{"data":{"skill":{"slug":"metalbear-co-mirrord-ci","name":"mirrord-ci","icon":"📦","repo":"https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-ci","status":"approved","author":"metalbear-co","authorVersion":"1.4","skillstoreRevision":1},"audit":{"id":"55e729d7-f366-45c7-8881-511ae0e62a9f","skill_id":"7ae3900d-e413-4d71-8b51-64fc17027f03","version":1,"content_hash":"v3:bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2:73bc8a4f38bfe2f15b5e34ff9f2db653101add3e0349c29f3116725555e247bf:a848c7cf96b3dd6f461a7b01a4fcda1d38d667e7139c6c7be42b866fc699014d:736b696c6c732f6d6574616c626561722d636f2f6d6972726f72642d6369:7d75381d6f122d0ef2199faece974919","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Of 400 supplied alerts, 399 concern documentation or intended CI operations; signature removal presents a genuine integrity risk. Four semantic findings cover certificate bypass, privileged containers, cluster-wide network changes, and unsupported isolation assurances. No evidence found of prompt injection or covert exfiltration; two omitted static matches still require manual review. Static review was capped at 400/402 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.","remediation":[{"issue":"Static review capped","severity":"medium","suggestion":"Manually review the omitted 2 static analyzer matches or reduce bundled generated/vendor/reference content before enabling automatic publication."},{"issue":"Troubleshooting removes binary signatures with sudo.","severity":"high","suggestion":"Prefer compatible development binaries. Require explicit approval for signature changes, restrict changes to disposable copies, and avoid sudo when ownership permits."},{"issue":"Certificate errors are addressed by trusting every certificate.","severity":"high","suggestion":"Configure the correct certificate chain and trust roots. Restrict any temporary bypass to isolated diagnostics with explicit approval and immediate restoration."},{"issue":"Permission failures trigger privileged container recommendations.","severity":"high","suggestion":"Diagnose RBAC, filesystem permissions, and security policies first. Require cluster administrator approval and document narrower capabilities before enabling privileged agents."},{"issue":"The Cilium workaround changes shared networking infrastructure.","severity":"medium","suggestion":"Require administrator approval, a tested maintenance plan, and rollback steps. Pin the chart version and test changes outside shared clusters."},{"issue":"Isolation claims omit potential shared dependency writes.","severity":"medium","suggestion":"Qualify the isolation claim. Add explicit traffic filters, isolated test data, database branches where supported, and approval before accessing shared services."},{"issue":"The supplied static catalog excludes two lower-priority or repeated matches.","severity":"low","suggestion":"Provide the two omitted matches for manual adjudication before automatic publication."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":94,"line_start":94},{"file":"references/schema.json","line_end":102,"line_start":102},{"file":"references/schema.json","line_end":110,"line_start":110},{"file":"references/schema.json","line_end":126,"line_start":126},{"file":"references/schema.json","line_end":134,"line_start":134},{"file":"references/schema.json","line_end":146,"line_start":146},{"file":"references/schema.json","line_end":154,"line_start":154},{"file":"references/schema.json","line_end":166,"line_start":166},{"file":"references/schema.json","line_end":220,"line_start":178},{"file":"references/schema.json","line_end":230,"line_start":220},{"file":"references/schema.json","line_end":230,"line_start":230},{"file":"references/schema.json","line_end":247,"line_start":247},{"file":"references/schema.json","line_end":317,"line_start":317},{"file":"references/schema.json","line_end":322,"line_start":322},{"file":"references/schema.json","line_end":359,"line_start":359},{"file":"references/schema.json","line_end":397,"line_start":381},{"file":"references/schema.json","line_end":405,"line_start":397},{"file":"references/schema.json","line_end":405,"line_start":405},{"file":"references/schema.json","line_end":417,"line_start":417},{"file":"references/schema.json","line_end":425,"line_start":425},{"file":"references/schema.json","line_end":436,"line_start":436},{"file":"references/schema.json","line_end":444,"line_start":444},{"file":"references/schema.json","line_end":452,"line_start":452},{"file":"references/schema.json","line_end":463,"line_start":463},{"file":"references/schema.json","line_end":491,"line_start":491},{"file":"references/schema.json","line_end":507,"line_start":507},{"file":"references/schema.json","line_end":515,"line_start":515},{"file":"references/schema.json","line_end":526,"line_start":526},{"file":"references/schema.json","line_end":542,"line_start":534},{"file":"references/schema.json","line_end":542,"line_start":542},{"file":"references/schema.json","line_end":566,"line_start":566},{"file":"references/schema.json","line_end":584,"line_start":574},{"file":"references/schema.json","line_end":584,"line_start":584},{"file":"references/schema.json","line_end":610,"line_start":595},{"file":"references/schema.json","line_end":617,"line_start":610},{"file":"references/schema.json","line_end":658,"line_start":617},{"file":"references/schema.json","line_end":658,"line_start":658},{"file":"references/schema.json","line_end":683,"line_start":683},{"file":"references/schema.json","line_end":688,"line_start":688},{"file":"references/schema.json","line_end":698,"line_start":698},{"file":"references/schema.json","line_end":729,"line_start":724},{"file":"references/schema.json","line_end":729,"line_start":729},{"file":"references/schema.json","line_end":740,"line_start":740},{"file":"references/schema.json","line_end":764,"line_start":756},{"file":"references/schema.json","line_end":764,"line_start":764},{"file":"references/schema.json","line_end":772,"line_start":772},{"file":"references/schema.json","line_end":781,"line_start":781},{"file":"references/schema.json","line_end":818,"line_start":818},{"file":"references/schema.json","line_end":886,"line_start":886}]},{"factor":"network","evidence":[{"file":"references/schema.json","line_end":220,"line_start":220},{"file":"references/schema.json","line_end":3173,"line_start":3173},{"file":"references/schema.json","line_end":2,"line_start":2},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":212,"line_start":212},{"file":"references/schema.json","line_end":230,"line_start":230},{"file":"references/schema.json","line_end":381,"line_start":381},{"file":"references/schema.json","line_end":417,"line_start":417},{"file":"references/schema.json","line_end":425,"line_start":425},{"file":"references/schema.json","line_end":658,"line_start":658},{"file":"references/schema.json","line_end":818,"line_start":818},{"file":"references/schema.json","line_end":1356,"line_start":1356},{"file":"references/schema.json","line_end":1462,"line_start":1462},{"file":"references/schema.json","line_end":1494,"line_start":1494},{"file":"references/schema.json","line_end":1564,"line_start":1564},{"file":"references/schema.json","line_end":1572,"line_start":1572},{"file":"references/schema.json","line_end":1657,"line_start":1657},{"file":"references/schema.json","line_end":1662,"line_start":1662},{"file":"references/schema.json","line_end":1807,"line_start":1807},{"file":"references/schema.json","line_end":1867,"line_start":1867},{"file":"references/schema.json","line_end":1875,"line_start":1875},{"file":"references/schema.json","line_end":1883,"line_start":1883},{"file":"references/schema.json","line_end":1935,"line_start":1935},{"file":"references/schema.json","line_end":2058,"line_start":2058},{"file":"references/schema.json","line_end":2105,"line_start":2105},{"file":"references/schema.json","line_end":2118,"line_start":2118},{"file":"references/schema.json","line_end":2453,"line_start":2453},{"file":"references/schema.json","line_end":2501,"line_start":2501},{"file":"references/schema.json","line_end":2542,"line_start":2542},{"file":"references/schema.json","line_end":3447,"line_start":3447},{"file":"references/schema.json","line_end":3454,"line_start":3454},{"file":"references/schema.json","line_end":3490,"line_start":3490},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":491,"line_start":491},{"file":"references/schema.json","line_end":772,"line_start":772},{"file":"references/schema.json","line_end":1325,"line_start":1325},{"file":"references/schema.json","line_end":1595,"line_start":1595},{"file":"references/schema.json","line_end":1657,"line_start":1657},{"file":"references/schema.json","line_end":2453,"line_start":2453},{"file":"references/schema.json","line_end":2501,"line_start":2501},{"file":"references/schema.json","line_end":2556,"line_start":2556},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":179,"line_start":179},{"file":"SKILL.md","line_end":205,"line_start":205},{"file":"SKILL.md","line_end":441,"line_start":441},{"file":"SKILL.md","line_end":442,"line_start":442},{"file":"SKILL.md","line_end":443,"line_start":443}]},{"factor":"filesystem","evidence":[{"file":"references/schema.json","line_end":280,"line_start":280},{"file":"references/schema.json","line_end":292,"line_start":292},{"file":"references/schema.json","line_end":304,"line_start":304},{"file":"references/schema.json","line_end":247,"line_start":247},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":110,"line_start":110},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":110,"line_start":110},{"file":"references/schema.json","line_end":2969,"line_start":2969},{"file":"references/schema.json","line_end":1580,"line_start":1580},{"file":"references/schema.json","line_end":247,"line_start":247},{"file":"references/schema.json","line_end":683,"line_start":683},{"file":"references/schema.json","line_end":688,"line_start":688},{"file":"references/troubleshooting.md","line_end":70,"line_start":70},{"file":"references/troubleshooting.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":173,"line_start":173},{"file":"SKILL.md","line_end":174,"line_start":174},{"file":"SKILL.md","line_end":209,"line_start":209},{"file":"SKILL.md","line_end":210,"line_start":210},{"file":"SKILL.md","line_end":234,"line_start":234},{"file":"SKILL.md","line_end":235,"line_start":235},{"file":"SKILL.md","line_end":173,"line_start":173},{"file":"SKILL.md","line_end":174,"line_start":174},{"file":"SKILL.md","line_end":209,"line_start":209},{"file":"SKILL.md","line_end":210,"line_start":210},{"file":"SKILL.md","line_end":234,"line_start":234},{"file":"SKILL.md","line_end":235,"line_start":235},{"file":"SKILL.md","line_end":147,"line_start":147},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":353,"line_start":353}]},{"factor":"env_access","evidence":[{"file":"references/schema.json","line_end":2667,"line_start":2667},{"file":"references/schema.json","line_end":2722,"line_start":2722},{"file":"references/schema.json","line_end":1129,"line_start":1129},{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":186,"line_start":186},{"file":"SKILL.md","line_end":217,"line_start":217},{"file":"SKILL.md","line_end":245,"line_start":245},{"file":"SKILL.md","line_end":263,"line_start":263},{"file":"SKILL.md","line_end":354,"line_start":354},{"file":"SKILL.md","line_end":422,"line_start":422},{"file":"SKILL.md","line_end":437,"line_start":437}]}],"critical_findings":[],"high_findings":[{"title":"sudo privilege escalation","locations":[{"file":"references/troubleshooting.md","line_end":15,"line_start":15}],"confidence":0.98,"description":"`sudo codesign --remove-signature ./<your-binary>`","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"The command uses sudo to remove a copied binary's signature for SIP troubleshooting. This weakens binary integrity protections despite its legitimate compatibility purpose."},{"title":"Troubleshooting Recommends Disabling Certificate Validation","locations":[{"file":"SKILL.md","line_end":367,"line_start":367},{"file":"references/troubleshooting.md","line_end":119,"line_start":107}],"confidence":0.99,"description":"The guidance recommends \"trust_any_certificate\": true for certificate errors and states that every certificate becomes trusted. This can expose application connections to server impersonation and interception.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The troubleshooting example explicitly enables universal certificate trust without limiting it to an isolated diagnostic session or requiring restoration."},{"title":"Permission Troubleshooting Broadens Container Privileges","locations":[{"file":"SKILL.md","line_end":365,"line_start":365},{"file":"references/troubleshooting.md","line_end":101,"line_start":91}],"confidence":0.97,"description":"The instructions recommend \"privileged\": true for permission or DNS failures. Privileged agents weaken container isolation and can expose the host when compromised.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The advice directly enables privileged execution without requiring administrator approval or evaluating narrower permissions. Actual exposure depends on deployment policy."}],"medium_findings":[{"title":"CI Troubleshooting Changes Cluster-Wide Networking","locations":[{"file":"references/troubleshooting.md","line_end":60,"line_start":49}],"confidence":0.96,"description":"The Cilium workaround upgrades the release in kube-system and restarts its DaemonSet. Applying it without administrator review can disrupt networking for unrelated workloads.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The commands directly change cluster networking infrastructure, but the surrounding instructions provide no change approval, maintenance window, or rollback requirement."},{"title":"Isolation Assurance Omits Shared Dependency Side Effects","locations":[{"file":"SKILL.md","line_end":56,"line_start":51},{"file":"SKILL.md","line_end":189,"line_start":182},{"file":"references/schema.json","line_end":2501,"line_start":2501}],"confidence":0.92,"description":"The skill promises isolated execution without workload interference, but its examples connect directly to shared services without configuring database or traffic isolation. Tests can therefore modify shared data or trigger downstream effects.