILL.md","line_end":928,"line_start":913},{"file":"SKILL.md","line_end":931,"line_start":928},{"file":"SKILL.md","line_end":949,"line_start":931},{"file":"SKILL.md","line_end":952,"line_start":949},{"file":"SKILL.md","line_end":961,"line_start":952},{"file":"SKILL.md","line_end":967,"line_start":961},{"file":"SKILL.md","line_end":970,"line_start":967},{"file":"SKILL.md","line_end":980,"line_start":970},{"file":"SKILL.md","line_end":983,"line_start":980},{"file":"SKILL.md","line_end":993,"line_start":983},{"file":"SKILL.md","line_end":996,"line_start":993},{"file":"SKILL.md","line_end":1004,"line_start":996},{"file":"SKILL.md","line_end":1011,"line_start":1004},{"file":"SKILL.md","line_end":1017,"line_start":1011},{"file":"SKILL.md","line_end":1020,"line_start":1017},{"file":"SKILL.md","line_end":1024,"line_start":1020},{"file":"SKILL.md","line_end":1027,"line_start":1024},{"file":"SKILL.md","line_end":1029,"line_start":1027},{"file":"SKILL.md","line_end":1032,"line_start":1029},{"file":"SKILL.md","line_end":1039,"line_start":1032},{"file":"SKILL.md","line_end":1042,"line_start":1039},{"file":"SKILL.md","line_end":1044,"line_start":1042},{"file":"SKILL.md","line_end":1047,"line_start":1044},{"file":"SKILL.md","line_end":1050,"line_start":1047},{"file":"SKILL.md","line_end":1052,"line_start":1050},{"file":"SKILL.md","line_end":1058,"line_start":1052},{"file":"templates/custom-hooks-pattern.tsx","line_end":28,"line_start":28},{"file":"templates/custom-hooks-pattern.tsx","line_end":29,"line_start":29},{"file":"templates/custom-hooks-pattern.tsx","line_end":44,"line_start":44},{"file":"templates/custom-hooks-pattern.tsx","line_end":54,"line_start":54},{"file":"templates/custom-hooks-pattern.tsx","line_end":199,"line_start":199},{"file":"templates/error-boundary.tsx","line_end":171,"line_start":171},{"file":"templates/error-boundary.tsx","line_end":186,"line_start":186},{"file":"templates/error-boundary.tsx","line_end":187,"line_start":187},{"file":"templates/use-infinite-query.tsx","line_end":26,"line_start":26},{"file":"templates/use-mutation-basic.tsx","line_end":30,"line_start":30},{"file":"templates/use-mutation-basic.tsx","line_end":38,"line_start":38},{"file":"templates/use-mutation-basic.tsx","line_end":47,"line_start":47},{"file":"templates/use-mutation-basic.tsx","line_end":55,"line_start":55},{"file":"templates/use-mutation-basic.tsx","line_end":62,"line_start":62},{"file":"templates/use-mutation-optimistic.tsx","line_end":105,"line_start":105},{"file":"templates/use-mutation-optimistic.tsx","line_end":158,"line_start":158},{"file":"templates/use-query-basic.tsx","line_end":21,"line_start":21},{"file":"templates/use-query-basic.tsx","line_end":56,"line_start":56},{"file":"templates/use-query-basic.tsx","line_end":60,"line_start":60}]},{"factor":"scripts","evidence":[{"file":"templates/devtools-setup.tsx","line_end":188,"line_start":188}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Production DevTools Can Expose Cache Data","locations":[{"file":"templates/devtools-setup.tsx","line_end":198,"line_start":173}],"confidence":0.82,"description":"The production DevTools example loads and renders React Query DevTools when a local showDevTools flag is true, but the sample does not enforce authentication. Query cache data can include user records, tokens, or API responses if copied into production.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The file explicitly labels the section as production DevTools and renders the component from a local toggle only. The same file later warns not to ship production DevTools without authentication."},{"title":"Error Boundary Displays Stack Traces","locations":[{"file":"templates/error-boundary.tsx","line_end":76,"line_start":70}],"confidence":0.86,"description":"The default fallback renders error.message and error.stack in the page. Production users could see implementation details if this template is copied without an environment guard.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The code directly renders error details and the stack trace inside the visible fallback UI. This is useful during development but can leak internal details in production."}],"low_findings":[{"title":"Fetch API call","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":22,"line_start":22}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/users')","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":28,"line_start":28}],"confidence":0.76,"description":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`)","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":34,"line_start":34}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/users', {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":44,"line_start":44}],"confidence":0.76,"description":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":54,"line_start":54}],"confidence":0.76,"description":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":22,"line_start":22}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/users')","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":28,"line_start":28}],"confidence":0.76,"description":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`)","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":34,"line_start":34}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/users', {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":44,"line_start":44}],"confidence":0.76,"description":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/custom-hooks-pattern.tsx","line_end":54,"line_start":54}],"confidence":0.76,"description":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-infinite-query.tsx","line_end":25,"line_start":25}],"confidence":0.76,"description":"const response = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-infinite-query.tsx","line_end":26,"line_start":26}],"confidence":0.76,"description":"`https://jsonplaceholder.typicode.com/todos?_start=${start}&_limit=${limit}`","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-mutation-basic.tsx","line_end":23,"line_start":23}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/todos', {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-mutation-basic.tsx","line_end":37,"line_start":37}],"confidence":0.76,"description":"const response = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-mutation-basic.tsx","line_end":54,"line_start":54}],"confidence":0.76,"description":"const response = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-mutation-basic.tsx","line_end":23,"line_start":23}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/todos', {","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-mutation-basic.tsx","line_end":38,"line_start":38}],"confidence":0.76,"description":"`https://jsonplaceholder.typicode.com/todos/${id}`,","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-mutation-basic.tsx","line_end":55,"line_start":55}],"confidence":0.76,"description":"`https://jsonplaceholder.typicode.com/todos/${id}`,","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-mutation-optimistic.tsx","line_end":40,"line_start":40}],"confidence":0.76,"description":"const response = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-mutation-optimistic.tsx","line_end":104,"line_start":104}],"confidence":0.76,"description":"const response = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-mutation-optimistic.tsx","line_end":157,"line_start":157}],"confidence":0.76,"description":"const response = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-mutation-optimistic.tsx","line_end":41,"line_start":41}],"confidence":0.76,"description":"'https://jsonplaceholder.typicode.com/todos',","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-mutation-optimistic.tsx","line_end":105,"line_start":105}],"confidence":0.76,"description":"`https://jsonplaceholder.typicode.com/todos/${id}`,","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-mutation-optimistic.tsx","line_end":158,"line_start":158}],"confidence":0.76,"description":"`https://jsonplaceholder.typicode.com/todos/${id}`,","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-query-basic.tsx","line_end":18,"line_start":18}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/todos')","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Fetch API call","locations":[{"file":"templates/use-query-basic.tsx","line_end":55,"line_start":55}],"confidence":0.76,"description":"const response = await fetch(","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-query-basic.tsx","line_end":18,"line_start":18}],"confidence":0.76,"description":"const response = await fetch('https://jsonplaceholder.typicode.com/todos')","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."},{"title":"Hardcoded URL","locations":[{"file":"templates/use-query-basic.tsx","line_end":56,"line_start":56}],"confidence":0.76,"description":"`https://jsonplaceholder.typicode.com/todos/${id}`","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged."}],"dangerous_patterns":[],"files_scanned":22,"total_lines":4893,"audit_model":"codex","audited_at":"2026-07-06T15:01:22.611+00:00","created_at":"2026-07-06T17:32:45.462899+00:00","static_findings":[{"id":"network:README.md:159:http-client-library","file":"README.md","pattern":"HTTP client library","snippet":"- axios (optional) - HTTP client alternative","category":"network","line_end":159,"severity":"low","line_start":159},{"id":"external_commands:references/best-practices.md:205:ruby-shell-backtick-execution","file":"references/best-practices.md","pattern":"Ruby/shell backtick execution","snippet":"<Link to={`/todos/${todo.id}`}>{todo.title}</Link>","category":"external_commands","line_end":211,"severity":"medium","line_start":205},{"id":"blocker:references/best-practices.md:7:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"## 1. Avoid Request Waterfalls","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"blocker:references/best-practices.md:45:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"queryKey: ['posts', userId], // Use userId, not user.id","category":"blocker","line_end":46,"severity":"low","line_start":45},{"id":"blocker:references/best-practices.md:221:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"Avoid for:","category":"blocker","line_end":221,"severity":"low","line_start":221},{"id":"external_commands:references/common-patterns.md:153:ruby-shell-backtick-execution","file":"references/common-patterns.md","pattern":"Ruby/shell backtick execution","snippet":"<Link to={`/todos/${todo.id}`}>{todo.title}</Link>","category":"external_commands","line_end":159,"severity":"medium","line_start":153},{"id":"external_commands:references/common-patterns.md:177:ruby-shell-backtick-execution","file":"references/common-patterns.md","pattern":"Ruby/shell backtick execution","snippet":"fetch(`/api/search?q=${deferredSearch}`, { signal }).then(r => r.json()),","category":"external_commands","line_end":181,"severity":"medium","line_start":177},{"id":"network:references/common-patterns.md:177:fetch-api-call","file":"references/common-patterns.md","pattern":"Fetch API call","snippet":"fetch(`/api/search?q=${deferredSearch}`, { signal }).then(r => r.json()),","category":"network","line_end":177,"severity":"low","line_start":177},{"id":"blocker:references/common-patterns.md:35:system-reconnaissance","file":"references/common-patterns.md","pattern":"System reconnaissance","snippet":"queries: ids.map(id => ({","category":"blocker","line_end":35,"severity":"low","line_start":35},{"id":"blocker:references/common-patterns.md:117:system-reconnaissance","file":"references/common-patterns.md","pattern":"System reconnaissance","snippet":"old.map(todo => todo.id === updated.id ? updated : todo)","category":"blocker","line_end":117,"severity":"low","line_start":117},{"id":"blocker:references/common-patterns.md:225:system-reconnaissance","file":"references/common-patterns.md","pattern":"System reconnaissance","snippet":"?.find(t => t.id === id)","category":"blocker","line_end":225,"severity":"low","line_start":225},{"id":"network:references/testing.md:97:http-https-get","file":"references/testing.md","pattern":"HTTP/HTTPS get","snippet":"http.get('/api/todos', () => {","category":"network","line_end":97,"severity":"low","line_start":97},{"id":"network:references/testing.md:120:http-https-get","file":"references/testing.md","pattern":"HTTP/HTTPS get","snippet":"http.get('/api/todos', () => {","category":"network","line_end":120,"severity":"low","line_start":120},{"id":"external_commands:references/top-errors.md:284:ruby-shell-backtick-execution","file":"references/top-errors.md","pattern":"Ruby/shell backtick execution","snippet":"throw new Error(`HTTP ${response.status}`) // ✅ Throw errors","category":"external_commands","line_end":291,"severity":"medium","line_start":284},{"id":"network:references/top-errors.md:282:fetch-api-call","file":"references/top-errors.md","pattern":"Fetch API call","snippet":"const response = await fetch('/api/todos')","category":"network","line_end":282,"severity":"low","line_start":282},{"id":"blocker:references/top-errors.md:127:system-reconnaissance","file":"references/top-errors.md","pattern":"System reconnaissance","snippet":"{id ? <TodoComponent id={id} /> : <div>No ID</div>}","category":"blocker","line_end":127,"severity":"low","line_start":127},{"id":"external_commands:references/typescript-patterns.md:39:ruby-shell-backtick-execution","file":"references/typescript-patterns.md","pattern":"Ruby/shell backtick execution","snippet":"const response = await fetch(`/api/${endpoint}/${id}`)","category":"external_commands","line_end":48,"severity":"medium","line_start":39},{"id":"network:references/typescript-patterns.md:20:fetch-api-call","file":"references/typescript-patterns.md","pattern":"Fetch API call","snippet":"const response = await fetch('/api/todos')","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:references/typescript-patterns.md:39:fetch-api-call","file":"references/typescript-patterns.md","pattern":"Fetch API call","snippet":"const response = await fetch(`/api/${endpoint}/${id}`)","category":"network","line_end":39,"severity":"low","line_start":39},{"id":"network:references/typescript-patterns.md:58:fetch-api-call","file":"references/typescript-patterns.md","pattern":"Fetch API call","snippet":"const response = await fetch('/api/todos')","category":"network","line_end":58,"severity":"low","line_start":58},{"id":"network:references/typescript-patterns.md:88:fetch-api-call","file":"references/typescript-patterns.md","pattern":"Fetch API call","snippet":"const response = await fetch('/api/todos', {","category":"network","line_end":88,"severity":"low","line_start":88},{"id":"network:references/typescript-patterns.md:118:fetch-api-call","file":"references/typescript-patterns.md","pattern":"Fetch API call","snippet":"const response = await fetch('/api/todos')","category":"network","line_end":118,"severity":"low","line_start":118},{"id":"network:references/typescript-patterns.md:153:fetch-api-call","file":"references/typescript-patterns.md","pattern":"Fetch API call","snippet":"const response = await fetch('/api/todos')","category":"network","line_end":153,"severity":"low","line_start":153},{"id":"external_commands:scripts/example-script.sh:1:unix-shell-invocation","file":"scripts/example-script.sh","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":1,"severity":"medium","line_start":1},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":42,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":46,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"New pattern using `variables` - no cache manipulation, no rollback needed:","category":"external_commands","line_end":48,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":71,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"<li key={`pending-${i}`} style={{ opacity: 0.5 }}>{todo.title}</li>","category":"external_commands","line_end":76,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":80,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Renamed from `useErrorBoundary` (breaking change):","category":"external_commands","line_end":82,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":110,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":116,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":131,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":135,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `online` (default) | Only fetch when online |","category":"external_commands","line_end":136,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `always` | Always try (useful for local/service worker APIs) |","category":"external_commands","line_end":137,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `offlineFirst` | Use cache first, fetch when online |","category":"external_commands","line_end":140,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":143,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":149,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":165,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":169,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Type-safe factory for infinite queries (parallel to `queryOptions`):","category":"external_commands","line_end":171,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":185,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":191,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":200,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":202,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Note:** `maxPages` requires bi-directional pagination (`getNextPageParam` AND `getPreviousPagePara","category":"external_commands","line_end":202,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":211,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":215,"severity":"medium","line_start":211},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":234,"severity":"medium","line_start":215},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":238,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":283,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":292,"severity":"medium","line_start":283},{"id":"external_commands:SKILL.md:292:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":296,"severity":"medium","line_start":292},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":299,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":303,"severity":"medium","line_start":299},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":306,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":308,"severity":"medium","line_start":306},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":311,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":314,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":317,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":319,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":322,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":326,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":329,"severity":"medium","line_start":326},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":334,"severity":"medium","line_start":329},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":337,"severity":"medium","line_start":334},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":339,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":344,"severity":"medium","line_start":339},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":350,"severity":"medium","line_start":344},{"id":"external_commands:SKILL.md:350:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":353,"severity":"medium","line_start":350},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":374,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":377,"severity":"medium","line_start":374},{"id":"external_commands:SKILL.md:377:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":384,"severity":"medium","line_start":377},{"id":"external_commands:SKILL.md:384:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":387,"severity":"medium","line_start":384},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":391,"severity":"medium","line_start":387},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":394,"severity":"medium","line_start":391},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":402,"severity":"medium","line_start":394},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":405,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:405:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":415,"severity":"medium","line_start":405},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":418,"severity":"medium","line_start":415},{"id":"external_commands:SKILL.md:418:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":434,"severity":"medium","line_start":418},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":443,"severity":"medium","line_start":434},{"id":"external_commands:SKILL.md:443:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `useQuery is not a function` or type errors","category":"external_commands","line_end":446,"severity":"medium","line_start":443},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Always use `useQuery({ queryKey, queryFn, ...options })`","category":"external_commands","line_end":449,"severity":"medium","line_start":446},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":451,"severity":"medium","line_start":449},{"id":"external_commands:SKILL.md:451:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":454,"severity":"medium","line_start":451},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":460,"severity":"medium","line_start":454},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":466,"severity":"medium","line_start":460},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use `useEffect` for side effects, or move logic to mutation callbacks","category":"external_commands","line_end":469,"severity":"medium","line_start":466},{"id":"external_commands:SKILL.md:469:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":477,"severity":"medium","line_start":469},{"id":"external_commands:SKILL.md:477:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":480,"severity":"medium","line_start":477},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":487,"severity":"medium","line_start":480},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":492,"severity":"medium","line_start":487},{"id":"external_commands:SKILL.md:492:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: `status: 'loading'` renamed to `status: 'pending'`, `isLoading` meaning changed","category":"external_commands","line_end":492,"severity":"medium","line_start":492},{"id":"external_commands:SKILL.md:493:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use `isPending` for initial load, `isLoading` for \"pending AND fetching\"","category":"external_commands","line_end":493,"severity":"medium","line_start":493},{"id":"external_commands:SKILL.md:496:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":499,"severity":"medium","line_start":496},{"id":"external_commands:SKILL.md:499:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":502,"severity":"medium","line_start":499},{"id":"external_commands:SKILL.md:502:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":506,"severity":"medium","line_start":502},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":509,"severity":"medium","line_start":506},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `cacheTime is not a valid option`","category":"external_commands","line_end":512,"severity":"medium","line_start":509},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use `gcTime` instead of `cacheTime`","category":"external_commands","line_end":512,"severity":"medium","line_start":512},{"id":"external_commands:SKILL.md:515:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":521,"severity":"medium","line_start":515},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":524,"severity":"medium","line_start":521},{"id":"external_commands:SKILL.md:524:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":530,"severity":"medium","line_start":524},{"id":"external_commands:SKILL.md:530:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":536,"severity":"medium","line_start":530},{"id":"external_commands:SKILL.md:536:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use conditional rendering instead of `enabled` option","category":"external_commands","line_end":539,"severity":"medium","line_start":536},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":545,"severity":"medium","line_start":539},{"id":"external_commands:SKILL.md:545:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":548,"severity":"medium","line_start":545},{"id":"external_commands:SKILL.md:548:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":565,"severity":"medium","line_start":548},{"id":"external_commands:SKILL.md:565:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":568,"severity":"medium","line_start":565},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `initialPageParam is required` type error","category":"external_commands","line_end":570,"severity":"medium","line_start":568},{"id":"external_commands:SKILL.md:570:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: v4 passed `undefined` as first pageParam, v5 requires explicit value","category":"external_commands","line_end":571,"severity":"medium","line_start":570},{"id":"external_commands:SKILL.md:571:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Always specify `initialPageParam` for infinite queries","category":"external_commands","line_end":574,"severity":"medium","line_start":571},{"id":"external_commands:SKILL.md:574:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":580,"severity":"medium","line_start":574},{"id":"external_commands:SKILL.md:580:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":583,"severity":"medium","line_start":580},{"id":"external_commands:SKILL.md:583:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":590,"severity":"medium","line_start":583},{"id":"external_commands:SKILL.md:590:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":593,"severity":"medium","line_start":590},{"id":"external_commands:SKILL.md:593:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `keepPreviousData is not a valid option`","category":"external_commands","line_end":595,"severity":"medium","line_start":593},{"id":"external_commands:SKILL.md:595:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: Replaced with more flexible `placeholderData` function","category":"external_commands","line_end":596,"severity":"medium","line_start":595},{"id":"external_commands:SKILL.md:596:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use `placeholderData: keepPreviousData` helper","category":"external_commands","line_end":599,"severity":"medium","line_start":596},{"id":"external_commands:SKILL.md:599:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":605,"severity":"medium","line_start":599},{"id":"external_commands:SKILL.md:605:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":608,"severity":"medium","line_start":605},{"id":"external_commands:SKILL.md:608:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":616,"severity":"medium","line_start":608},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":621,"severity":"medium","line_start":616},{"id":"external_commands:SKILL.md:621:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: v4 used `unknown`, v5 defaults to `Error` type","category":"external_commands","line_end":621,"severity":"medium","line_start":621},{"id":"external_commands:SKILL.md:625:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":634,"severity":"medium","line_start":625},{"id":"external_commands:SKILL.md:634:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":637,"severity":"medium","line_start":634},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":656,"severity":"medium","line_start":637},{"id":"external_commands:SKILL.md:656:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":659,"severity":"medium","line_start":656},{"id":"external_commands:SKILL.md:659:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `Hydration failed because the initial UI does not match what was rendered on the server`","category":"external_commands","line_end":662,"severity":"medium","line_start":659},{"id":"external_commands:SKILL.md:662:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: Race condition where `hydrate()` resolves synchronously but `query.fetch()` crea","category":"external_commands","line_end":662,"severity":"medium","line_start":662},{"id":"external_commands:SKILL.md:663:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Don't conditionally render based on `fetchStatus` with `useSuspenseQuery` and stream","category":"external_commands","line_end":663,"severity":"medium","line_start":663},{"id":"external_commands:SKILL.md:666:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":673,"severity":"medium","line_start":666},{"id":"external_commands:SKILL.md:673:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":676,"severity":"medium","line_start":673},{"id":"external_commands:SKILL.md:676:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":683,"severity":"medium","line_start":676},{"id":"external_commands:SKILL.md:683:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":685,"severity":"medium","line_start":683},{"id":"external_commands:SKILL.md:685:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Status**: Known issue, being investigated by maintainers. Requires implementation of `getServerSna","category":"external_commands","line_end":691,"severity":"medium","line_start":685},{"id":"external_commands:SKILL.md:691:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: `tryResolveSync` detects resolved promises in RSC payload and extracts data sync","category":"external_commands","line_end":692,"severity":"medium","line_start":691},{"id":"external_commands:SKILL.md:692:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use `useSuspenseQuery` instead of `useQuery` for SSR, or avoid conditional rendering","category":"external_commands","line_end":692,"severity":"medium","line_start":692},{"id":"external_commands:SKILL.md:695:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":706,"severity":"medium","line_start":695},{"id":"external_commands:SKILL.md:706:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":709,"severity":"medium","line_start":706},{"id":"external_commands:SKILL.md:709:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":715,"severity":"medium","line_start":709},{"id":"external_commands:SKILL.md:715:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":717,"severity":"medium","line_start":715},{"id":"external_commands:SKILL.md:717:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Status**: \"At the top of my OSS list of things to fix\" - maintainer Ephem (Nov 2025). Requires imp","category":"external_commands","line_end":720,"severity":"medium","line_start":717},{"id":"external_commands:SKILL.md:720:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: Queries refetch on mount despite `refetchOnMount: false`","category":"external_commands","line_end":724,"severity":"medium","line_start":720},{"id":"external_commands:SKILL.md:724:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use `retryOnMount: false` instead of (or in addition to) `refetchOnMount: false`","category":"external_commands","line_end":724,"severity":"medium","line_start":724},{"id":"external_commands:SKILL.md:727:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":735,"severity":"medium","line_start":727},{"id":"external_commands:SKILL.md:735:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":738,"severity":"medium","line_start":735},{"id":"external_commands:SKILL.md:738:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":746,"severity":"medium","line_start":738},{"id":"external_commands:SKILL.md:746:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":748,"severity":"medium","line_start":746},{"id":"external_commands:SKILL.md:748:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Status**: Documented behavior (intentional). The name `retryOnMount` is slightly misleading - it c","category":"external_commands","line_end":754,"severity":"medium","line_start":748},{"id":"external_commands:SKILL.md:754:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: `onMutateResult` parameter added between `variables` and `context`, changing