{"data":{"skill":{"slug":"limrun-inc-limrun-xcode-bazel","name":"limrun-xcode-bazel","icon":"📦","repo":"https://github.com/limrun-inc/skills/tree/e29a129cea3d311d2bd348eef1aadcd1b20397d5/skills/limrun-xcode-bazel","status":"approved","author":"limrun-inc","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"378cc180-c760-41d2-8ea0-acae01cd380e","skill_id":"8a911c84-19fd-4020-a4e1-ab10e4bef305","version":1,"content_hash":"v3:c79b480950993002e3cfc6f31c87e6eb44b7d19b:81f8ccb8c6d5acd1061530af1d7964e0aeaeb41708ef66fdbc489800daadd264:fa206ef906e9cfad8864606dc8ba4bcdae909f6e028bb731b5d4e2ae64ef2b2c:736b696c6c732f6c696d72756e2d696e632f6c696d72756e2d78636f64652d62617a656c:a7e8d3f46452868835f41eddc133f81b","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 69 static findings are false positives caused by documentation syntax, Bazel terminology, illustrative paths, or expected Limrun endpoints. No prompt injection, secret extraction, covert exfiltration, or executable skill code was found.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"references/verify-remote.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":100,"line_start":100}]},{"factor":"filesystem","evidence":[{"file":"references/verify-remote.md","line_end":22,"line_start":22},{"file":"references/verify-remote.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":121,"line_start":121}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":11,"line_start":11},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":51,"line_start":48},{"file":"SKILL.md","line_end":53,"line_start":51},{"file":"SKILL.md","line_end":59,"line_start":53},{"file":"SKILL.md","line_end":62,"line_start":59},{"file":"SKILL.md","line_end":64,"line_start":62},{"file":"SKILL.md","line_end":67,"line_start":64},{"file":"SKILL.md","line_end":68,"line_start":67},{"file":"SKILL.md","line_end":70,"line_start":68},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":74,"line_start":73},{"file":"SKILL.md","line_end":77,"line_start":74},{"file":"SKILL.md","line_end":85,"line_start":77},{"file":"SKILL.md","line_end":88,"line_start":85},{"file":"SKILL.md","line_end":90,"line_start":88},{"file":"SKILL.md","line_end":91,"line_start":90},{"file":"SKILL.md","line_end":92,"line_start":91},{"file":"SKILL.md","line_end":93,"line_start":92},{"file":"SKILL.md","line_end":95,"line_start":93},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":104,"line_start":100},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":111,"line_start":110},{"file":"SKILL.md","line_end":112,"line_start":111},{"file":"SKILL.md","line_end":113,"line_start":112},{"file":"SKILL.md","line_end":114,"line_start":113},{"file":"SKILL.md","line_end":115,"line_start":114},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":118,"line_start":117},{"file":"SKILL.md","line_end":119,"line_start":118},{"file":"SKILL.md","line_end":121,"line_start":119},{"file":"SKILL.md","line_end":124,"line_start":121}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":19,"line_start":19}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":286,"audit_model":"codex","audited_at":"2026-08-21T08:33:55.494+00:00","created_at":"2026-08-21T10:07:57.515149+00:00","static_findings":[{"id":"sensitive:references/project-compatibility.md:53:crypto-seed-private-key-mention","file":"references/project-compatibility.md","pattern":"Crypto seed/private key mention","snippet":"### Per-mnemonic strategy pins beyond Swift/Genrule","category":"sensitive","line_end":53,"severity":"high","line_start":53},{"id":"sensitive:references/project-compatibility.md:54:crypto-seed-private-key-mention","file":"references/project-compatibility.md","pattern":"Crypto seed/private key mention","snippet":"If a repo pins other mnemonics local (e.g. `--strategy=ObjcCompile=local`), those","category":"sensitive","line_end":54,"severity":"high","line_start":54},{"id":"sensitive:references/project-compatibility.md:57:crypto-seed-private-key-mention","file":"references/project-compatibility.md","pattern":"Crypto seed/private key mention","snippet":"local toolchain. Fix: override the offending mnemonic to `remote`.","category":"sensitive","line_end":57,"severity":"high","line_start":57},{"id":"network:references/verify-remote.md:44:hardcoded-ip-address","file":"references/verify-remote.md","pattern":"Hardcoded IP address","snippet":"# expect: connection error to 127.0.0.1:<port> / Remote Execution Failure","category":"network","line_end":44,"severity":"medium","line_start":44},{"id":"filesystem:references/verify-remote.md:22:path-traversal-sequence","file":"references/verify-remote.md","pattern":"Path traversal sequence","snippet":"`/Users/<worker-user>/.../.rbe-<id>/runner/build/.../root/...`. Local execution","category":"filesystem","line_end":22,"severity":"high","line_start":22},{"id":"filesystem:references/verify-remote.md:22:hidden-file-access","file":"references/verify-remote.md","pattern":"Hidden file access","snippet":"`/Users/<worker-user>/.../.rbe-<id>/runner/build/.../root/...`. Local execution","category":"filesystem","line_end":22,"severity":"medium","line_start":22},{"id":"blocker:references/verify-remote.md:8:system-reconnaissance","file":"references/verify-remote.md","pattern":"System reconnaissance","snippet":"(over the tunnel). The action did **not** re-execute. The cache is shared","category":"blocker","line_end":8,"severity":"low","line_start":8},{"id":"blocker:references/verify-remote.md:21:system-reconnaissance","file":"references/verify-remote.md","pattern":"System reconnaissance","snippet":"A tell that work did run remotely: action stdout shows worker paths under","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"description: \"Build a Bazel-based iOS / macOS / Apple app on Limrun's remote build execution (RBE) i","category":"external_commands","line_end":3,"severity":"medium","line_start":3},{"id":"external_commands:SKILL.md:11:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(Linux, Windows, macOS, VM, container), no local Xcode. `lim xcode rbe` brings up","category":"external_commands","line_end":11,"severity":"medium","line_start":11},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"a remote RBE stack, tunnels it to a local port, and writes a `.limrun/` config so","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`bazelisk build --config=limrun` runs Apple