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The unconditional assurance exceeds the protections configured in the examples. The schema documents outbound traffic tunneling, which does not itself isolate dependency writes."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":4165,"audit_model":"codex","audited_at":"2026-09-29T21:26:40.264+00:00","created_at":"2026-09-30T13:38:15.566691+00:00","static_findings":[{"id":"sensitive:references/schema.json:230:gcp-credentials-directory","file":"references/schema.json","pattern":"GCP credentials directory","snippet":"\"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"read\\\"","category":"sensitive","line_end":230,"severity":"critical","line_start":230},{"id":"sensitive:references/schema.json:4:kubernetes-config-file","file":"references/schema.json","pattern":"Kubernetes config file","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"sensitive","line_end":4,"severity":"critical","line_start":4},{"id":"sensitive:references/schema.json:110:kubernetes-config-file","file":"references/schema.json","pattern":"Kubernetes config file","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"sensitive","line_end":110,"severity":"critical","line_start":110},{"id":"sensitive:SKILL.md:174:kubernetes-config-file","file":"SKILL.md","pattern":"Kubernetes config file","snippet":"echo \"${{ secrets.KUBECONFIG }}\" | base64 -d > ~/.kube/config","category":"sensitive","line_end":174,"severity":"critical","line_start":174},{"id":"sensitive:SKILL.md:210:kubernetes-config-file","file":"SKILL.md","pattern":"Kubernetes config file","snippet":"- echo \"$KUBECONFIG_CONTENT\" | base64 -d > ~/.kube/config","category":"sensitive","line_end":210,"severity":"critical","line_start":210},{"id":"sensitive:SKILL.md:235:kubernetes-config-file","file":"SKILL.md","pattern":"Kubernetes config file","snippet":"echo \"$KUBECONFIG_B64\" | base64 -d > ~/.kube/config","category":"sensitive","line_end":235,"severity":"critical","line_start":235},{"id":"sensitive:references/schema.json:764:certificate-key-files","file":"references/schema.json","pattern":"Certificate/key files","snippet":"\"description\": \"When using`mirrord container` with external_proxy TLS enabled (is enabled by default","category":"sensitive","line_end":764,"severity":"high","line_start":764},{"id":"sensitive:references/schema.json:2267:certificate-key-files","file":"references/schema.json","pattern":"Certificate/key files","snippet":"\"description\": \"Stolen TLS traffic can be delivered to the local application either as TLS or as pla","category":"sensitive","line_end":2267,"severity":"high","line_start":2267},{"id":"sensitive:references/schema.json:2283:crypto-seed-private-key-mention","file":"references/schema.json","pattern":"Crypto seed/private key mention","snippet":"\"description\": \"Path to a PEM file containing the certificate chain used by the local application's ","category":"sensitive","line_end":2283,"severity":"high","line_start":2283},{"id":"sensitive:references/schema.json:2299:crypto-seed-private-key-mention","file":"references/schema.json","pattern":"Crypto seed/private key mention","snippet":"\"description\": \"Paths to PEM files and directories with PEM files containing allowed root certificat","category":"sensitive","line_end":2299,"severity":"high","line_start":2299},{"id":"sensitive:references/schema.json:1360:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.env_file {#feature-env-env-file}\",","category":"sensitive","line_end":1360,"severity":"high","line_start":1360},{"id":"sensitive:references/schema.json:1368:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.exclude {#feature-env-exclude}\",","category":"sensitive","line_end":1368,"severity":"high","line_start":1368},{"id":"sensitive:references/schema.json:1380:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.include {#feature-env-include}\",","category":"sensitive","line_end":1380,"severity":"high","line_start":1380},{"id":"sensitive:references/schema.json:1392:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.load_from_process {#feature-env-load_from_process}\",","category":"sensitive","line_end":1392,"severity":"high","line_start":1392},{"id":"sensitive:references/schema.json:1400:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.mapping {#feature-env-mapping}\",","category":"sensitive","line_end":1400,"severity":"high","line_start":1400},{"id":"sensitive:references/schema.json:1411:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.override {#feature-env-override}\",","category":"sensitive","line_end":1411,"severity":"high","line_start":1411},{"id":"sensitive:references/schema.json:1422:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.unset {#feature-env-unset}\",","category":"sensitive","line_end":1422,"severity":"high","line_start":1422},{"id":"sensitive:references/schema.json:1685:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env {#feature-env}\",","category":"sensitive","line_end":1685,"severity":"high","line_start":1685},{"id":"sensitive:references/troubleshooting.md:133:environment-file-access","file":"references/troubleshooting.md","pattern":"Environment file access","snippet":"To fix this, use `feature.env.exclude` to prevent mirrord from importing these specific variables:","category":"sensitive","line_end":133,"severity":"high","line_start":133},{"id":"obfuscation:references/schema.json:1828:heuristic-extremely-long-line-2304-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2304 chars) - likely obfuscated","snippet":"      \"description\": \"Filter configuration for the HTTP traffic stealer feature.\\n\\nAllows the user ","category":"obfuscation","line_end":1828,"severity":"high","line_start":1828},{"id":"obfuscation:references/schema.json:3490:heuristic-extremely-long-line-2479-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2479 chars) - likely obfuscated","snippet":"      \"description\": \"Quantity is a fixed-point representation of a number. It provides convenient m","category":"obfuscation","line_end":3490,"severity":"high","line_start":3490},{"id":"obfuscation:references/schema.json:4:heuristic-extremely-long-line-3222-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (3222 chars) - likely obfuscated","snippet":"  \"description\": \"mirrord allows for a high degree of customization when it comes to which features ","category":"obfuscation","line_end":4,"severity":"high","line_start":4},{"id":"obfuscation:references/schema.json:230:heuristic-extremely-long-line-3367-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (3367 chars) - likely obfuscated","snippet":"      \"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"","category":"obfuscation","line_end":230,"severity":"high","line_start":230},{"id":"env_access:references/schema.json:2667:aws-credential-environment-variables","file":"references/schema.json","pattern":"AWS credential environment variables","snippet":"\"description\": \"For AWS RDS/Aurora IAM authentication, set `type` to `\\\"aws_rds\\\"`.\\n\\nExample: ```j","category":"env_access","line_end":2667,"severity":"high","line_start":2667},{"id":"env_access:references/schema.json:1129:database-connection-strings","file":"references/schema.json","pattern":"Database connection strings","snippet":"\"description\": \"When configuring a branch for Redis, set `type` to `redis`.\\n\\nExample with URL-base","category":"env_access","line_end":1129,"severity":"high","line_start":1129},{"id":"env_access:references/schema.json:2722:gcp-credential-environment-variables","file":"references/schema.json","pattern":"GCP credential environment variables","snippet":"\"description\": \"For GCP Cloud SQL IAM authentication, set `type` to `\\\"gcp_cloud_sql\\\"`.\\n\\nExample ","category":"env_access","line_end":2722,"severity":"high","line_start":2722},{"id":"env_access:SKILL.md:130:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"Store this as a **secret** environment variable named `MIRRORD_CI_API_KEY` in your CI platform.","category":"env_access","line_end":130,"severity":"high","line_start":130},{"id":"env_access:SKILL.md:186:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"MIRRORD_CI_API_KEY: ${{ secrets.MIRRORD_CI_API_KEY }}","category":"env_access","line_end":186,"severity":"high","line_start":186},{"id":"env_access:SKILL.md:217:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"MIRRORD_CI_API_KEY: $MIRRORD_CI_API_KEY","category":"env_access","line_end":217,"severity":"high","line_start":217},{"id":"env_access:SKILL.md:245:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"MIRRORD_CI_API_KEY: ${MIRRORD_CI_API_KEY}","category":"env_access","line_end":245,"severity":"high","line_start":245},{"id":"env_access:SKILL.md:263:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"MIRRORD_CI_API_KEY = credentials('mirrord-ci-api-key')","category":"env_access","line_end":263,"severity":"high","line_start":263},{"id":"env_access:SKILL.md:354:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"| \"Seats being consumed\" | Set `MIRRORD_CI_API_KEY` environment variable |","category":"env_access","line_end":354,"severity":"high","line_start":354},{"id":"env_access:SKILL.md:422:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"5. **Mention API key** - Remind about `MIRRORD_CI_API_KEY` for Enterprise users","category":"env_access","line_end":422,"severity":"high","line_start":422},{"id":"env_access:SKILL.md:437:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"4. Mention: `MIRRORD_CI_API_KEY` if using the Enterprise plan","category":"env_access","line_end":437,"severity":"high","line_start":437},{"id":"filesystem:references/schema.json:4:hidden-file-in-home-directory","file":"references/schema.json","pattern":"Hidden file in home directory","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"filesystem","line_end":4,"severity":"high","line_start":4},{"id":"filesystem:references/schema.json:110:hidden-file-in-home-directory","file":"references/schema.json","pattern":"Hidden file in home directory","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"filesystem","line_end":110,"severity":"high","line_start":110},{"id":"filesystem:SKILL.md:173:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"mkdir -p ~/.kube","category":"filesystem","line_end":173,"severity":"high","line_start":173},{"id":"filesystem:SKILL.md:174:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"echo \"${{ secrets.KUBECONFIG }}\" | base64 -d > ~/.kube/config","category":"filesystem","line_end":174,"severity":"high","line_start":174},{"id":"filesystem:SKILL.md:209:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"- mkdir -p ~/.kube","category":"filesystem","line_end":209,"severity":"high","line_start":209},{"id":"filesystem:SKILL.md:210:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"- echo \"$KUBECONFIG_CONTENT\" | base64 -d > ~/.kube/config","category":"filesystem","line_end":210,"severity":"high","line_start":210},{"id":"filesystem:SKILL.md:234:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"mkdir -p ~/.kube","category":"filesystem","line_end":234,"severity":"high","line_start":234},{"id":"filesystem:SKILL.md:235:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"echo \"$KUBECONFIG_B64\" | base64 -d > ~/.kube/config","category":"filesystem","line_end":235,"severity":"high","line_start":235},{"id":"filesystem:references/schema.json:247:non-standard-device-file-access","file":"references/schema.json","pattern":"Non-standard device file access","snippet":"\"description\": \"Specify map of patterns that if matched will replace the path according to specifica","category":"filesystem","line_end":247,"severity":"high","line_start":247},{"id":"filesystem:references/schema.json:247:path-traversal-sequence","file":"references/schema.json","pattern":"Path traversal sequence","snippet":"\"description\": \"Specify map of patterns that if matched will replace the path according to specifica","category":"filesystem","line_end":247,"severity":"high","line_start":247},{"id":"external_commands:references/troubleshooting.md:15:sudo-privilege-escalation","file":"references/troubleshooting.md","pattern":"sudo privilege escalation","snippet":"`sudo codesign --remove-signature ./<your-binary>`","category":"external_commands","line_end":15,"severity":"high","line_start":15},{"id":"sensitive:references/schema.json:897:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection (type: mysql, pg, mongodb) {#feature-db_branches-sql-conn","category":"sensitive","line_end":897,"severity":"medium","line_start":897},{"id":"sensitive:references/schema.json:917:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].creation_timeout_secs (type: mysql, pg, mongodb) {#feature-db_branch","category":"sensitive","line_end":917,"severity":"medium","line_start":917},{"id":"sensitive:references/schema.json:925:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].id (type: mysql, pg, mongodb) {#feature-db_branches-sql-id}\",","category":"sensitive","line_end":925,"severity":"medium","line_start":925},{"id":"sensitive:references/schema.json:933:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].name (type: mysql, pg, mongodb) {#feature-db_branches-sql-name}\",","category":"sensitive","line_end":933,"severity":"medium","line_start":933},{"id":"sensitive:references/schema.json:941:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].ttl_secs (type: mysql, pg, mongodb) {#feature-db_branches-sql-ttl_se","category":"sensitive","line_end":941,"severity":"medium","line_start":941},{"id":"sensitive:references/schema.json:955:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].version (type: mysql, pg, mongodb) {#feature-db_branches-sql-version","category":"sensitive","line_end":955,"severity":"medium","line_start":955},{"id":"sensitive:references/schema.json:973:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection (type: mysql, pg, mongodb) {#feature-db_branches-sql-conn","category":"sensitive","line_end":973,"severity":"medium","line_start":973},{"id":"sensitive:references/schema.json:993:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].creation_timeout_secs (type: mysql, pg, mongodb) {#feature-db_branch","category":"sensitive","line_end":993,"severity":"medium","line_start":993},{"id":"sensitive:references/schema.json:1001:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].id (type: mysql, pg, mongodb) {#feature-db_branches-sql-id}\",","category":"sensitive","line_end":1001,"severity":"medium","line_start":1001},{"id":"sensitive:references/schema.json:1009:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].name (type: mysql, pg, mongodb) {#feature-db_branches-sql-name}\",","category":"sensitive","line_end":1009,"severity":"medium","line_start":1009},{"id":"sensitive:references/schema.json:1017:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].ttl_secs (type: mysql, pg, mongodb) {#feature-db_branches-sql-ttl_se","category":"sensitive","line_end":1017,"severity":"medium","line_start":1017},{"id":"sensitive:references/schema.json:1031:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].version (type: mysql, pg, mongodb) {#feature-db_branches-sql-version","category":"sensitive","line_end":1031,"severity":"medium","line_start":1031},{"id":"sensitive:references/schema.json:1049:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection (type: mysql, pg, mongodb) {#feature-db_branches-sql-conn","category":"sensitive","line_end":1049,"severity":"medium","line_start":1049},{"id":"sensitive:references/schema.json:1069:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].creation_timeout_secs (type: mysql, pg, mongodb) {#feature-db_branch","category":"sensitive","line_end":1069,"severity":"medium","line_start":1069},{"id":"sensitive:references/schema.json:1077:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: pg) {#feature-db_branches-pg-iam_auth}\",","category":"sensitive","line_end":1077,"severity":"medium","line_start":1077},{"id":"sensitive:references/schema.json:1089:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].id (type: mysql, pg, mongodb) {#feature-db_branches-sql-id}\",","category":"sensitive","line_end":1089,"severity":"medium","line_start":1089},{"id":"sensitive:references/schema.json:1097:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].name (type: mysql, pg, mongodb) {#feature-db_branches-sql-name}\",","category":"sensitive","line_end":1097,"severity":"medium","line_start":1097},{"id":"sensitive:references/schema.json:1105:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].ttl_secs (type: mysql, pg, mongodb) {#feature-db_branches-sql-ttl_se","category":"sensitive","line_end":1105,"severity":"medium","line_start":1105},{"id":"sensitive:references/schema.json:1119:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].version (type: mysql, pg, mongodb) {#feature-db_branches-sql-version","category":"sensitive","line_end":1119,"severity":"medium","line_start":1119},{"id":"sensitive:references/schema.json:1136:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection (type: redis) {#feature-db_branches-redis-connection}\",","category":"sensitive","line_end":1136,"severity":"medium","line_start":1136},{"id":"sensitive:references/schema.json:1154:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].id (type: redis) {#feature-db_branches-redis-id}\",","category":"sensitive","line_end":1154,"severity":"medium","line_start":1154},{"id":"sensitive:references/schema.json:1163:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local (type: redis) {#feature-db_branches-redis-local}\",","category":"sensitive","line_end":1163,"severity":"medium","line_start":1163},{"id":"sensitive:references/schema.json:1183:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].location (type: redis) {#feature-db_branches-redis-location}\",","category":"sensitive","line_end":1183,"severity":"medium","line_start":1183},{"id":"sensitive:references/schema.json:1673:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches {#feature-db_branches}\",","category":"sensitive","line_end":1673,"severity":"medium","line_start":1673},{"id":"sensitive:references/schema.json:2849:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.database (type: redis)\",","category":"sensitive","line_end":2849,"severity":"medium","line_start":2849},{"id":"sensitive:references/schema.json:2860:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.host (type: redis)\",","category":"sensitive","line_end":2860,"severity":"medium","line_start":2860},{"id":"sensitive:references/schema.json:2873:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.password (type: redis)\",","category":"sensitive","line_end":2873,"severity":"medium","line_start":2873},{"id":"sensitive:references/schema.json:2886:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.port (type: redis)\",","category":"sensitive","line_end":2886,"severity":"medium","line_start":2886},{"id":"sensitive:references/schema.json:2897:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.tls (type: redis)\",","category":"sensitive","line_end":2897,"severity":"medium","line_start":2897},{"id":"sensitive:references/schema.json:2906:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.url (type: redis)\",","category":"sensitive","line_end":2906,"severity":"medium","line_start":2906},{"id":"sensitive:references/schema.json:2919:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.username (type: redis)\",","category":"sensitive","line_end":2919,"severity":"medium","line_start":2919},{"id":"sensitive:references/schema.json:2968:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.container_command (type: redis)\",","category":"sensitive","line_end":2968,"severity":"medium","line_start":2968},{"id":"sensitive:references/schema.json:2977:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.container_runtime (type: redis)\",","category":"sensitive","line_end":2977,"severity":"medium","line_start":2977},{"id":"sensitive:references/schema.json:2987:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.options (type: redis)\",","category":"sensitive","line_end":2987,"severity":"medium","line_start":2987},{"id":"sensitive:references/schema.json:2999:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.port (type: redis)\",","category":"sensitive","line_end":2999,"severity":"medium","line_start":2999},{"id":"sensitive:references/schema.json:3007:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.runtime (type: redis)\",","category":"sensitive","line_end":3007,"severity":"medium","line_start":3007},{"id":"sensitive:references/schema.json:3017:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.server_command (type: redis)\",","category":"sensitive","line_end":3017,"severity":"medium","line_start":3017},{"id":"sensitive:references/schema.json:3026:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.version (type: redis)\",","category":"sensitive","line_end":3026,"severity":"medium","line_start":3026},{"id":"network:references/schema.json:4:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"network","line_end":4,"severity":"medium","line_start":4},{"id":"network:references/schema.json:491:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Enables prometheus metrics for the agent pod.\\n\\nYou might need to add annotations t","category":"network","line_end":491,"severity":"medium","line_start":491},{"id":"network:references/schema.json:772:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Allows to override the IP address for the internal proxy to use when connecting to t","category":"network","line_end":772,"severity":"medium","line_start":772},{"id":"network:references/schema.json:1325:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"List of addresses/ports/subnets that should be resolved through either the remote po","category":"network","line_end":1325,"severity":"medium","line_start":1325},{"id":"network:references/schema.json:1595:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Specify a custom host ip addr to listen on.\\n\\nThis address must be accessible from ","category":"network","line_end":1595,"severity":"medium","line_start":1595},{"id":"network:references/schema.json:1657:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Controls mirrord features.\\n\\nSee the [technical reference, Technical Reference](htt","category":"network","line_end":1657,"severity":"medium","line_start":1657},{"id":"network:references/schema.json:2453:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Controls mirrord network operations.\\n\\nSee the network traffic [reference](https://","category":"network","line_end":2453,"severity":"medium","line_start":2453},{"id":"network:references/schema.json:2501:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Tunnel outgoing network operations through mirrord.\\n\\nSee the outgoing [reference](","category":"network","line_end":2501,"severity":"medium","line_start":2501},{"id":"network:references/schema.json:2556:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"List of addresses/ports/subnets that should be sent through either the remote pod or","category":"network","line_end":2556,"severity":"medium","line_start":2556},{"id":"filesystem:references/schema.json:4:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"filesystem","line_end":4,"severity":"medium","line_start":4},{"id":"filesystem:references/schema.json:110:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"filesystem","line_end":110,"severity":"medium","line_start":110},{"id":"filesystem:references/schema.json:2969:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"Custom path to the container command. If not provided, uses the runtime name from PA","category":"filesystem","line_end":2969,"severity":"medium","line_start":2969},{"id":"filesystem:SKILL.md:173:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"mkdir -p ~/.kube","category":"filesystem","line_end":173,"severity":"medium","line_start":173},{"id":"filesystem:SKILL.md:174:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"echo \"${{ secrets.KUBECONFIG }}\" | base64 -d > ~/.kube/config","category":"filesystem","line_end":174,"severity":"medium","line_start":174},{"id":"filesystem:SKILL.md:209:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- mkdir -p ~/.kube","category":"filesystem","line_end":209,"severity":"medium","line_start":209},{"id":"filesystem:SKILL.md:210:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- echo \"$KUBECONFIG_CONTENT\" | base64 -d > ~/.kube/config","category":"filesystem","line_end":210,"severity":"medium","line_start":210},{"id":"filesystem:SKILL.md:234:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"mkdir -p ~/.kube","category":"filesystem","line_end":234,"severity":"medium","line_start":234},{"id":"filesystem:SKILL.md:235:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"echo \"$KUBECONFIG_B64\" | base64 -d > ~/.kube/config","category":"filesystem","line_end":235,"severity":"medium","line_start":235},{"id":"filesystem:references/schema.json:280:node-js-fs-operations","file":"references/schema.json","pattern":"Node.js fs operations","snippet":"\"title\": \"feature.fs.read_only {#feature-fs-read_only}\",","category":"filesystem","line_end":280,"severity":"medium","line_start":280},{"id":"filesystem:references/schema.json:292:node-js-fs-operations","file":"references/schema.json","pattern":"Node.js fs operations","snippet":"\"title\": \"feature.fs.read_write {#feature-fs-read_write}\",","category":"filesystem","line_end":292,"severity":"medium","line_start":292},{"id":"filesystem:references/schema.json:304:node-js-fs-operations","file":"references/schema.json","pattern":"Node.js fs operations","snippet":"\"title\": \"feature.fs.readonly_file_buffer {#feature-fs-readonly_file_buffer}\",","category":"filesystem","line_end":304,"severity":"medium","line_start":304},{"id":"filesystem:references/troubleshooting.md:70:node-js-fs-operations","file":"references/troubleshooting.md","pattern":"Node.js fs operations","snippet":"1. `feature.fs.read_only` if you want read operations to that path to happen remotely, but write ope","category":"filesystem","line_end":70,"severity":"medium","line_start":70},{"id":"filesystem:references/troubleshooting.md:71:node-js-fs-operations","file":"references/troubleshooting.md","pattern":"Node.js fs operations","snippet":"2. `feature.fs.read_write` if you want read and write operations to that path to happen remotely.","category":"filesystem","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:references/schema.json:4:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"external_commands","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:references/schema.json:94:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"An identifier for a mirrord session.\\n\\nThis key can be referenced in your configura","category":"external_commands","line_end":94,"severity":"medium","line_start":94},{"id":"external_commands:references/schema.json:102:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Kube context to use from the kubeconfig file. Will use current context if not specif","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:references/schema.json:110:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"external_commands","line_end":110,"severity":"medium","line_start":110},{"id":"external_commands:references/schema.json:126:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Name of the mirrord profile to use.\\n\\nTo select a cluster-wide profile\\n\\n```json {","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"external_commands:references/schema.json:134:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Binaries to patch (macOS SIP).\\n\\nUse this when mirrord isn't loaded to protected bi","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:references/schema.json:146:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip build tools. Useful when running command lines that build and","category":"external_commands","line_end":146,"severity":"medium","line_start":146},{"id":"external_commands:references/schema.json:154:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip the specified build tools. Useful when running command lines ","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:references/schema.json:166:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip unwanted processes.\\n\\nUseful when process A spawns process B","category":"external_commands","line_end":166,"severity":"medium","line_start":166},{"id":"external_commands:references/schema.json:178:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip patching (macOS SIP) unwanted processes.