cal","category":"external_commands","line_end":754,"severity":"medium","line_start":754},{"id":"external_commands:SKILL.md:758:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":768,"severity":"medium","line_start":758},{"id":"external_commands:SKILL.md:768:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":771,"severity":"medium","line_start":768},{"id":"external_commands:SKILL.md:771:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":782,"severity":"medium","line_start":771},{"id":"external_commands:SKILL.md:782:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":784,"severity":"medium","line_start":782},{"id":"external_commands:SKILL.md:784:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Note**: If you don't use `onMutate`, the `onMutateResult` parameter will be undefined. This breaki","category":"external_commands","line_end":784,"severity":"medium","line_start":784},{"id":"external_commands:SKILL.md:787:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `Type 'readonly [\"todos\", string]' is not assignable to type '[\"todos\", string]'`","category":"external_commands","line_end":790,"severity":"medium","line_start":787},{"id":"external_commands:SKILL.md:790:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: Partial query matching broke TypeScript types for readonly query keys (using `as","category":"external_commands","line_end":794,"severity":"medium","line_start":790},{"id":"external_commands:SKILL.md:794:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":809,"severity":"medium","line_start":794},{"id":"external_commands:SKILL.md:809:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":812,"severity":"medium","line_start":809},{"id":"external_commands:SKILL.md:812:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":817,"severity":"medium","line_start":812},{"id":"external_commands:SKILL.md:817:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":819,"severity":"medium","line_start":817},{"id":"external_commands:SKILL.md:819:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Status**: Fixed in v5.90.9. Particularly affected users of code generators like `openapi-react-que","category":"external_commands","line_end":822,"severity":"medium","line_start":819},{"id":"external_commands:SKILL.md:822:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `mutation.state.variables` typed as `unknown` instead of actual type","category":"external_commands","line_end":822,"severity":"medium","line_start":822},{"id":"external_commands:SKILL.md:825:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: Fuzzy mutation key matching prevents guaranteed type inference (same issue as `q","category":"external_commands","line_end":826,"severity":"medium","line_start":825},{"id":"external_commands:SKILL.md:826:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Explicitly cast types in the `select` callback","category":"external_commands","line_end":829,"severity":"medium","line_start":826},{"id":"external_commands:SKILL.md:829:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":841,"severity":"medium","line_start":829},{"id":"external_commands:SKILL.md:841:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":844,"severity":"medium","line_start":841},{"id":"external_commands:SKILL.md:844:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":851,"severity":"medium","line_start":844},{"id":"external_commands:SKILL.md:851:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":856,"severity":"medium","line_start":851},{"id":"external_commands:SKILL.md:856:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: `CancelledError` when using `fetchQuery()` with `useQuery`","category":"external_commands","line_end":856,"severity":"medium","line_start":856},{"id":"external_commands:SKILL.md:859:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: StrictMode causes double mount/unmount. When `useQuery` unmounts and is the last","category":"external_commands","line_end":859,"severity":"medium","line_start":859},{"id":"external_commands:SKILL.md:863:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":880,"severity":"medium","line_start":863},{"id":"external_commands:SKILL.md:880:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":883,"severity":"medium","line_start":880},{"id":"external_commands:SKILL.md:883:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":890,"severity":"medium","line_start":883},{"id":"external_commands:SKILL.md:890:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":895,"severity":"medium","line_start":890},{"id":"external_commands:SKILL.md:895:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Error**: Inactive queries not refetching despite `invalidateQueries()` call","category":"external_commands","line_end":898,"severity":"medium","line_start":895},{"id":"external_commands:SKILL.md:898:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Why It Happens**: Documentation was misleading - `invalidateQueries()` only refetches \"active\" que","category":"external_commands","line_end":899,"severity":"medium","line_start":898},{"id":"external_commands:SKILL.md:899:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prevention**: Use `refetchType: 'all'` to force refetch of inactive queries","category":"external_commands","line_end":902,"severity":"medium","line_start":899},{"id":"external_commands:SKILL.md:902:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":905,"severity":"medium","line_start":902},{"id":"external_commands:SKILL.md:905:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":908,"severity":"medium","line_start":905},{"id":"external_commands:SKILL.md:908:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":913,"severity":"medium","line_start":908},{"id":"external_commands:SKILL.md:913:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":928,"severity":"medium","line_start":913},{"id":"external_commands:SKILL.md:928:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When multiple components use the same query with different options (like `staleTime`), the \"last wri","category":"external_commands","line_end":931,"severity":"medium","line_start":928},{"id":"external_commands:SKILL.md:931:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":949,"severity":"medium","line_start":931},{"id":"external_commands:SKILL.md:949:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":952,"severity":"medium","line_start":949},{"id":"external_commands:SKILL.md:952:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":961,"severity":"medium","line_start":952},{"id":"external_commands:SKILL.md:961:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":967,"severity":"medium","line_start":961},{"id":"external_commands:SKILL.md:967:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The `refetch()` function should ONLY be used for refreshing with the same parameters (like a manual ","category":"external_commands","line_end":970,"severity":"medium","line_start":967},{"id":"external_commands:SKILL.md:970:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":980,"severity":"medium","line_start":970},{"id":"external_commands:SKILL.md:980:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":983,"severity":"medium","line_start":980},{"id":"external_commands:SKILL.md:983:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":993,"severity":"medium","line_start":983},{"id":"external_commands:SKILL.md:993:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":996,"severity":"medium","line_start":993},{"id":"external_commands:SKILL.md:996:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":1004,"severity":"medium","line_start":996},{"id":"external_commands:SKILL.md:1004:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1011,"severity":"medium","line_start":1004},{"id":"external_commands:SKILL.md:1011:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":1017,"severity":"medium","line_start":1011},{"id":"external_commands:SKILL.md:1017:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1020,"severity":"medium","line_start":1017},{"id":"external_commands:SKILL.md:1020:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":1024,"severity":"medium","line_start":1020},{"id":"external_commands:SKILL.md:1024:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1027,"severity":"medium","line_start":1024},{"id":"external_commands:SKILL.md:1027:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":1029,"severity":"medium","line_start":1027},{"id":"external_commands:SKILL.md:1029:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1032,"severity":"medium","line_start":1029},{"id":"external_commands:SKILL.md:1032:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":1039,"severity":"medium","line_start":1032},{"id":"external_commands:SKILL.md:1039:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1042,"severity":"medium","line_start":1039},{"id":"external_commands:SKILL.md:1042:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":1044,"severity":"medium","line_start":1042},{"id":"external_commands:SKILL.md:1044:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"const res = await fetch(`/api/todos?q=${search}`, { signal })","category":"external_commands","line_end":1047,"severity":"medium","line_start":1044},{"id":"external_commands:SKILL.md:1047:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1050,"severity":"medium","line_start":1047},{"id":"external_commands:SKILL.md:1050:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":1052,"severity":"medium","line_start":1050},{"id":"external_commands:SKILL.md:1052:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1058,"severity":"medium","line_start":1052},{"id":"network:SKILL.md:246:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"const res = await fetch('/api/todos')","category":"network","line_end":246,"severity":"low","line_start":246},{"id":"network:SKILL.md:260:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"const res = await fetch('/api/todos', {","category":"network","line_end":260,"severity":"low","line_start":260},{"id":"network:SKILL.md:662:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"**Why It Happens**: Race condition where `hydrate()` resolves synchronously but `query.fetch()` crea","category":"network","line_end":662,"severity":"low","line_start":662},{"id":"network:SKILL.md:1044:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"const res = await fetch(`/api/todos?q=${search}`, { signal })","category":"network","line_end":1044,"severity":"low","line_start":1044},{"id":"network:SKILL.md:444:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [v5 Migration Guide](https://tanstack.com/query/latest/docs/framework/react/guides/migra","category":"network","line_end":444,"severity":"low","line_start":444},{"id":"network:SKILL.md:464:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [v5 Breaking Changes](https://tanstack.com/query/latest/docs/framework/react/guides/migr","category":"network","line_end":464,"severity":"low","line_start":464},{"id":"network:SKILL.md:491:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [v5 