actions remotely. Never fall back to","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Install if needed: `npm install --global lim`. Auth is `lim login` or","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`LIM_API_KEY` (may be set outside the project — don't ask for it just because","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`lim xcode rbe --help` instead of guessing.","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. From the **Bazel workspace root** (has `MODULE.bazel` / `WORKSPACE`), run","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`lim xcode rbe`. It sets up the instance + `.limrun/` config and **prints the","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--no-daemon` keeps it foreground.","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`bazelisk --digest_function=sha256 build --config=limrun //App`.","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Don't hand-write `.limrun/` or the flags — the CLI generates them for the fleet's","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Xcode and your OS. Re-run `lim xcode rbe` (after `--stop`) to refresh after a","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"config, put them in **`user.limrun.bazelrc`** at the workspace root. The","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"generated config try-imports it last, so your `build:limrun --...` lines win, and","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"it survives `lim xcode rbe` regeneration (`.limrun/` does not).","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`lim xcode rbe` is build-only; attach a simulator when the user wants to see or","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":51,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Add `--no-open` when you have no browser to show the user; it skips opening","category":"external_commands","line_end":59,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"With a simulator attached, every successful `--config=limrun` build automatically","category":"external_commands","line_end":62,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":64,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":67,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Attach upfront** if you already know you want a sim: `lim xcode rbe --ios`","category":"external_commands","line_end":68,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(attaches at startup, removed on `--stop`).","category":"external_commands","line_end":70,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`lim xcode rbe install` subcommand or `--target` flag. To force a reinstall,","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"multi-app workspace build one app target per invocation (`//App`, not","category":"external_commands","line_end":74,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`//...`); a multi-app build succeeds but installs nothing.","category":"external_commands","line_end":77,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"switch to the **`limrun-ios-simulator`** skill.","category":"external_commands","line_end":85,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":88,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":90,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--auto-upload` holds for the tunnel's lifetime: each successful","category":"external_commands","line_end":91,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--config=limrun` build re-uploads the app under that asset name, no","category":"external_commands","line_end":92,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"post-build step. Upload results land in `.limrun/rbe.log`.","category":"external_commands","line_end":93,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rbe upload` runs from the workspace root and needs a background tunnel","category":"external_commands","line_end":95,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- TTLs are Go durations (`24h`, `30m`; `1d` is invalid) and optional; each","category":"external_commands","line_end":95,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- To change the `--auto-upload` config of a running tunnel, `--stop` and","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`https://console.limrun.com/preview?asset=<name>&platform=ios`.","category":"external_commands","line_end":104,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Stop with **`lim xcode rbe --stop`** (~20s to tear the remote stack down) and delete the instance wi","category":"external_commands","line_end":104,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Always pass `--digest_function=sha256` before `build`** (use the command the","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"BLAKE3. It's a startup flag, so it can't live in `--config=limrun`. Symptoms:","category":"external_commands","line_end":111,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"build → `Cannot use hash function BLAKE3 with remote cache`; install →","category":"external_commands","line_end":112,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`non-SHA256 digest ... rebuild with --digest_function=sha256`.","category":"external_commands","line_end":113,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Run `lim xcode rbe` from the workspace root**, not a subdirectory — it writes","category":"external_commands","line_end":114,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`.limrun/` there and fails fast otherwise.","category":"external_commands","line_end":115,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"hit` / `remote cache hit`) make builds pass even with the tunnel gone. To force","category":"external_commands","line_end":116,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and verify real remote execution, see `references/verify-remote.md`.","category":"external_commands","line_end":118,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **The printed `.ipa` path won't exist on your machine** — the build command","category":"external_commands","line_end":119,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"carries `--remote_download_outputs=minimal`, which keeps the artifact in the","category":"external_commands","line_end":121,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`Target //App:App up-to-date: .../App.ipa` line, but that file is **not** on","category":"external_commands","line_end":124,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"log, not the local file). Only if you genuinely need the `.ipa` locally, drop","category":"external_commands","line_end":125,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--remote_download_outputs=minimal` from the build command and Bazel downloads","category":"external_commands","line_end":127,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"available remotely`** (e.g. `... Assets.car`). It's a transient cache eviction","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"error, retrying the build...