\\n\\nWhen patching is ","category":"external_commands","line_end":220,"severity":"medium","line_start":178},{"id":"external_commands:references/schema.json:220:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When disabled, mirrord will remove `HTTP[S]_PROXY` env variables before doing any ne","category":"external_commands","line_end":230,"severity":"medium","line_start":220},{"id":"external_commands:references/schema.json:230:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"read\\\"","category":"external_commands","line_end":230,"severity":"medium","line_start":230},{"id":"external_commands:references/schema.json:247:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify map of patterns that if matched will replace the path according to specifica","category":"external_commands","line_end":247,"severity":"medium","line_start":247},{"id":"external_commands:references/schema.json:317:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for the mirrord-agent pod that is spawned in the Kubernetes cluster.\\n","category":"external_commands","line_end":317,"severity":"medium","line_start":317},{"id":"external_commands:references/schema.json:322:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom annotations for the agent Job and Pod.\\n\\n```json { \\\"agent","category":"external_commands","line_end":322,"severity":"medium","line_start":322},{"id":"external_commands:references/schema.json:359:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"If nothing is disabled here, agent uses: 1. `NET_ADMIN`, 2. `SYS_PTRACE`, 3. `SYS_AD","category":"external_commands","line_end":359,"severity":"medium","line_start":359},{"id":"external_commands:references/schema.json:381:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Runs the agent as an [ephemeral container](https://kubernetes.io/docs/concepts/workl","category":"external_commands","line_end":397,"severity":"medium","line_start":381},{"id":"external_commands:references/schema.json:397:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Flushes existing connections when starting to steal, might fix issues where connecti","category":"external_commands","line_end":405,"severity":"medium","line_start":397},{"id":"external_commands:references/schema.json:405:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Name of the agent's docker image.\\n\\nUseful when a custom build of mirrord-agent is ","category":"external_commands","line_end":405,"severity":"medium","line_start":405},{"id":"external_commands:references/schema.json:417:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls when a new agent image is downloaded.\\n\\nSupports `\\\"IfNotPresent\\\"`, `\\\"Al","category":"external_commands","line_end":417,"severity":"medium","line_start":417},{"id":"external_commands:references/schema.json:425:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"List of secrets the agent pod has access to.\\n\\nTakes an array of entries with the f","category":"external_commands","line_end":425,"severity":"medium","line_start":425},{"id":"external_commands:references/schema.json:436:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Sets whether `Mirrord-Agent` headers are injected into HTTP responses that went thro","category":"external_commands","line_end":436,"severity":"medium","line_start":436},{"id":"external_commands:references/schema.json:444:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls whether the agent produces logs in a human-friendly format, or json.\\n\\n```","category":"external_commands","line_end":444,"severity":"medium","line_start":444},{"id":"external_commands:references/schema.json:452:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom labels for the agent Job and Pod.\\n\\n```json { \\\"agent\\\": {","category":"external_commands","line_end":452,"severity":"medium","line_start":452},{"id":"external_commands:references/schema.json:463:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Log level for the agent.\\n\\nSupports `\\\"trace\\\"`, `\\\"debug\\\"`, `\\\"info\\\"`, `\\\"warn\\\"","category":"external_commands","line_end":463,"severity":"medium","line_start":463},{"id":"external_commands:references/schema.json:491:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Enables prometheus metrics for the agent pod.\\n\\nYou might need to add annotations t","category":"external_commands","line_end":491,"severity":"medium","line_start":491},{"id":"external_commands:references/schema.json:507:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Determines which iptables backend will be used for traffic redirection.\\n\\nIf set to","category":"external_commands","line_end":507,"severity":"medium","line_start":507},{"id":"external_commands:references/schema.json:515:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom node selector for the agent Pod. Applies only to targetless","category":"external_commands","line_end":515,"severity":"medium","line_start":515},{"id":"external_commands:references/schema.json:526:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specifies the priority class to assign to the agent pod.\\n\\n```json { \\\"agent\\\": { \\","category":"external_commands","line_end":526,"severity":"medium","line_start":526},{"id":"external_commands:references/schema.json:534:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Run the mirror agent as privileged container. Defaults to `false`.\\n\\nMight be neede","category":"external_commands","line_end":542,"severity":"medium","line_start":534},{"id":"external_commands:references/schema.json:542:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set pod resource requirements. (not with ephemeral agents) Default is ```json { \\\"ag","category":"external_commands","line_end":542,"severity":"medium","line_start":542},{"id":"external_commands:references/schema.json:566:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom Service Account for the agent Job and Pod.\\n\\n```json { \\\"a","category":"external_commands","line_end":566,"severity":"medium","line_start":566},{"id":"external_commands:references/schema.json:574:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls how long to wait for the agent to finish initialization.\\n\\nIf initializati","category":"external_commands","line_end":584,"severity":"medium","line_start":574},{"id":"external_commands:references/schema.json:584:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set pod tolerations. (not with ephemeral agents).\\n\\nDefaults to `operator: Exists`.","category":"external_commands","line_end":584,"severity":"medium","line_start":584},{"id":"external_commands:references/schema.json:595:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls how long the agent pod persists for after the agent exits (in seconds).\\n\\n","category":"external_commands","line_end":610,"severity":"medium","line_start":595},{"id":"external_commands:references/schema.json:610:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"The shortened version of: `image: \\\"repo/mirrord:latest\\\"`.\",","category":"external_commands","line_end":617,"severity":"medium","line_start":610},{"id":"external_commands:references/schema.json:617:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Expanded version: `image: { registry: \\\"repo/mirrord\\\", tag: \\\"latest\\\" }`.\",","category":"external_commands","line_end":658,"severity":"medium","line_start":617},{"id":"external_commands:references/schema.json:658:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Tries to parse the body as a JSON object and find (a) matching subobjects(s).\\n\\n`qu","category":"external_commands","line_end":658,"severity":"medium","line_start":658},{"id":"external_commands:references/schema.json:683:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for mirrord for CI.\\n\\n```json { \\\"ci\\\": { \\\"output_dir\\\": \\\"/tmp/mirr","category":"external_commands","line_end":683,"severity":"medium","line_start":683},{"id":"external_commands:references/schema.json:688:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Path to a directory where `mirrord ci` will flush application's stdout and stderr.\\n","category":"external_commands","line_end":688,"severity":"medium","line_start":688},{"id":"external_commands:references/schema.json:698:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"(Operator Only): Allows overriding port locks\\n\\nCan be set to either `\\\"continue\\\"`","category":"external_commands","line_end":698,"severity":"medium","line_start":698},{"id":"external_commands:references/schema.json:724:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Unstable: `mirrord container` command specific config.\",","category":"external_commands","line_end":729,"severity":"medium","line_start":724},{"id":"external_commands:references/schema.json:729:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Any extra args to use when creating the sidecar mirrord-cli container.\\n\\nThis is us","category":"external_commands","line_end":729,"severity":"medium","line_start":729},{"id":"external_commands:references/schema.json:740:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Tag of the `mirrord-cli` image you want to use.\\n\\nDefaults to `\\\"ghcr.io/metalbear-","category":"external_commands","line_end":740,"severity":"medium","line_start":740},{"id":"external_commands:references/schema.json:756:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Don't add `--rm` to sidecar command to prevent cleanup.\",","category":"external_commands","line_end":764,"severity":"medium","line_start":756},{"id":"external_commands:references/schema.json:764:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When using`mirrord container` with external_proxy TLS enabled (is enabled by default","category":"external_commands","line_end":764,"severity":"medium","line_start":764},{"id":"external_commands:references/schema.json:772:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows to override the IP address for the internal proxy to use when connecting to t","category":"external_commands","line_end":772,"severity":"medium","line_start":772},{"id":"external_commands:references/schema.json:781:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Platform specification for the target container (e.g., \\\"linux/amd64\\\", \\\"linux/arm6","category":"external_commands","line_end":781,"severity":"medium","line_start":781},{"id":"external_commands:references/schema.json:818:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows the user to target a pod created dynamically from the original [`target`](#ta","category":"external_commands","line_end":818,"severity":"medium","line_start":818},{"id":"external_commands:references/schema.json:886:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json { \\\"id\\\": \\\"my-branch-db","category":"external_commands","line_end":886,"severity":"medium","line_start":886},{"id":"external_commands:references/schema.json:889:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for MongoDB, set `type` to `mongodb`.\",","category":"external_commands","line_end":889,"severity":"medium","line_start":889},{"id":"external_commands:references/schema.json:898:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"`connection` describes how to get the connection information to the source database.","category":"external_commands","line_end":926,"severity":"medium","line_start":898},{"id":"external_commands:references/schema.json:926:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose to specify a unique `id`. This is useful for reusing or sharing the","category":"external_commands","line_end":934,"severity":"medium","line_start":926},{"id":"external_commands:references/schema.json:934:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When source database connection detail is not accessible to mirrord operator, users ","category":"external_commands","line_end":942,"severity":"medium","line_start":934},{"id":"external_commands:references/schema.json:942:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mirrord operator starts counting the TTL when a branch is no longer used by any sess","category":"external_commands","line_end":956,"severity":"medium","line_start":942},{"id":"external_commands:references/schema.json:956:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mirrord operator uses a default version of the database image unless `version` is gi","category":"external_commands","line_end":965,"severity":"medium","line_start":956},{"id":"external_commands:references/schema.json:965:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for MySQL, set `type` to `mysql`.\",","category":"external_commands","line_end":965,"severity":"medium","line_start":965},{"id":"external_commands:references/schema.json:974:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"`connection` describes how to get the connection information to the source database.","category":"external_commands","line_end":1002,"severity":"medium","line_start":974},{"id":"external_commands:references/schema.json:1002:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose to specify a unique `id`. This is useful for reusing or sharing the","category":"external_commands","line_end":1010,"severity":"medium","line_start":1002},{"id":"external_commands:references/schema.json:1010:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When source database connection detail is not accessible to mirrord operator, users ","category":"external_commands","line_end":1018,"severity":"medium","line_start":1010},{"id":"external_commands:references/schema.json:1018:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mirrord operator starts counting the TTL when a branch is no longer used by any sess","category":"external_commands","line_end":1032,"severity":"medium","line_start":1018},{"id":"external_commands:references/schema.json:1032:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mirrord operator uses a default version of the database image unless `version` is gi","category":"external_commands","line_end":1041,"severity":"medium","line_start":1032},{"id":"external_commands:references/schema.json:1041:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for PostgreSQL, set `type` to `pg`.