Migration: isLoading renamed](https://tanstack.com/query/latest/docs/framework/react","category":"network","line_end":491,"severity":"low","line_start":491},{"id":"network:SKILL.md:510:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [v5 Migration: gcTime](https://tanstack.com/query/latest/docs/framework/react/guides/mig","category":"network","line_end":510,"severity":"low","line_start":510},{"id":"network:SKILL.md:534:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Discussion #6206](https://github.com/TanStack/query/discussions/6206)","category":"network","line_end":534,"severity":"low","line_start":534},{"id":"network:SKILL.md:569:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [v5 Migration: Infinite Queries](https://tanstack.com/query/latest/docs/framework/react/","category":"network","line_end":569,"severity":"low","line_start":569},{"id":"network:SKILL.md:594:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [v5 Migration: placeholderData](https://tanstack.com/query/latest/docs/framework/react/g","category":"network","line_end":594,"severity":"low","line_start":594},{"id":"network:SKILL.md:620:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [v5 Migration: Error Types](https://tanstack.com/query/latest/docs/framework/react/guide","category":"network","line_end":620,"severity":"low","line_start":620},{"id":"network:SKILL.md:660:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #9642](https://github.com/TanStack/query/issues/9642)","category":"network","line_end":660,"severity":"low","line_start":660},{"id":"network:SKILL.md:689:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #9399](https://github.com/TanStack/query/issues/9399)","category":"network","line_end":689,"severity":"low","line_start":689},{"id":"network:SKILL.md:721:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #10018](https://github.com/TanStack/query/issues/10018)","category":"network","line_end":721,"severity":"low","line_start":721},{"id":"network:SKILL.md:752:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #9660](https://github.com/TanStack/query/issues/9660)","category":"network","line_end":752,"severity":"low","line_start":752},{"id":"network:SKILL.md:788:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #9871](https://github.com/TanStack/query/issues/9871) | Fixed in [PR #9872","category":"network","line_end":788,"severity":"low","line_start":788},{"id":"network:SKILL.md:823:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #9825](https://github.com/TanStack/query/issues/9825)","category":"network","line_end":823,"severity":"low","line_start":823},{"id":"network:SKILL.md:857:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #9798](https://github.com/TanStack/query/issues/9798)","category":"network","line_end":857,"severity":"low","line_start":857},{"id":"network:SKILL.md:896:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [GitHub Issue #9531](https://github.com/TanStack/query/issues/9531)","category":"network","line_end":896,"severity":"low","line_start":896},{"id":"network:SKILL.md:925:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [TkDodo's Blog - API Design Lessons](https://tkdodo.eu/blog/react-query-api-design-lesso","category":"network","line_end":925,"severity":"low","line_start":925},{"id":"network:SKILL.md:965:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Source**: [Avoiding Common Mistakes with TanStack Query](https://www.buncolak.com/posts/avoiding-c","category":"network","line_end":965,"severity":"low","line_start":965},{"id":"network:SKILL.md:1058:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Official Docs**: https://tanstack.com/query/latest | **v5 Migration**: https://tanstack.com/query/","category":"network","line_end":1058,"severity":"low","line_start":1058},{"id":"blocker:SKILL.md:151:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"queries: userIds.map(id => ({","category":"blocker","line_end":151,"severity":"low","line_start":151},{"id":"blocker:SKILL.md:414:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"{id && <TodoComponent id={id} />}","category":"blocker","line_end":414,"severity":"low","line_start":414},{"id":"blocker:SKILL.md:509:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Error**: `cacheTime is not a valid option`","category":"blocker","line_end":509,"severity":"low","line_start":509},{"id":"blocker:SKILL.md:550:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"{id ? (","category":"blocker","line_end":550,"severity":"low","line_start":550},{"id":"blocker:SKILL.md:557:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"function TodoComponent({ id }: { id: number }) {","category":"blocker","line_end":557,"severity":"low","line_start":557},{"id":"blocker:SKILL.md:593:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Error**: `keepPreviousData is not a valid option`","category":"blocker","line_end":593,"severity":"low","line_start":593},{"id":"blocker:SKILL.md:661:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Affects**: v5.82.0+ with streaming SSR (void prefetch pattern)","category":"blocker","line_end":661,"severity":"low","line_start":661},{"id":"blocker:SKILL.md:663:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Prevention**: Don't conditionally render based on `fetchStatus` with `useSuspenseQuery` and stream","category":"blocker","line_end":663,"severity":"low","line_start":663},{"id":"blocker:SKILL.md:667:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// Server: void prefetch","category":"blocker","line_end":667,"severity":"low","line_start":667},{"id":"blocker:SKILL.md:692:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Prevention**: Use `useSuspenseQuery` instead of `useQuery` for SSR, or avoid conditional rendering","category":"blocker","line_end":692,"severity":"low","line_start":692},{"id":"blocker:SKILL.md:723:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Why It Happens**: Errored queries with no data are always treated as stale. This is intentional to","category":"blocker","line_end":723,"severity":"low","line_start":723},{"id":"blocker:SKILL.md:796:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"return id ? ['todos', id] as const : ['todos'] as const;","category":"blocker","line_end":796,"severity":"low","line_start":796},{"id":"blocker:SKILL.md:1022:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"queries: ids.map(id => ({ queryKey: ['todos', id], queryFn: () => fetchTodo(id) })),","category":"blocker","line_end":1022,"severity":"low","line_start":1022},{"id":"blocker:SKILL.md:1054:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Avoid Request Waterfalls**: Fetch in parallel when possible (don't chain queries unless truly depe","category":"blocker","line_end":1054,"severity":"low","line_start":1054},{"id":"external_commands:templates/custom-hooks-pattern.tsx:28:ruby-shell-backtick-execution","file":"templates/custom-hooks-pattern.tsx","pattern":"Ruby/shell backtick execution","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`)","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:templates/custom-hooks-pattern.tsx:29:ruby-shell-backtick-execution","file":"templates/custom-hooks-pattern.tsx","pattern":"Ruby/shell backtick execution","snippet":"if (!response.ok) throw new Error(`Failed to fetch user ${id}`)","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:templates/custom-hooks-pattern.tsx:44:ruby-shell-backtick-execution","file":"templates/custom-hooks-pattern.tsx","pattern":"Ruby/shell backtick execution","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:templates/custom-hooks-pattern.tsx:54:ruby-shell-backtick-execution","file":"templates/custom-hooks-pattern.tsx","pattern":"Ruby/shell backtick execution","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:templates/custom-hooks-pattern.tsx:199:ruby-shell-backtick-execution","file":"templates/custom-hooks-pattern.tsx","pattern":"Ruby/shell backtick execution","snippet":"<a href={`/users/${user.id}`}>{user.name}</a>","category":"external_commands","line_end":199,"severity":"medium","line_start":199},{"id":"network:templates/custom-hooks-pattern.tsx:22:fetch-api-call","file":"templates/custom-hooks-pattern.tsx","pattern":"Fetch API call","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/users')","category":"network","line_end":22,"severity":"low","line_start":22},{"id":"network:templates/custom-hooks-pattern.tsx:28:fetch-api-call","file":"templates/custom-hooks-pattern.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`)","category":"network","line_end":28,"severity":"low","line_start":28},{"id":"network:templates/custom-hooks-pattern.tsx:34:fetch-api-call","file":"templates/custom-hooks-pattern.tsx","pattern":"Fetch API call","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/users', {","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:templates/custom-hooks-pattern.tsx:44:fetch-api-call","file":"templates/custom-hooks-pattern.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","category":"network","line_end":44,"severity":"low","line_start":44},{"id":"network:templates/custom-hooks-pattern.tsx:54:fetch-api-call","file":"templates/custom-hooks-pattern.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","category":"network","line_end":54,"severity":"low","line_start":54},{"id":"network:templates/custom-hooks-pattern.tsx:22:hardcoded-url","file":"templates/custom-hooks-pattern.tsx","pattern":"Hardcoded URL","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/users')","category":"network","line_end":22,"severity":"low","line_start":22},{"id":"network:templates/custom-hooks-pattern.tsx:28:hardcoded-url","file":"templates/custom-hooks-pattern.tsx","pattern":"Hardcoded URL","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`)","category":"network","line_end":28,"severity":"low","line_start":28},{"id":"network:templates/custom-hooks-pattern.tsx:34:hardcoded-url","file":"templates/custom-hooks-pattern.tsx","pattern":"Hardcoded URL","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/users', {","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:templates/custom-hooks-pattern.tsx:44:hardcoded-url","file":"templates/custom-hooks-pattern.tsx","pattern":"Hardcoded URL","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","category":"network","line_end":44,"severity":"low","line_start":44},{"id":"network:templates/custom-hooks-pattern.tsx:54:hardcoded-url","file":"templates/custom-hooks-pattern.tsx","pattern":"Hardcoded URL","snippet":"const response = await fetch(`https://jsonplaceholder.typicode.com/users/${id}`, {","category":"network","line_end":54,"severity":"low","line_start":54},{"id":"blocker:templates/custom-hooks-pattern.tsx:144:system-reconnaissance","file":"templates/custom-hooks-pattern.tsx","pattern":"System reconnaissance","snippet":"old.map((user) => (user.id === updatedUser.id ? updatedUser : user))","category":"blocker","line_end":144,"severity":"low","line_start":144},{"id":"blocker:templates/custom-hooks-pattern.tsx:158:system-reconnaissance","file":"templates/custom-hooks-pattern.tsx","pattern":"System reconnaissance","snippet":"old.filter((user) => user.id !