` and the retry succeeds. To avoid hitting it","category":"external_commands","line_end":131,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"mid-demo, pre-warm with a full build right after `lim xcode rbe`.","category":"external_commands","line_end":132,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`You don't have permission to save ... in \"CoreSimulator\"`** (actool/ibtool) is","category":"external_commands","line_end":136,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"transition, custom `remote_default_exec_properties`, sandbox-hostile genrules).","category":"external_commands","line_end":138,"severity":"medium","line_start":136},{"id":"network:SKILL.md:100:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"`https://console.limrun.com/preview?asset=<name>&platform=ios`.","category":"network","line_end":100,"severity":"low","line_start":100},{"id":"filesystem:SKILL.md:121:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"`Target //App:App up-to-date: .../App.ipa` line, but that file is **not** on","category":"filesystem","line_end":121,"severity":"high","line_start":121},{"id":"env_access:SKILL.md:19:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"`LIM_API_KEY` (may be set outside the project — don't ask for it just because","category":"env_access","line_end":19,"severity":"high","line_start":19},{"id":"blocker:SKILL.md:130:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"error, retrying the build...` and the retry succeeds. To avoid hitting it","category":"blocker","line_end":130,"severity":"low","line_start":130}],"finding_verdicts":[{"id":"sensitive:references/project-compatibility.md:53:crypto-seed-private-key-mention","reason":"The word mnemonic refers to a Bazel action class, not a wallet seed or private key. The surrounding guidance only changes remote execution strategy.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/project-compatibility.md:54:crypto-seed-private-key-mention","reason":"The word mnemonic refers to a Bazel action class, not a wallet seed or private key. The surrounding guidance only changes remote execution strategy.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/project-compatibility.md:57:crypto-seed-private-key-mention","reason":"The word mnemonic refers to a Bazel action class, not a wallet seed or private key. The surrounding guidance only changes remote execution strategy.","verdict":"false_positive","confidence":0.99},{"id":"network:references/verify-remote.md:44:hardcoded-ip-address","reason":"127.0.0.1 is the loopback endpoint used in an expected tunnel-failure example. It is not an external destination or hidden network target.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/verify-remote.md:22:path-traversal-sequence","reason":"The line displays a representative remote worker path using placeholders and ellipses. It does not construct a traversal path or access the filesystem.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/verify-remote.md:22:hidden-file-access","reason":"The hidden-looking .rbe directory appears only inside an illustrative worker path. No instruction reads or modifies that directory.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/verify-remote.md:8:system-reconnaissance","reason":"The text explains that a remote cache hit avoids action execution. It does not collect system information or run reconnaissance commands.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/verify-remote.md:21:system-reconnaissance","reason":"The text teaches users to recognize remote worker paths in normal build output. It does not probe the host or enumerate sensitive system details.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:11:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"This is Markdown documentation containing inline command literals or fenced examples. No Ruby runtime or shell backtick operator exists in the skill files.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:100:hardcoded-url","reason":"The URL is the documented Limrun console preview route for an explicitly uploaded asset. It does not transmit data to an unrelated or concealed endpoint.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:121:path-traversal-sequence","reason":"The ellipsis is abbreviated Bazel output showing where an IPA would appear. It is not a traversal operator or filesystem access instruction.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:19:generic-api-secret-keys","reason":"The documentation names LIM_API_KEY as an authentication option and explicitly discourages requesting it. No code reads, logs, or transmits the secret.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:130:system-reconnaissance","reason":"The line quotes a normal Bazel retry message for transient cache errors. It performs no system discovery or reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"c79b480950993002e3cfc6f31c87e6eb44b7d19b","subject_content_hash":"81f8ccb8c6d5acd1061530af1d7964e0aeaeb41708ef66fdbc489800daadd264","subject_tree_hash":"fa206ef906e9cfad8864606dc8ba4bcdae909f6e028bb731b5d4e2ae64ef2b2c","subject_plugin_path":"skills/limrun-inc/limrun-xcode-bazel","audit_payload_hash":"a7e8d3f46452868835f41eddc133f81b","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"c79b480950993002e3cfc6f31c87e6eb44b7d19b","contentHash":"81f8ccb8c6d5acd1061530af1d7964e0aeaeb41708ef66fdbc489800daadd264","treeHash":"fa206ef906e9cfad8864606dc8ba4bcdae909f6e028bb731b5d4e2ae64ef2b2c","pluginPath":"skills/limrun-inc/limrun-xcode-bazel","auditPayloadHash":"a7e8d3f46452868835f41eddc133f81b"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/limrun-inc-limrun-xcode-bazel/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}