\",","category":"external_commands","line_end":1041,"severity":"medium","line_start":1041},{"id":"external_commands:references/schema.json:1050:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"`connection` describes how to get the connection information to the source database.","category":"external_commands","line_end":1090,"severity":"medium","line_start":1050},{"id":"external_commands:references/schema.json:1090:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose to specify a unique `id`. This is useful for reusing or sharing the","category":"external_commands","line_end":1098,"severity":"medium","line_start":1090},{"id":"external_commands:references/schema.json:1098:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When source database connection detail is not accessible to mirrord operator, users ","category":"external_commands","line_end":1106,"severity":"medium","line_start":1098},{"id":"external_commands:references/schema.json:1106:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mirrord operator starts counting the TTL when a branch is no longer used by any sess","category":"external_commands","line_end":1120,"severity":"medium","line_start":1106},{"id":"external_commands:references/schema.json:1120:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mirrord operator uses a default version of the database image unless `version` is gi","category":"external_commands","line_end":1129,"severity":"medium","line_start":1120},{"id":"external_commands:references/schema.json:1129:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for Redis, set `type` to `redis`.\\n\\nExample with URL-base","category":"external_commands","line_end":1129,"severity":"medium","line_start":1129},{"id":"external_commands:references/schema.json:1164:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Local Redis runtime configuration. Only used when `location` is `local`.\",","category":"external_commands","line_end":1164,"severity":"medium","line_start":1164},{"id":"external_commands:references/schema.json:1184:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Where the Redis instance should run. - `local`: Spawns a local Redis instance manage","category":"external_commands","line_end":1184,"severity":"medium","line_start":1184},{"id":"external_commands:references/schema.json:1203:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"A list of configurations for database branches.\\n\\n```json { \\\"feature\\\": { \\\"db_bra","category":"external_commands","line_end":1203,"severity":"medium","line_start":1203},{"id":"external_commands:references/schema.json:1210:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Different ways of connecting to the source database.\\n\\nExample:\\n\\nA single complet","category":"external_commands","line_end":1210,"severity":"medium","line_start":1210},{"id":"external_commands:references/schema.json:1227:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}--> Different ways to source the connection options.\\n\\nSupport: - `e","category":"external_commands","line_end":1227,"severity":"medium","line_start":1227},{"id":"external_commands:references/schema.json:1280:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}--> Mirror the deployment specified by [`DeploymentTarget::deployment","category":"external_commands","line_end":1300,"severity":"medium","line_start":1280},{"id":"external_commands:references/schema.json:1300:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Resolve DNS via the remote pod.\\n\\nDefaults to `true`.\\n\\nMind that: - DNS resolving","category":"external_commands","line_end":1300,"severity":"medium","line_start":1300},{"id":"external_commands:references/schema.json:1325:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"List of addresses/ports/subnets that should be resolved through either the remote po","category":"external_commands","line_end":1325,"severity":"medium","line_start":1325},{"id":"external_commands:references/schema.json:1328:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When filters are specified under `remote`, matching DNS queries will go through the ","category":"external_commands","line_end":1341,"severity":"medium","line_start":1328},{"id":"external_commands:references/schema.json:1341:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When filters are specified under `local`, matching DNS queries will go through the l","category":"external_commands","line_end":1356,"severity":"medium","line_start":1341},{"id":"external_commands:references/schema.json:1356:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows the user to set or override the local process' environment variables with the","category":"external_commands","line_end":1356,"severity":"medium","line_start":1356},{"id":"external_commands:references/schema.json:1369:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Include the remote environment variables in the local process that are **NOT** speci","category":"external_commands","line_end":1369,"severity":"medium","line_start":1369},{"id":"external_commands:references/schema.json:1381:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Include only these remote environment variables in the local process. Variable names","category":"external_commands","line_end":1381,"severity":"medium","line_start":1381},{"id":"external_commands:references/schema.json:1401:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify map of patterns that if matched will replace the value according to specific","category":"external_commands","line_end":1401,"severity":"medium","line_start":1401},{"id":"external_commands:references/schema.json:1412:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting or overriding environment variables (locally) with a custom value.\\n\\","category":"external_commands","line_end":1412,"severity":"medium","line_start":1412},{"id":"external_commands:references/schema.json:1423:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows unsetting environment variables in the executed process.\\n\\nThis is useful fo","category":"external_commands","line_end":1423,"severity":"medium","line_start":1423},{"id":"external_commands:references/schema.json:1454:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"mirrord will open a URL for initiating mirrord browser extension to automatically in","category":"external_commands","line_end":1462,"severity":"medium","line_start":1454},{"id":"external_commands:references/schema.json:1462:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Disables the `SO_REUSEADDR` socket option on sockets that mirrord steals/mirrors. On","category":"external_commands","line_end":1470,"severity":"medium","line_start":1462},{"id":"external_commands:references/schema.json:1470:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Useful when the user's application loads a c-shared golang library dynamically.\\n\\nD","category":"external_commands","line_end":1478,"severity":"medium","line_start":1470},{"id":"external_commands:references/schema.json:1478:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Whether to terminate the session when a permission denied error occurs during DNS re","category":"external_commands","line_end":1478,"severity":"medium","line_start":1478},{"id":"external_commands:references/schema.json:1502:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Enables `getifaddrs` hook that removes IPv6 interfaces from the list returned by lib","category":"external_commands","line_end":1510,"severity":"medium","line_start":1502},{"id":"external_commands:references/schema.json:1510:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Enables hooking the `rename` function.\\n\\nUseful if you need file remapping and your","category":"external_commands","line_end":1510,"severity":"medium","line_start":1510},{"id":"external_commands:references/schema.json:1548:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Enables better support for outgoing connections using non-blocking TCP sockets.\\n\\nD","category":"external_commands","line_end":1556,"severity":"medium","line_start":1548},{"id":"external_commands:references/schema.json:1556:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Writes basic fork-safe SIP patching logs to a destination file. Useful for seeing th","category":"external_commands","line_end":1590,"severity":"medium","line_start":1556},{"id":"external_commands:references/schema.json:1590:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for the external proxy mirrord spawns when using the `mirrord containe","category":"external_commands","line_end":1590,"severity":"medium","line_start":1590},{"id":"external_commands:references/schema.json:1595:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify a custom host ip addr to listen on.\\n\\nThis address must be accessible from ","category":"external_commands","line_end":1595,"severity":"medium","line_start":1595},{"id":"external_commands:references/schema.json:1604:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How much time to wait while we don't have any active connections before exiting.\\n\\n","category":"external_commands","line_end":1604,"severity":"medium","line_start":1604},{"id":"external_commands:references/schema.json:1622:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set the log destination for the external proxy.\\n\\n1. If the provided path ends with","category":"external_commands","line_end":1622,"severity":"medium","line_start":1622},{"id":"external_commands:references/schema.json:1630:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set the log level for the external proxy.\\n\\nThe value should follow the RUST_LOG co","category":"external_commands","line_end":1630,"severity":"medium","line_start":1630},{"id":"external_commands:references/schema.json:1638:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How much time to wait for the first connection to the external proxy in seconds.\\n\\n","category":"external_commands","line_end":1638,"severity":"medium","line_start":1638},{"id":"external_commands:references/schema.json:1657:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls mirrord features.\\n\\nSee the [technical reference, Technical Reference](htt","category":"external_commands","line_end":1657,"severity":"medium","line_start":1657},{"id":"external_commands:references/schema.json:1662:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Creates a new copy of the target. mirrord will use this copy instead of the original","category":"external_commands","line_end":1708,"severity":"medium","line_start":1662},{"id":"external_commands:references/schema.json:1708:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Should mirrord return the hostname of the target pod when calling `gethostname`\",","category":"external_commands","line_end":1727,"severity":"medium","line_start":1708},{"id":"external_commands:references/schema.json:1727:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Define filters to split queues by, and make your local application consume only mess","category":"external_commands","line_end":1769,"severity":"medium","line_start":1727},{"id":"external_commands:references/schema.json:1769:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for enabling read-only or read-write file operations.\\n\\nThese options","category":"external_commands","line_end":1769,"severity":"medium","line_start":1769},{"id":"external_commands:references/schema.json:1807:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Changes file operations behavior based on user configuration.\\n\\nSee the file operat","category":"external_commands","line_end":1807,"severity":"medium","line_start":1807},{"id":"external_commands:references/schema.json:1810:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}--> Basic configuration that controls the env vars `MIRRORD_FILE_OPS`","category":"external_commands","line_end":1810,"severity":"medium","line_start":1810},{"id":"external_commands:references/schema.json:1818:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}--> Allows the user to specify both [`FsModeConfig`] (as above), and ","category":"external_commands","line_end":1828,"severity":"medium","line_start":1818},{"id":"external_commands:references/schema.json:1828:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Filter configuration for the HTTP traffic stealer feature.\\n\\nAllows the user to set","category":"external_commands","line_end":1828,"severity":"medium","line_start":1828},{"id":"external_commands:references/schema.json:1833:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"An array of HTTP filters.\\n\\nEach inner filter specifies either header or path regex","category":"external_commands","line_end":1833,"severity":"medium","line_start":1833},{"id":"external_commands:references/schema.json:1844:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"An array of HTTP filters.\\n\\nEach inner filter specifies either header or path regex","category":"external_commands","line_end":1844,"severity":"medium","line_start":1844},{"id":"external_commands:references/schema.json:1867:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"external_commands","line_end":1867,"severity":"medium","line_start":1867},{"id":"external_commands:references/schema.json:1883:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"external_commands","line_end":1911,"severity":"medium","line_start":1883},{"id":"external_commands:references/schema.json:1911:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Sets up the HTTP traffic filter (currently, only useful when `incoming: steal`).\\n\\n","category":"external_commands","line_end":1911,"severity":"medium","line_start":1911},{"id":"external_commands:references/schema.json:1923:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"DEPRECATED: use `tls_delivery` instead.\",","category":"external_commands","line_end":1943,"severity":"medium","line_start":1923},{"id":"external_commands:references/schema.json:1943:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Ports to ignore when mirroring/stealing traffic. Useful if you want specific ports t","category":"external_commands","line_end":1956,"severity":"medium","line_start":1943},{"id":"external_commands:references/schema.json:1956:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mapping for local ports to actually used local ports. When application listens on a ","category":"external_commands","line_end":1956,"severity":"medium","line_start":1956},{"id":"external_commands:references/schema.json:1981:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows selecting between mirrorring or stealing traffic.\\n\\nSee [`mode`](##mode (inc","category":"external_commands","line_end":2005,"severity":"medium","line_start":1981},{"id":"external_commands:references/schema.json:2005:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Mapping for local ports to remote ports.\\n\\nThis is useful when you want to mirror/s","category":"external_commands","line_end":2005,"severity":"medium","line_start":2005},{"id":"external_commands:references/schema.json:2030:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"List of ports to mirror/steal traffic from. Other ports will remain local.