{"data":{"skill":{"slug":"metalbear-co-mirrord-chaos","name":"mirrord-chaos","icon":"📦","repo":"https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-chaos","status":"approved","author":"metalbear-co","authorVersion":"2.0","skillstoreRevision":1},"audit":{"id":"5f98978f-c1ef-4797-ac5f-431ecc01a910","skill_id":"4347fe88-abf2-491d-acf5-33f536a5a8d6","version":1,"content_hash":"v3:bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2:2d29e0360d17f010d194f2969eb8ef065aeedc0c8921776fec82d0e65cb0e6bf:6469466b0a0a4edc1229abc3825c6441bda498ff30804f80cadcc77d24daed81:736b696c6c732f6d6574616c626561722d636f2f6d6972726f72642d6368616f73:a9d5c805043cec808b3ff491916e2d30","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 78 static findings are false positives for this document-only skill. The flagged commands are explicit mirrord, shell, and text-processing examples for session-scoped chaos testing; no malicious installation, credential access, exfiltration, or prompt injection was found.","remediation":[{"issue":"Chaos commands can affect real dependencies when a mirrord session targets production.","severity":"medium","suggestion":"Keep the existing staging-only warning prominent and require an explicit production approval process before applying rules."},{"issue":"The CI example extracts a session identifier with shell pipelines.","severity":"low","suggestion":"Use a trusted, pinned mirrord runner and validate the extracted session identifier before applying or deleting rules."},{"issue":"The guide includes a command that deletes all chaos rules for a session.","severity":"low","suggestion":"Prefer deleting by rule ID when possible and require a deliberate cleanup step for the session-wide delete command."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":78,"line_start":64},{"file":"SKILL.md","line_end":84,"line_start":78},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":91,"line_start":85},{"file":"SKILL.md","line_end":93,"line_start":91},{"file":"SKILL.md","line_end":101,"line_start":93},{"file":"SKILL.md","line_end":103,"line_start":101},{"file":"SKILL.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":107,"line_start":105},{"file":"SKILL.md","line_end":114,"line_start":107},{"file":"SKILL.md","line_end":116,"line_start":114},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":139,"line_start":122},{"file":"SKILL.md","line_end":141,"line_start":139},{"file":"SKILL.md","line_end":143,"line_start":141},{"file":"SKILL.md","line_end":143,"line_start":143},{"file":"SKILL.md","line_end":147,"line_start":147},{"file":"SKILL.md","line_end":148,"line_start":148},{"file":"SKILL.md","line_end":149,"line_start":149},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":154,"line_start":154},{"file":"SKILL.md","line_end":158,"line_start":156},{"file":"SKILL.md","line_end":160,"line_start":158},{"file":"SKILL.md","line_end":162,"line_start":160},{"file":"SKILL.md","line_end":164,"line_start":162},{"file":"SKILL.md","line_end":166,"line_start":164},{"file":"SKILL.md","line_end":180,"line_start":166},{"file":"SKILL.md","line_end":182,"line_start":180},{"file":"SKILL.md","line_end":182,"line_start":182},{"file":"SKILL.md","line_end":186,"line_start":184},{"file":"SKILL.md","line_end":192,"line_start":186},{"file":"SKILL.md","line_end":192,"line_start":192},{"file":"SKILL.md","line_end":194,"line_start":194},{"file":"SKILL.md","line_end":225,"line_start":196},{"file":"SKILL.md","line_end":227,"line_start":225}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":264,"line_start":264},{"file":"SKILL.md","line_end":265,"line_start":265},{"file":"SKILL.md","line_end":266,"line_start":266}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":205,"line_start":205}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":319,"audit_model":"codex","audited_at":"2026-09-29T21:23:28.154+00:00","created_at":"2026-09-30T13:38:06.8025+00:00","static_findings":[{"id":"blocker:README.md:8:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"- **Generate** valid chaos rule JSON files (selector + effect + priority)","category":"blocker","line_end":8,"severity":"low","line_start":8},{"id":"external_commands:SKILL.md:4:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Help users chaos test their app with mirrord: inject artificial latency or connection errors into a ","category":"external_commands","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Help users inject artificial failures and disruptions into a mirrord session's **outgoing traffic**,","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Interactive mode**: a developer starts a session with `mirrord exec` and manages rules with `mi","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **CI mode**: a pipeline applies rule files checked into the repo with `mirrord chaos add`, and ru","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- \"How do I use `mirrord chaos`?\"","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"## Not the `_experimental_.latency` config","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The mirrord config schema contains an `_experimental_.latency` option for outgoing latency. It is ma","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- A rule = `selector` + `effect`, plus an optional `name` and `priority`.","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Rules are scoped to one session: every `mirrord chaos` command takes a `--session-id`.","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- When multiple rules match the same connection, **only one is applied: the rule with the highest `p","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Each rule gets an `id` (UUID) on creation. `name` is a free-form label with **no uniqueness guaran","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Each rule tracks a `hit_count` of how many times it was applied. Editing a rule keeps its `id` but","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **CLI** | mirrord CLI **3.241.0+** for the `mirrord chaos` command. Older CLIs (3.232.0+) can mana","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **UI server** | Not a manual step: `mirrord chaos` silently starts the local UI server if it isn't","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":78,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":84,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `upstream` | The destination to match: a host, or `host:port` to match a specific port. Uses the s","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `percentage` | Roughly how often a matched connection gets the effect. Integer 0–100; values above","category":"external_commands","line_end":91,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**`latency`**: delays the connection's read and/or write operations:","category":"external_commands","line_end":93,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":101,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":103,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"At least one of `read_ms` or `write_ms` must be non-zero, or the rule is rejected with: `either 'eff","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**`connection_error`**: fails the connection:","category":"external_commands","line_end":107,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":114,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":116,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`type` is one of `reset` (can be applied to ongoing connections), `timed_out`, `refused`.","category":"external_commands","line_end":116,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`mirrord chaos` prints the full rule, pretty-printed by default or as JSON with `--format json`. Not","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":139,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":141,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"## The `mirrord chaos` command","category":"external_commands","line_end":143,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every subcommand takes `--session-id` (`-s`). `add` and `edit` read the rule JSON from `stdin`, or f","category":"external_commands","line_end":143,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mirrord chaos add -s <session> -f <file>` | Create a rule, or several at once from a JSON array. ","category":"external_commands","line_end":147,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mirrord chaos list -s <session>` | List the session's active rules. Add `-r <rule-id>` to get one","category":"external_commands","line_end":148,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mirrord chaos edit -s <session> -r <rule-id> -f <file>` | Replace a rule (same `id`, `hit_count` ","category":"external_commands","line_end":149,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mirrord chaos delete -s <session>` | Delete **all** of the session's rules. Add `-r <rule-id>` to","category":"external_commands","line_end":150,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Start a mirrord session and grab its session ID: it's printed by `mirrord exec`, or listed by `mirro","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":158,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":160,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":162,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":164,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Write the rule to a JSON file (e.g. `latency-rule.json`, see [Rule anatomy](#rule-anatomy)) and mana","category":"external_commands","line_end":166,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":180,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":182,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Rules can also be piped on `stdin` instead of `-f`:","category":"external_commands","line_end":182,"severity":"medium","line_start":182},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":186,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":192,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Rule files are declarative JSON: check them into the repo (e.g. `.mirrord/chaos/`) so chaos scenario","category":"external_commands","line_end":192,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Tag the session with a known key (`mirrord exec --key`) so the pipeline can find its session ID in t","category":"external_commands","line_end":194,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":225,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":227,"severity":"medium","line_start":225},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Polling note: session registration is asynchronous, so `mirrord session list` may not show the sessi","category":"external_commands","line_end":227,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Rule creation rejected for a latency effect | At least one of `read_ms` / `write_ms` must be non-z","category":"external_commands","line_end":233,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Rule created but never fires | Only outgoing **TCP** selectors are implemented today; file operati","category":"external_commands","line_end":234,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Two rules match, only one applies | By design: highest `priority` wins. Raise the priority of the ","category":"external_commands","line_end":236,"severity":"medium","line_start":235},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `percentage` above 100 | Rounded down to 100. |","category":"external_commands","line_end":237,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Can't find a rule by name | `name` is not unique: `mirrord chaos list` the rules and use the `id`.","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `hit_count` dropped to zero after an edit | `edit` resets `hit_count`; the `id` stays the same. |","category":"external_commands","line_end":238,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `upstream` in output shows `host:0` | `0` means any port; it's the serialized form of a filter wit","category":"external_commands","line_end":239,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Session not found | Wrong `--session-id`, the session ended, or it hasn't registered yet. List ses","category":"external_commands","line_end":240,"severity":"medium","line_start":240},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `chaos edit` rejects the input | `edit` accepts a single rule, not an array. To replace several ru","category":"external_commands","line_end":241,"severity":"medium","line_start":241},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Identify the mode**: interactive terminal vs. CI. Both use the same `mirrord chaos` commands.","category":"external_commands","line_end":247,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Get the session ID**: printed by `mirrord exec`, or from `mirrord session list`.","category":"external_commands","line_end":247,"severity":"medium","line_start":247},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Validate the rule shape before suggesting it**: one effect per rule, latency needs `read_ms` or","category":"external_commands","line_end":249,"severity":"medium","line_start":249},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Always include teardown in CI**: `mirrord chaos delete -s <session>` to clear the rules, and `m","category":"external_commands","line_end":250,"severity":"medium","line_start":250},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Generate `payments-timeout.json`: `connection_error` effect with `\"type\": \"timed_out\"`, selector ","category":"external_commands","line_end":258,"severity":"medium","line_start":258},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Provide the `mirrord chaos add -s <session> -f payments-timeout.json` command, and the matching `","category":"external_commands","line_end":259,"severity":"medium","line_start":259},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Point out that the output includes the rule `id` needed to `edit` or `delete` it later.","category":"external_commands","line_end":260,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:204:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"for i in $(seq 1 10); do","category":"external_commands","line_end":204,"severity":"medium","line_start":204},{"id":"external_commands:SKILL.md:205:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"SESSION_ID=\"$(mirrord session list 2>/dev/null \\","category":"external_commands","line_end":206,"severity":"medium","line_start":205},{"id":"external_commands:SKILL.md:196:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```yaml","category":"external_commands","line_end":225,"severity":"medium","line_start":196},{"id":"network:SKILL.md:34:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Never** instruct or generate remote pipe-to-shell installs (downloading a script and executing i","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:SKILL.md:58:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| **CLI** | mirrord CLI **3.241.0+** for the `mirrord chaos` command. Older CLIs (3.232.0+) can mana","category":"network","line_end":58,"severity":"low","line_start":58},{"id":"network:SKILL.md:264:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Chaos Testing docs](https://metalbear.com/mirrord/docs/use-cases/chaos-testing)","category":"network","line_end":264,"severity":"low","line_start":264},{"id":"network:SKILL.md:265:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Local UI docs](https://metalbear.com/mirrord/docs/using-mirrord/local-ui): the dashboard for mana","category":"network","line_end":265,"severity":"low","line_start":265},{"id":"network:SKILL.md:266:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Filtering Outgoing Traffic](https://metalbear.com/mirrord/docs/using-mirrord/outgoing-traffic/fil","category":"network","line_end":266,"severity":"low","line_start":266},{"id":"filesystem:SKILL.md:205:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"SESSION_ID=\"$(mirrord session list 2>/dev/null \\","category":"filesystem","line_end":205,"severity":"low","line_start":205},{"id":"blocker:SKILL.md:257:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"1. Confirm a mirrord session is running, and the payments API hostname as the session sees it.","category":"blocker","line_end":257,"severity":"low","line_start":257}],"finding_verdicts":[{"id":"blocker:README.md:8:system-reconnaissance","reason":"The text describes identifying a mirrord session or generating a rule file for the documented test workflow. It is operational context, not unauthorized system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:4:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:204:shell-command-substitution","reason":"The command substitution reads the mirrord session table and uses bounded retries to obtain a session ID for the documented CI workflow. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:205:shell-command-substitution","reason":"The command substitution reads the mirrord session table and uses bounded retries to obtain a session ID for the documented CI workflow. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:196:template-literal-with-command-substitution","reason":"The match is Markdown prose, an inline code reference, or a fixed mirrord CLI example. It documents an intentional testing workflow and does not show untrusted command construction or malicious execution.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:34:hardcoded-url","reason":"The URLs are official mirrord documentation links or text that explicitly prohibits remote pipe-to-shell installation. No data transfer or download-and-execute behavior is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:58:hardcoded-url","reason":"The URLs are official mirrord documentation links or text that explicitly prohibits remote pipe-to-shell installation. No data transfer or download-and-execute behavior is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:264:hardcoded-url","reason":"The URLs are official mirrord documentation links or text that explicitly prohibits remote pipe-to-shell installation. No data transfer or download-and-execute behavior is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:265:hardcoded-url","reason":"The URLs are official mirrord documentation links or text that explicitly prohibits remote pipe-to-shell installation. No data transfer or download-and-execute behavior is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:266:hardcoded-url","reason":"The URLs are official mirrord documentation links or text that explicitly prohibits remote pipe-to-shell installation. No data transfer or download-and-execute behavior is shown.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:205:standard-device-file-access","reason":"The file access is a shell pipeline reading local session-list output for CI session discovery. No sensitive file collection or destructive filesystem operation is shown.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:257:system-reconnaissance","reason":"The text describes identifying a mirrord session or generating a rule file for the documented test workflow. It is operational context, not unauthorized system reconnaissance.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","subject_content_hash":"2d29e0360d17f010d194f2969eb8ef065aeedc0c8921776fec82d0e65cb0e6bf","subject_tree_hash":"6469466b0a0a4edc1229abc3825c6441bda498ff30804f80cadcc77d24daed81","subject_plugin_path":"skills/metalbear-co/mirrord-chaos","audit_payload_hash":"a9d5c805043cec808b3ff491916e2d30","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","contentHash":"2d29e0360d17f010d194f2969eb8ef065aeedc0c8921776fec82d0e65cb0e6bf","treeHash":"6469466b0a0a4edc1229abc3825c6441bda498ff30804f80cadcc77d24daed81","pluginPath":"skills/metalbear-co/mirrord-chaos","auditPayloadHash":"a9d5c805043cec808b3ff491916e2d30"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/metalbear-co-mirrord-chaos/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}