== deletedId)","category":"blocker","line_end":158,"severity":"low","line_start":158},{"id":"blocker:templates/custom-hooks-pattern.tsx:207:system-reconnaissance","file":"templates/custom-hooks-pattern.tsx","pattern":"System reconnaissance","snippet":"export function UserDetail({ id }: { id: number }) {","category":"blocker","line_end":207,"severity":"low","line_start":207},{"id":"scripts:templates/devtools-setup.tsx:188:dynamic-import-expression","file":"templates/devtools-setup.tsx","pattern":"Dynamic import() expression","snippet":"import('@tanstack/react-query-devtools-production').then((module) => {","category":"scripts","line_end":188,"severity":"medium","line_start":188},{"id":"sensitive:templates/devtools-setup.tsx:73:environment-file-access","file":"templates/devtools-setup.tsx","pattern":"Environment file access","snippet":"{import.meta.env.DEV && (","category":"sensitive","line_end":73,"severity":"high","line_start":73},{"id":"sensitive:templates/devtools-setup.tsx:213:certificate-key-files","file":"templates/devtools-setup.tsx","pattern":"Certificate/key files","snippet":"if ((e.ctrlKey || e.metaKey) && e.shiftKey && e.key === 'd') {","category":"sensitive","line_end":213,"severity":"high","line_start":213},{"id":"blocker:templates/devtools-setup.tsx:235:system-reconnaissance","file":"templates/devtools-setup.tsx","pattern":"System reconnaissance","snippet":"* ✅ Start with initialIsOpen={false} to avoid distraction","category":"blocker","line_end":235,"severity":"low","line_start":235},{"id":"external_commands:templates/error-boundary.tsx:171:ruby-shell-backtick-execution","file":"templates/error-boundary.tsx","pattern":"Ruby/shell backtick execution","snippet":"const response = await fetch(`/api/users/${id}`)","category":"external_commands","line_end":171,"severity":"medium","line_start":171},{"id":"external_commands:templates/error-boundary.tsx:186:ruby-shell-backtick-execution","file":"templates/error-boundary.tsx","pattern":"Ruby/shell backtick execution","snippet":"const response = await fetch(`/api/users/${id}`)","category":"external_commands","line_end":186,"severity":"medium","line_start":186},{"id":"external_commands:templates/error-boundary.tsx:187:ruby-shell-backtick-execution","file":"templates/error-boundary.tsx","pattern":"Ruby/shell backtick execution","snippet":"if (!response.ok) throw new Error(`HTTP ${response.status}`)","category":"external_commands","line_end":187,"severity":"medium","line_start":187},{"id":"network:templates/error-boundary.tsx:171:fetch-api-call","file":"templates/error-boundary.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(`/api/users/${id}`)","category":"network","line_end":171,"severity":"low","line_start":171},{"id":"network:templates/error-boundary.tsx:186:fetch-api-call","file":"templates/error-boundary.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(`/api/users/${id}`)","category":"network","line_end":186,"severity":"low","line_start":186},{"id":"blocker:templates/error-boundary.tsx:24:system-reconnaissance","file":"templates/error-boundary.tsx","pattern":"System reconnaissance","snippet":"ErrorBoundaryProps & { onReset?: () => void },","category":"blocker","line_end":24,"severity":"low","line_start":24},{"id":"blocker:templates/error-boundary.tsx:27:system-reconnaissance","file":"templates/error-boundary.tsx","pattern":"System reconnaissance","snippet":"constructor(props: ErrorBoundaryProps & { onReset?: () => void }) {","category":"blocker","line_end":27,"severity":"low","line_start":27},{"id":"blocker:templates/error-boundary.tsx:64:system-reconnaissance","file":"templates/error-boundary.tsx","pattern":"System reconnaissance","snippet":"border: '2px solid #ef4444',","category":"blocker","line_end":64,"severity":"low","line_start":64},{"id":"blocker:templates/error-boundary.tsx:167:system-reconnaissance","file":"templates/error-boundary.tsx","pattern":"System reconnaissance","snippet":"function UserData({ id }: { id: number }) {","category":"blocker","line_end":167,"severity":"low","line_start":167},{"id":"blocker:templates/error-boundary.tsx:182:system-reconnaissance","file":"templates/error-boundary.tsx","pattern":"System reconnaissance","snippet":"function ConditionalErrorThrowing({ id }: { id: number }) {","category":"blocker","line_end":182,"severity":"low","line_start":182},{"id":"external_commands:templates/use-infinite-query.tsx:26:ruby-shell-backtick-execution","file":"templates/use-infinite-query.tsx","pattern":"Ruby/shell backtick execution","snippet":"`https://jsonplaceholder.typicode.com/todos?_start=${start}&_limit=${limit}`","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"network:templates/use-infinite-query.tsx:25:fetch-api-call","file":"templates/use-infinite-query.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":25,"severity":"low","line_start":25},{"id":"network:templates/use-infinite-query.tsx:26:hardcoded-url","file":"templates/use-infinite-query.tsx","pattern":"Hardcoded URL","snippet":"`https://jsonplaceholder.typicode.com/todos?_start=${start}&_limit=${limit}`","category":"network","line_end":26,"severity":"low","line_start":26},{"id":"external_commands:templates/use-mutation-basic.tsx:30:ruby-shell-backtick-execution","file":"templates/use-mutation-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"throw new Error(`Failed to add todo: ${response.statusText}`)","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:templates/use-mutation-basic.tsx:38:ruby-shell-backtick-execution","file":"templates/use-mutation-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:templates/use-mutation-basic.tsx:47:ruby-shell-backtick-execution","file":"templates/use-mutation-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"throw new Error(`Failed to update todo: ${response.statusText}`)","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:templates/use-mutation-basic.tsx:55:ruby-shell-backtick-execution","file":"templates/use-mutation-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:templates/use-mutation-basic.tsx:62:ruby-shell-backtick-execution","file":"templates/use-mutation-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"throw new Error(`Failed to delete todo: ${response.statusText}`)","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"network:templates/use-mutation-basic.tsx:23:fetch-api-call","file":"templates/use-mutation-basic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/todos', {","category":"network","line_end":23,"severity":"low","line_start":23},{"id":"network:templates/use-mutation-basic.tsx:37:fetch-api-call","file":"templates/use-mutation-basic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":37,"severity":"low","line_start":37},{"id":"network:templates/use-mutation-basic.tsx:54:fetch-api-call","file":"templates/use-mutation-basic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":54,"severity":"low","line_start":54},{"id":"network:templates/use-mutation-basic.tsx:23:hardcoded-url","file":"templates/use-mutation-basic.tsx","pattern":"Hardcoded URL","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/todos', {","category":"network","line_end":23,"severity":"low","line_start":23},{"id":"network:templates/use-mutation-basic.tsx:38:hardcoded-url","file":"templates/use-mutation-basic.tsx","pattern":"Hardcoded URL","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"network","line_end":38,"severity":"low","line_start":38},{"id":"network:templates/use-mutation-basic.tsx:55:hardcoded-url","file":"templates/use-mutation-basic.tsx","pattern":"Hardcoded URL","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"network","line_end":55,"severity":"low","line_start":55},{"id":"blocker:templates/use-mutation-basic.tsx:137:system-reconnaissance","file":"templates/use-mutation-basic.tsx","pattern":"System reconnaissance","snippet":"old.filter((todo) => todo.id !== deletedId)","category":"blocker","line_end":137,"severity":"low","line_start":137},{"id":"external_commands:templates/use-mutation-optimistic.tsx:105:ruby-shell-backtick-execution","file":"templates/use-mutation-optimistic.tsx","pattern":"Ruby/shell backtick execution","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"external_commands","line_end":105,"severity":"medium","line_start":105},{"id":"external_commands:templates/use-mutation-optimistic.tsx:158:ruby-shell-backtick-execution","file":"templates/use-mutation-optimistic.tsx","pattern":"Ruby/shell backtick execution","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"external_commands","line_end":158,"severity":"medium","line_start":158},{"id":"network:templates/use-mutation-optimistic.tsx:40:fetch-api-call","file":"templates/use-mutation-optimistic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"network:templates/use-mutation-optimistic.tsx:104:fetch-api-call","file":"templates/use-mutation-optimistic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":104,"severity":"low","line_start":104},{"id":"network:templates/use-mutation-optimistic.tsx:157:fetch-api-call","file":"templates/use-mutation-optimistic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":157,"severity":"low","line_start":157},{"id":"network:templates/use-mutation-optimistic.tsx:41:hardcoded-url","file":"templates/use-mutation-optimistic.tsx","pattern":"Hardcoded URL","snippet":"'https://jsonplaceholder.typicode.com/todos',","category":"network","line_end":41,"severity":"low","line_start":41},{"id":"network:templates/use-mutation-optimistic.tsx:105:hardcoded-url","file":"templates/use-mutation-optimistic.tsx","pattern":"Hardcoded URL","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"network","line_end":105,"severity":"low","line_start":105},{"id":"network:templates/use-mutation-optimistic.tsx:158:hardcoded-url","file":"templates/use-mutation-optimistic.tsx","pattern":"Hardcoded URL","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`,","category":"network","line_end":158,"severity":"low","line_start":158},{"id":"blocker:templates/use-mutation-optimistic.tsx:16:system-reconnaissance","file":"templates/use-mutation-optimistic.tsx","pattern":"System reconnaissance","snippet":"* Avoid for:","category":"blocker","line_end":16,"severity":"low","line_start":16},{"id":"blocker:templates/use-mutation-optimistic.tsx:126:system-reconnaissance","file":"templates/use-mutation-optimistic.tsx","pattern":"System reconnaissance","snippet":"todo.id === id ? { ...todo, completed } : todo","category":"blocker","line_end":126,"severity":"low","line_start":126},{"id":"blocker:templates/use-mutation-optimistic.tsx:174:system-reconnaissance","file":"templates/use-mutation-optimistic.tsx","pattern":"System reconnaissance","snippet":"old.filter((todo) => todo.id !