\\n\\nMutual","category":"external_commands","line_end":2058,"severity":"medium","line_start":2030},{"id":"external_commands:references/schema.json:2058:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls the incoming TCP traffic feature.\\n\\nSee the incoming [reference](https://m","category":"external_commands","line_end":2058,"severity":"medium","line_start":2058},{"id":"external_commands:references/schema.json:2076:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows selecting between mirrorring or stealing traffic.\\n\\nCan be set to either `\\\"","category":"external_commands","line_end":2076,"severity":"medium","line_start":2076},{"id":"external_commands:references/schema.json:2105:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"external_commands","line_end":2105,"severity":"medium","line_start":2105},{"id":"external_commands:references/schema.json:2118:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"external_commands","line_end":2152,"severity":"medium","line_start":2118},{"id":"external_commands:references/schema.json:2152:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for the internal proxy mirrord spawns for each local mirrord session t","category":"external_commands","line_end":2152,"severity":"medium","line_start":2152},{"id":"external_commands:references/schema.json:2157:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How much time to wait while we don't have any active connections before exiting.\\n\\n","category":"external_commands","line_end":2157,"severity":"medium","line_start":2157},{"id":"external_commands:references/schema.json:2175:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set the log destination for the internal proxy.\\n\\n1. If the provided path ends with","category":"external_commands","line_end":2175,"severity":"medium","line_start":2175},{"id":"external_commands:references/schema.json:2183:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set the log level for the internal proxy.\\n\\nThe value should follow the RUST_LOG co","category":"external_commands","line_end":2183,"severity":"medium","line_start":2183},{"id":"external_commands:references/schema.json:2191:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How often to log information about connected processes in seconds.\\n\\nThis feature l","category":"external_commands","line_end":2191,"severity":"medium","line_start":2191},{"id":"external_commands:references/schema.json:2200:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\n\\nSometimes the cpu is too busy with other tasks and the interna","category":"external_commands","line_end":2200,"severity":"medium","line_start":2200},{"id":"external_commands:references/schema.json:2210:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How much time to wait for the first connection to the proxy in seconds.\\n\\nCommon ca","category":"external_commands","line_end":2210,"severity":"medium","line_start":2210},{"id":"external_commands:references/schema.json:2245:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Delay in milliseconds for outgoing receive operations (Agent → Layer).\\n\\nDefaults t","category":"external_commands","line_end":2255,"severity":"medium","line_start":2245},{"id":"external_commands:references/schema.json:2255:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Delay in milliseconds for outgoing send operations (Layer → Agent).\\n\\nDefaults to `","category":"external_commands","line_end":2267,"severity":"medium","line_start":2255},{"id":"external_commands:references/schema.json:2267:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Stolen TLS traffic can be delivered to the local application either as TLS or as pla","category":"external_commands","line_end":2267,"severity":"medium","line_start":2267},{"id":"external_commands:references/schema.json:2311:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for copying a specific collection.\\n\\nExample:\\n\\n```json { \\\"users\\\":","category":"external_commands","line_end":2311,"severity":"medium","line_start":2311},{"id":"external_commands:references/schema.json:2324:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their MongoDB branch data","category":"external_commands","line_end":2376,"severity":"medium","line_start":2324},{"id":"external_commands:references/schema.json:2376:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their MySQL branch databa","category":"external_commands","line_end":2441,"severity":"medium","line_start":2376},{"id":"external_commands:references/schema.json:2441:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"In addition to copying an empty database or all tables' schema, mirrord operator wil","category":"external_commands","line_end":2441,"severity":"medium","line_start":2441},{"id":"external_commands:references/schema.json:2453:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls mirrord network operations.\\n\\nSee the network traffic [reference](https://","category":"external_commands","line_end":2453,"severity":"medium","line_start":2453},{"id":"external_commands:references/schema.json:2501:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Tunnel outgoing network operations through mirrord.\\n\\nSee the outgoing [reference](","category":"external_commands","line_end":2501,"severity":"medium","line_start":2501},{"id":"external_commands:references/schema.json:2518:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Defaults to `false`.\",","category":"external_commands","line_end":2526,"severity":"medium","line_start":2518},{"id":"external_commands:references/schema.json:2526:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Defaults to `true`.\",","category":"external_commands","line_end":2534,"severity":"medium","line_start":2526},{"id":"external_commands:references/schema.json:2534:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Defaults to `true`.\",","category":"external_commands","line_end":2556,"severity":"medium","line_start":2534},{"id":"external_commands:references/schema.json:2556:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"List of addresses/ports/subnets that should be sent through either the remote pod or","category":"external_commands","line_end":2556,"severity":"medium","line_start":2556},{"id":"external_commands:references/schema.json:2559:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When filters are specified under `remote`, matching traffic will go through the remo","category":"external_commands","line_end":2572,"severity":"medium","line_start":2559},{"id":"external_commands:references/schema.json:2572:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When filters are specified under `local`, matching traffic will go through the local","category":"external_commands","line_end":2587,"severity":"medium","line_start":2572},{"id":"external_commands:references/schema.json:2587:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their PostgreSQL branch d","category":"external_commands","line_end":2652,"severity":"medium","line_start":2587},{"id":"external_commands:references/schema.json:2652:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"In addition to copying an empty database or all tables' schema, mirrord operator wil","category":"external_commands","line_end":2652,"severity":"medium","line_start":2652},{"id":"external_commands:references/schema.json:2664:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Environment variable sources follow the same pattern as `connection.url`: - `{ \\\"typ","category":"external_commands","line_end":2664,"severity":"medium","line_start":2664},{"id":"external_commands:references/schema.json:2667:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"For AWS RDS/Aurora IAM authentication, set `type` to `\\\"aws_rds\\\"`.\\n\\nExample: ```j","category":"external_commands","line_end":2667,"severity":"medium","line_start":2667},{"id":"external_commands:references/schema.json:2722:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"For GCP Cloud SQL IAM authentication, set `type` to `\\\"gcp_cloud_sql\\\"`.\\n\\nExample ","category":"external_commands","line_end":2722,"severity":"medium","line_start":2722},{"id":"external_commands:references/schema.json:2769:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}--> Mirror the pod specified by [`PodTarget::pod`].\",","category":"external_commands","line_end":2845,"severity":"medium","line_start":2769},{"id":"external_commands:references/schema.json:2845:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Supports either a complete URL or separated connection parameters. If both are provi","category":"external_commands","line_end":2845,"severity":"medium","line_start":2845},{"id":"external_commands:references/schema.json:2907:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Complete Redis URL (e.g., `redis://user:pass@host:6379/0`). Can be sourced from an e","category":"external_commands","line_end":2969,"severity":"medium","line_start":2907},{"id":"external_commands:references/schema.json:2969:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Custom path to the container command. If not provided, uses the runtime name from PA","category":"external_commands","line_end":2969,"severity":"medium","line_start":2969},{"id":"external_commands:references/schema.json:2978:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Which container runtime to use (Docker, Podman, or nerdctl). Only applies when `runt","category":"external_commands","line_end":2978,"severity":"medium","line_start":2978},{"id":"external_commands:references/schema.json:3008:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Runtime backend for local Redis: `container`, `redis_server`, or `auto`.\",","category":"external_commands","line_end":3008,"severity":"medium","line_start":3008},{"id":"external_commands:references/schema.json:3018:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Custom path to the redis-server binary. If not provided, uses \\\"redis-server\\\" from ","category":"external_commands","line_end":3034,"severity":"medium","line_start":3018},{"id":"external_commands:references/schema.json:3034:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Example: ```json { \\\"args\\\": [\\\"--maxmemory\\\", \\\"256mb\\\", \\\"--appendonly\\\", \\\"yes\\\"]","category":"external_commands","line_end":3034,"severity":"medium","line_start":3034},{"id":"external_commands:references/schema.json:3048:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"For container-based runtimes, mirrord spawns the Redis image in a container. For `re","category":"external_commands","line_end":3048,"severity":"medium","line_start":3048},{"id":"external_commands:references/schema.json:3086:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}--> Mirror the rollout specified by [`RolloutTarget::rollout`].\",","category":"external_commands","line_end":3166,"severity":"medium","line_start":3086},{"id":"external_commands:references/schema.json:3166:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"```json { \\\"feature\\\": { \\\"split_queues\\\": { \\\"first-queue\\\": { \\\"queue_type\\\": \\\"SQ","category":"external_commands","line_end":3166,"severity":"medium","line_start":3166},{"id":"external_commands:references/schema.json:3173:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls how many times, and how often mirrord retries its initial Kubernetes API re","category":"external_commands","line_end":3173,"severity":"medium","line_start":3173},{"id":"external_commands:references/schema.json:3178:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Sets the max interval (in milliseconds) of retries for Kubernetes API requests made ","category":"external_commands","line_end":3188,"severity":"medium","line_start":3178},{"id":"external_commands:references/schema.json:3188:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Sets the max amount of retries for Kubernetes API requests made by mirrord during st","category":"external_commands","line_end":3188,"severity":"medium","line_start":3188},{"id":"external_commands:references/schema.json:3198:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Sets the min interval (in milliseconds) of retries for Kubernetes API requests made ","category":"external_commands","line_end":3285,"severity":"medium","line_start":3198},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Set up** `mirrord ci start/stop` commands in CI workflows","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Pre-install mirrord in a **trusted CI image**, use your org’s **approved** package manager with pi","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read the reference files from this skill's `references/` directory:","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/schema.json` - Authoritative mirrord JSON Schema","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/troubleshooting.md` - Common issues and solutions","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If using absolute paths, search for them using patterns like `**/mirrord-ci/references/*`.","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":49,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":64,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **mirrord Operator** installed with a Teams/Enterprise license. No license yet? An AI agent can o","category":"external_commands","line_end":67,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":74,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":80,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":82,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":87,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":99,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":103,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":105,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":112,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":119,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":123,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"This only applies to the Enterprise plan; if you're on the open-source version of mirrord, skip this","category":"external_commands","line_end":125,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":128,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":130,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Store this as a **secret** environment variable named `MIRRORD_CI_API_KEY` in your CI platform.","category":"external_commands","line_end":136,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":143,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":147,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ci.output_dir` | Directory for stdout/stderr logs | OS temp dir (e.g., `/tmp/mirrord`) |","category":"external_commands","line_end":147,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":154,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":160,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":194,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":198,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":218,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":222,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":253,"severity":"medium","line_start":222},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":257,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```groovy","category":"external_commands","line_end":289,"severity":"medium","line_start":257},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":299,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":332,"severity":"medium","line_start":299},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":342,"severity":"medium","line_start":332},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For detailed troubleshooting, refer to `references/troubleshooting.md`.","category":"external_commands","line_end":352,"severity":"medium","line_start":342},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Session not stopping\" | Use `mirrord ci stop` in `after_script` or `post` block |","category":"external_commands","line_end":352,"severity":"medium","line_start":352},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Logs not found\" | Check `ci.output_dir` config or default `/tmp/mirrord` |","category":"external_commands","line_end":353,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Seats being consumed\" | Set `MIRRORD_CI_API_KEY` environment variable |","category":"external_commands","line_end":360,"severity":"medium","line_start":354},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| mirrord seems to have no effect | Binary may be statically linked. For Go: use `go build -ldflags=","category":"external_commands","line_end":361,"severity":"medium","line_start":360},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Go DNS/outgoing filters not working | Build with `GODEBUG=netdns=cgo` |","category":"external_commands","line_end":363,"severity":"medium","line_start":361},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Traffic stops reaching remote target | With service mesh, try `{\"agent\": {\"flush_connections\": fal","category":"external_commands","line_end":364,"severity":"medium","line_start":363},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| DNS resolution fails for K8s services | Change `feature.fs.mode` from `local` to `localwithoverrid","category":"external_commands","line_end":364,"severity":"medium","line_start":364},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Permission (EACCES) errors | Enable privileged mode: `{\"agent\": {\"privileged\": true}}` |","category":"external_commands","line_end":366,"severity":"medium","line_start":365},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Agent pods not cleaned up | Run: `kubectl delete jobs --selector=app=mirrord --field-selector=stat","category":"external_commands","line_end":367,"severity":"medium","line_start":366},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Certificate validation errors (macOS) | Use `{\"experimental\": {\"trust_any_certificate\": true}}` |","category":"external_commands","line_end":368,"severity":"medium","line_start":367},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Service mesh drops agent connection | Set static `agent.port` and add port exclusion in mesh confi","category":"external_commands","line_end":373,"severity":"medium","line_start":368},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":378,"severity":"medium","line_start":373},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":381,"severity":"medium","line_start":378},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":391,"severity":"medium","line_start":381},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":394,"severity":"medium","line_start":391},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":402,"severity":"medium","line_start":394},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":407,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:407:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":414,"severity":"medium","line_start":407},{"id":"external_commands:SKILL.md:414:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":421,"severity":"medium","line_start":414},{"id":"external_commands:SKILL.md:421:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Include cleanup steps** - Always show `mirrord ci stop` in appropriate hooks","category":"external_commands","line_end":422,"severity":"medium","line_start":421},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Mention API key** - Remind about `MIRRORD_CI_API_KEY` for Enterprise users","category":"external_commands","line_end":434,"severity":"medium","line_start":422},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mirrord ci start` with their target","category":"external_commands","line_end":436,"severity":"medium","line_start":434},{"id":"external_commands:SKILL.md:436:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `mirrord ci stop` in `if: always()` block","category":"external_commands","line_end":436,"severity":"medium","line_start":436},{"id":"filesystem:references/schema.json:683:temp-directory-access","file":"references/schema.json","pattern":"Temp directory access","snippet":"\"description\": \"Configuration for mirrord for CI.\\n\\n```json { \\\"ci\\\": { \\\"output_dir\\\": \\\"/tmp/mirr","category":"filesystem","line_end":683,"severity":"medium","line_start":683},{"id":"filesystem:references/schema.json:688:temp-directory-access","file":"references/schema.json","pattern":"Temp directory access","snippet":"\"description\": \"Path to a directory where `mirrord ci` will flush application's stdout and stderr.\\n","category":"filesystem","line_end":688,"severity":"medium","line_start":688},{"id":"filesystem:SKILL.md:147:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"| `ci.output_dir` | Directory for stdout/stderr logs | OS temp dir (e.g., `/tmp/mirrord`) |","category":"filesystem","line_end":147,"severity":"medium","line_start":147},{"id":"filesystem:SKILL.md:153:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"/tmp/mirrord/<binary-name>-<unique-id>/","category":"filesystem","line_end":153,"severity":"medium","line_start":153},{"id":"filesystem:SKILL.md:353:temp-directory-access","file":"SKILL.md","pattern":"Temp directory access","snippet":"| \"Logs not found\" | Check `ci.output_dir` config or default `/tmp/mirrord` |","category":"filesystem","line_end":353,"severity":"medium","line_start":353},{"id":"external_commands:references/schema.json:134:unix-shell-invocation","file":"references/schema.json","pattern":"Unix shell invocation","snippet":"\"description\": \"Binaries to patch (macOS SIP).\\n\\nUse this when mirrord isn't loaded to protected bi","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"blocker:references/schema.json:1595:network-reconnaissance","file":"references/schema.json","pattern":"Network reconnaissance","snippet":"\"description\": \"Specify a custom host ip addr to listen on.\\n\\nThis address must be accessible from ","category":"blocker","line_end":1595,"severity":"low","line_start":1595},{"id":"blocker:references/schema.json:9:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Controls whether or not mirrord accepts invalid TLS certificates (e.g. self-signed c","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"blocker:references/schema.json:417:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Controls when a new agent image is downloaded.\\n\\nSupports `\\\"IfNotPresent\\\"`, `\\\"Al","category":"blocker","line_end":417,"severity":"low","line_start":417},{"id":"blocker:references/schema.json:515:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Allows setting up custom node selector for the agent Pod. Applies only to targetless","category":"blocker","line_end":515,"severity":"low","line_start":515},{"id":"blocker:references/schema.json:658:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Tries to parse the body as a JSON object and find (a) matching subobjects(s).\\n\\n`qu","category":"blocker","line_end":658,"severity":"low","line_start":658},{"id":"blocker:references/schema.json:925:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.db_branches[].id (type: mysql, pg, mongodb) {#feature-db_branches-sql-id}\",","category":"blocker","line_end":925,"severity":"low","line_start":925},{"id":"blocker:references/schema.json:1001:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.db_branches[].id (type: mysql, pg, mongodb) {#feature-db_branches-sql-id}\",","category":"blocker","line_end":1001,"severity":"low","line_start":1001},{"id":"blocker:references/schema.json:1089:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.db_branches[].id (type: mysql, pg, mongodb) {#feature-db_branches-sql-id}\",","category":"blocker","line_end":1089,"severity":"low","line_start":1089},{"id":"blocker:references/schema.json:1154:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.db_branches[].id (type: redis) {#feature-db_branches-redis-id}\",","category":"blocker","line_end":1154,"severity":"low","line_start":1154},{"id":"blocker:references/schema.json:1325:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"List of addresses/ports/subnets that should be resolved through either the remote po","category":"blocker","line_end":1325,"severity":"low","line_start":1325},{"id":"blocker:references/schema.json:1657:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Controls mirrord features.\\n\\nSee the [technical reference, Technical Reference](htt","category":"blocker","line_end":1657,"severity":"low","line_start":1657},{"id":"blocker:references/schema.json:1706:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"hostname\": {","category":"blocker","line_end":1706,"severity":"low","line_start":1706},{"id":"blocker:references/schema.json:1707:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.hostname {#feature-hostname}\",","category":"blocker","line_end":1707,"severity":"low","line_start":1707},{"id":"blocker:references/schema.json:1708:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Should mirrord return the hostname of the target pod when calling `gethostname`\",","category":"blocker","line_end":1708,"severity":"low","line_start":1708},{"id":"blocker:references/schema.json:1956:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Mapping for local ports to actually used local ports. When application listens on a ","category":"blocker","line_end":1956,"severity":"low","line_start":1956},{"id":"blocker:references/schema.json:2267:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Stolen TLS traffic can be delivered to the local application either as TLS or as pla","category":"blocker","line_end":2267,"severity":"low","line_start":2267},{"id":"blocker:references/schema.json:2291:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Server name to use when making a connection.\\n\\nMust be a valid DNS name or an IP ad","category":"blocker","line_end":2291,"severity":"low","line_start":2291},{"id":"blocker:references/schema.json:2556:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"List of addresses/ports/subnets that should be sent through either the remote pod or","category":"blocker","line_end":2556,"severity":"low","line_start":2556},{"id":"blocker:references/schema.json:2861:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Redis host/hostname. Can be sourced from an environment variable.\",","category":"blocker","line_end":2861,"severity":"low","line_start":2861},{"id":"blocker:references/schema.json:3475:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Operator represents a key's relationship to the value. Valid operators are Exists an","category":"blocker","line_end":3475,"severity":"low","line_start":3475},{"id":"blocker:SKILL.md:40:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"The schema defines all valid configuration options for mirrord, including CI-specific settings.","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"blocker:SKILL.md:380:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Remix/Vite/Next.js** - Override NODE_ENV to avoid production config:","category":"blocker","line_end":380,"severity":"low","line_start":380},{"id":"network:references/schema.json:2:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:references/schema.json:4:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"network:references/schema.json:212:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls whether or not mirrord sends telemetry data to MetalBear cloud. Telemetry s","category":"network","line_end":212,"severity":"low","line_start":212},{"id":"network:references/schema.json:230:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"read\\\"","category":"network","line_end":230,"severity":"low","line_start":230},{"id":"network:references/schema.json:381:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Runs the agent as an [ephemeral container](https://kubernetes.io/docs/concepts/workl","category":"network","line_end":381,"severity":"low","line_start":381},{"id":"network:references/schema.json:417:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls when a new agent image is downloaded.\\n\\nSupports `\\\"IfNotPresent\\\"`, `\\\"Al","category":"network","line_end":417,"severity":"low","line_start":417},{"id":"network:references/schema.json:425:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"List of secrets the agent pod has access to.\\n\\nTakes an array of entries with the f","category":"network","line_end":425,"severity":"low","line_start":425},{"id":"network:references/schema.json:658:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Tries to parse the body as a JSON object and find (a) matching subobjects(s).