== deletedId)","category":"blocker","line_end":174,"severity":"low","line_start":174},{"id":"external_commands:templates/use-query-basic.tsx:21:ruby-shell-backtick-execution","file":"templates/use-query-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"throw new Error(`Failed to fetch todos: ${response.statusText}`)","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:templates/use-query-basic.tsx:56:ruby-shell-backtick-execution","file":"templates/use-query-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:templates/use-query-basic.tsx:60:ruby-shell-backtick-execution","file":"templates/use-query-basic.tsx","pattern":"Ruby/shell backtick execution","snippet":"throw new Error(`Failed to fetch todo ${id}: ${response.statusText}`)","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"network:templates/use-query-basic.tsx:18:fetch-api-call","file":"templates/use-query-basic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/todos')","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"network:templates/use-query-basic.tsx:55:fetch-api-call","file":"templates/use-query-basic.tsx","pattern":"Fetch API call","snippet":"const response = await fetch(","category":"network","line_end":55,"severity":"low","line_start":55},{"id":"network:templates/use-query-basic.tsx:18:hardcoded-url","file":"templates/use-query-basic.tsx","pattern":"Hardcoded URL","snippet":"const response = await fetch('https://jsonplaceholder.typicode.com/todos')","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"network:templates/use-query-basic.tsx:56:hardcoded-url","file":"templates/use-query-basic.tsx","pattern":"Hardcoded URL","snippet":"`https://jsonplaceholder.typicode.com/todos/${id}`","category":"network","line_end":56,"severity":"low","line_start":56},{"id":"blocker:templates/use-query-basic.tsx:76:system-reconnaissance","file":"templates/use-query-basic.tsx","pattern":"System reconnaissance","snippet":"enabled: !!id, // Only fetch if id is truthy","category":"blocker","line_end":76,"severity":"low","line_start":76}],"finding_verdicts":[{"id":"network:README.md:159:http-client-library","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:references/best-practices.md:205:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/best-practices.md:7:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/best-practices.md:45:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/best-practices.md:221:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/common-patterns.md:153:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/common-patterns.md:177:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:references/common-patterns.md:177:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/common-patterns.md:35:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/common-patterns.md:117:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/common-patterns.md:225:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"network:references/testing.md:97:http-https-get","reason":"The http.get call is an MSW test handler example, not a live outbound network request from the skill. It is documentation for local testing behavior.","verdict":"false_positive","confidence":0.96},{"id":"network:references/testing.md:120:http-https-get","reason":"The http.get call is an MSW test handler example, not a live outbound network request from the skill. It is documentation for local testing behavior.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/top-errors.md:284:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:references/top-errors.md:282:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/top-errors.md:127:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/typescript-patterns.md:39:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:references/typescript-patterns.md:20:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:references/typescript-patterns.md:39:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:references/typescript-patterns.md:58:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:references/typescript-patterns.md:88:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:references/typescript-patterns.md:118:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:references/typescript-patterns.md:153:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:scripts/example-script.sh:1:unix-shell-invocation","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:292:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:350:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:377:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:384:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:405:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:418:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:443:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:451:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:469:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:477:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:492:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:493:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:496:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:499:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:502:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:515:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:524:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:530:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:536:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:545:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:548:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:565:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:570:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:571:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:574:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:580:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:583:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:590:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:593:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:595:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:596:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:599:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:605:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:608:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:621:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:625:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:634:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:656:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:659:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:662:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:663:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:666:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:673:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:676:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:683:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:685:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:691:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:692:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:695:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:706:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:709:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:715:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:717:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:720:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:724:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:727:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:735:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:738:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:746:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:748:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:754:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:758:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:768:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:771:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:782:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:784:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:787:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:790:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:794:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:809:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:812:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:817:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:819:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:822:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:825:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:826:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:829:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:841:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:844:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:851:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:856:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:859:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:863:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:880:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:883:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:890:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:895:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:898:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:899:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:902:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:905:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:908:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:913:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:928:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:931:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:949:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:952:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:961:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:967:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:970:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:980:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:983:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:993:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:996:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1004:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1011:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1017:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1020:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1024:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1027:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1029:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1032:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1039:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1042:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1044:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1047:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1050:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:1052:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:246:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:260:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:662:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:1044:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:444:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:464:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:491:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:510:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:534:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:569:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:594:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:620:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:660:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:689:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:721:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:752:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:788:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:823:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:857:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:896:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:925:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:965:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:1058:hardcoded-url","reason":"The match is a documentation citation or dependency description, not code that sends data. It does not create an unauthorized network path.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:151:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:414:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:509:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:550:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:557:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:593:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:661:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:663:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:667:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:692:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:723:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:796:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:1022:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:1054:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:templates/custom-hooks-pattern.tsx:28:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/custom-hooks-pattern.tsx:29:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/custom-hooks-pattern.tsx:44:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/custom-hooks-pattern.tsx:54:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/custom-hooks-pattern.tsx:199:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:templates/custom-hooks-pattern.tsx:22:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:28:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:34:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:44:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:54:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:22:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:28:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:34:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:44:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/custom-hooks-pattern.tsx:54:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"blocker:templates/custom-hooks-pattern.tsx:144:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/custom-hooks-pattern.tsx:158:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/custom-hooks-pattern.tsx:207:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"scripts:templates/devtools-setup.tsx:188:dynamic-import-expression","reason":"The dynamic import loads a fixed TanStack DevTools package after a local UI toggle. The import path is not user-controlled and is not arbitrary code loading.","verdict":"false_positive","confidence":0.89},{"id":"sensitive:templates/devtools-setup.tsx:73:environment-file-access","reason":"This reads Vite's DEV boolean to conditionally render DevTools, not an environment file or secret. It does not expose credential material.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:templates/devtools-setup.tsx:213:certificate-key-files","reason":"The match is the KeyboardEvent ctrlKey property, not a certificate or private key file. No sensitive file access occurs.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/devtools-setup.tsx:235:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:templates/error-boundary.tsx:171:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/error-boundary.tsx:186:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/error-boundary.tsx:187:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:templates/error-boundary.tsx:171:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"network:templates/error-boundary.tsx:186:fetch-api-call","reason":"The fetch example uses an application-relative API route or educational sample code. No external endpoint, credential transfer, or hidden request is present.","verdict":"false_positive","confidence":0.94},{"id":"blocker:templates/error-boundary.tsx:24:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/error-boundary.tsx:27:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/error-boundary.tsx:64:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/error-boundary.tsx:167:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/error-boundary.tsx:182:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:templates/use-infinite-query.tsx:26:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:templates/use-infinite-query.tsx:25:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-infinite-query.tsx:26:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"external_commands:templates/use-mutation-basic.tsx:30:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/use-mutation-basic.tsx:38:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/use-mutation-basic.tsx:47:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/use-mutation-basic.tsx:55:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/use-mutation-basic.tsx:62:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:templates/use-mutation-basic.tsx:23:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-basic.tsx:37:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-basic.tsx:54:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-basic.tsx:23:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-basic.tsx:38:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-basic.tsx:55:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"blocker:templates/use-mutation-basic.tsx:137:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:templates/use-mutation-optimistic.tsx:105:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/use-mutation-optimistic.tsx:158:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:templates/use-mutation-optimistic.tsx:40:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-optimistic.tsx:104:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-optimistic.tsx:157:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-optimistic.tsx:41:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-optimistic.tsx:105:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-mutation-optimistic.tsx:158:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"blocker:templates/use-mutation-optimistic.tsx:16:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/use-mutation-optimistic.tsx:126:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:templates/use-mutation-optimistic.tsx:174:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:templates/use-query-basic.tsx:21:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/use-query-basic.tsx:56:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:templates/use-query-basic.tsx:60:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences, inline documentation, or JavaScript/TSX template literals. They are not shell or Ruby command execution and do not invoke external commands.","verdict":"false_positive","confidence":0.98},{"id":"network:templates/use-query-basic.tsx:18:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-query-basic.tsx:55:fetch-api-call","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-query-basic.tsx:18:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:templates/use-query-basic.tsx:56:hardcoded-url","reason":"This copy-ready template calls the public jsonplaceholder API. It is not malicious, but users could accidentally send entered sample data to an external third-party service if run unchanged.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"blocker:templates/use-query-basic.tsx:76:system-reconnaissance","reason":"The snippet is React or TanStack Query guidance using identifiers, booleans, or avoid/prevention wording. It does not inspect the host system or perform reconnaissance.","verdict":"false_positive","confidence":0.96}],"semantic_findings":[{"title":"Production DevTools Can Expose Cache Data","severity":"medium","locations":[{"file":"templates/devtools-setup.tsx","line_end":198,"line_start":173}],"confidence":0.82,"description":"The production DevTools example loads and renders React Query DevTools when a local showDevTools flag is true, but the sample does not enforce authentication. Query cache data can include user records, tokens, or API responses if copied into production.","confidence_reasoning":"The file explicitly labels the section as production DevTools and renders the component from a local toggle only. The same file later warns not to ship production DevTools without authentication."},{"title":"Error Boundary Displays Stack Traces","severity":"medium","locations":[{"file":"templates/error-boundary.tsx","line_end":76,"line_start":70}],"confidence":0.86,"description":"The default fallback renders error.message and error.stack in the page. Production users could see implementation details if this template is copied without an environment guard.","confidence_reasoning":"The code directly renders error details and the stack trace inside the visible fallback UI. This is useful during development but can leak internal details in production."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":28,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}