\\n\\n`qu","category":"network","line_end":658,"severity":"low","line_start":658},{"id":"network:references/schema.json:818:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Allows the user to target a pod created dynamically from the original [`target`](#ta","category":"network","line_end":818,"severity":"low","line_start":818},{"id":"network:references/schema.json:1356:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Allows the user to set or override the local process' environment variables with the","category":"network","line_end":1356,"severity":"low","line_start":1356},{"id":"network:references/schema.json:1462:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Disables the `SO_REUSEADDR` socket option on sockets that mirrord steals/mirrors. On","category":"network","line_end":1462,"severity":"low","line_start":1462},{"id":"network:references/schema.json:1494:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Forces hooking all instances of the connect function. In very niche cases the connec","category":"network","line_end":1494,"severity":"low","line_start":1494},{"id":"network:references/schema.json:1564:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"<https://github.com/metalbear-co/mirrord/issues/2421#issuecomment-2093200904>\",","category":"network","line_end":1564,"severity":"low","line_start":1564},{"id":"network:references/schema.json:1572:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Enables trusting any certificate on macOS, useful for <https://github.com/golang/go/","category":"network","line_end":1572,"severity":"low","line_start":1572},{"id":"network:references/schema.json:1657:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls mirrord features.\\n\\nSee the [technical reference, Technical Reference](htt","category":"network","line_end":1657,"severity":"low","line_start":1657},{"id":"network:references/schema.json:1662:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Creates a new copy of the target. mirrord will use this copy instead of the original","category":"network","line_end":1662,"severity":"low","line_start":1662},{"id":"network:references/schema.json:1807:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Changes file operations behavior based on user configuration.\\n\\nSee the file operat","category":"network","line_end":1807,"severity":"low","line_start":1807},{"id":"network:references/schema.json:1867:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"network","line_end":1867,"severity":"low","line_start":1867},{"id":"network:references/schema.json:1875:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports standard [HTTP methods](https://developer.mozilla.org/en-US/docs/Web/HTTP/R","category":"network","line_end":1875,"severity":"low","line_start":1875},{"id":"network:references/schema.json:1883:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"network","line_end":1883,"severity":"low","line_start":1883},{"id":"network:references/schema.json:1935:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Consider removing when adding <https://github.com/metalbear-co/mirrord/issues/702>\",","category":"network","line_end":1935,"severity":"low","line_start":1935},{"id":"network:references/schema.json:2058:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls the incoming TCP traffic feature.\\n\\nSee the incoming [reference](https://m","category":"network","line_end":2058,"severity":"low","line_start":2058},{"id":"network:references/schema.json:2105:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"network","line_end":2105,"severity":"low","line_start":2105},{"id":"network:references/schema.json:2118:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the [`fancy-regex`](https://docs.rs/fancy-regex/latest","category":"network","line_end":2118,"severity":"low","line_start":2118},{"id":"network:references/schema.json:2453:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls mirrord network operations.\\n\\nSee the network traffic [reference](https://","category":"network","line_end":2453,"severity":"low","line_start":2453},{"id":"network:references/schema.json:2501:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Tunnel outgoing network operations through mirrord.\\n\\nSee the outgoing [reference](","category":"network","line_end":2501,"severity":"low","line_start":2501},{"id":"network:references/schema.json:2542:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Connect to these unix streams remotely (and to all other paths locally).\\n\\nYou can ","category":"network","line_end":2542,"severity":"low","line_start":2542},{"id":"network:references/schema.json:3447:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Limits describes the maximum amount of compute resources allowed. More info: https:/","category":"network","line_end":3447,"severity":"low","line_start":3447},{"id":"network:references/schema.json:3454:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Requests describes the minimum amount of compute resources required. If Requests is ","category":"network","line_end":3454,"severity":"low","line_start":3454},{"id":"network:references/schema.json:3490:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Quantity is a fixed-point representation of a number. It provides convenient marshal","category":"network","line_end":3490,"severity":"low","line_start":3490},{"id":"network:SKILL.md:31:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Pre-install mirrord in a **trusted CI image**, use your org’s **approved** package manager with pi","category":"network","line_end":31,"severity":"low","line_start":31},{"id":"network:SKILL.md:179:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# See https://mirrord.dev/docs/overview/quick-start/ — do not pipe remote install scripts.","category":"network","line_end":179,"severity":"low","line_start":179},{"id":"network:SKILL.md:205:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# See https://mirrord.dev/docs/overview/quick-start/ for options","category":"network","line_end":205,"severity":"low","line_start":205},{"id":"network:SKILL.md:441:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mirrord for CI Overview](https://metalbear.com/mirrord-for-ci/)","category":"network","line_end":441,"severity":"low","line_start":441},{"id":"network:SKILL.md:442:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mirrord CI Documentation](https://mirrord.dev/docs/using-mirrord/mirrord-for-ci/)","category":"network","line_end":442,"severity":"low","line_start":442},{"id":"network:SKILL.md:443:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mirrord Installation](https://mirrord.dev/docs/overview/quick-start/)","category":"network","line_end":443,"severity":"low","line_start":443},{"id":"network:references/schema.json:220:python-http-libraries","file":"references/schema.json","pattern":"Python HTTP libraries","snippet":"\"description\": \"When disabled, mirrord will remove `HTTP[S]_PROXY` env variables before doing any ne","category":"network","line_end":220,"severity":"low","line_start":220},{"id":"network:references/schema.json:3173:python-http-libraries","file":"references/schema.json","pattern":"Python HTTP libraries","snippet":"\"description\": \"Controls how many times, and how often mirrord retries its initial Kubernetes API re","category":"network","line_end":3173,"severity":"low","line_start":3173},{"id":"filesystem:references/schema.json:1580:standard-device-file-access","file":"references/schema.json","pattern":"Standard device file access","snippet":"\"description\": \"Uses /dev/null for creating local fake files (should be better than using /tmp)\",","category":"filesystem","line_end":1580,"severity":"low","line_start":1580}],"finding_verdicts":[{"id":"sensitive:references/schema.json:230:gcp-credentials-directory","reason":"The gcloud path appears in a not_found filter that hides matching files from the application. This example restricts credential access rather than collecting credentials.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:4:kubernetes-config-file","reason":"The schema documents the kubeconfig option and its conventional default path. It neither reads credentials itself nor instructs sending them to an unrelated destination.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:110:kubernetes-config-file","reason":"The schema documents the kubeconfig option and its conventional default path. It neither reads credentials itself nor instructs sending them to an unrelated destination.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:174:kubernetes-config-file","reason":"The CI example decodes a user-provided secret into the conventional kubeconfig path for authorized cluster authentication. No credential upload or unrelated collection is shown.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:SKILL.md:210:kubernetes-config-file","reason":"The CI example decodes a user-provided secret into the conventional kubeconfig path for authorized cluster authentication. No credential upload or unrelated collection is shown.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:SKILL.md:235:kubernetes-config-file","reason":"The CI example decodes a user-provided secret into the conventional kubeconfig path for authorized cluster authentication. No credential upload or unrelated collection is shown.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:764:certificate-key-files","reason":"The schema documents where mirrord creates its container TLS certificate. The PEM path is configuration metadata, not a request to collect private keys.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2267:certificate-key-files","reason":"The PEM examples configure trust roots or a server certificate for local TLS delivery. They do not extract credentials; certificate-trust behavior is a separate concern.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2283:crypto-seed-private-key-mention","reason":"The certificate-loading description explicitly states that private key entries are ignored. It documents certificate parsing, not secret-key extraction.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2299:crypto-seed-private-key-mention","reason":"The certificate-loading description explicitly states that private key entries are ignored. It documents certificate parsing, not secret-key extraction.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1360:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1368:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1380:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1392:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1400:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1411:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1422:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1685:environment-file-access","reason":"This is a feature.env schema title describing environment configuration. Naming an environment option does not itself access a dotenv file or disclose secrets.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/troubleshooting.md:133:environment-file-access","reason":"The advice excludes NODE_ENV and NX_NEXT_DIR to prevent framework conflicts. It does not read a dotenv file or export secret contents.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:1828:heuristic-extremely-long-line-2304-chars-likely-","reason":"The long JSON string contains readable documentation for HTTP request filtering and examples. Escaped newlines explain its length; no encoded executable payload is present.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:3490:heuristic-extremely-long-line-2479-chars-likely-","reason":"The long JSON string contains readable documentation for Kubernetes resource quantity serialization. Escaped newlines explain its length; no encoded executable payload is present.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:4:heuristic-extremely-long-line-3222-chars-likely-","reason":"The long JSON string contains readable documentation for the complete mirrord configuration example. Escaped newlines explain its length; no encoded executable payload is present.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:230:heuristic-extremely-long-line-3367-chars-likely-","reason":"The long JSON string contains readable documentation for filesystem modes, exceptions, and path filters. Escaped newlines explain its length; no encoded executable payload is present.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/schema.json:2667:aws-credential-environment-variables","reason":"The schema describes AWS IAM credential sources for RDS authentication, including temporary roles. These are variable names and authorized authentication options, not embedded credentials.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/schema.json:1129:database-connection-strings","reason":"The Redis branching example references REDIS_URL and REDIS_PASSWORD by variable name. It does not contain actual credentials or send them to an unrelated service.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/schema.json:2722:gcp-credential-environment-variables","reason":"The schema documents Cloud SQL IAM authentication through workload identity or explicitly supplied credentials. No actual key value or unrelated destination is provided.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:130:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:186:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:217:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:245:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:263:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:354:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:422:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:437:generic-api-secret-keys","reason":"MIRRORD_CI_API_KEY is the documented Enterprise authentication variable, referenced through CI secrets or credential bindings. No actual key value or exfiltration instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/schema.json:4:hidden-file-in-home-directory","reason":"The schema names conventional .mirrord and kubeconfig locations used for explicit configuration. Hidden path syntax alone is not evidence of persistence or credential collection.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:110:hidden-file-in-home-directory","reason":"The schema names conventional .mirrord and kubeconfig locations used for explicit configuration. Hidden path syntax alone is not evidence of persistence or credential collection.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:173:hidden-file-in-home-directory","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:174:hidden-file-in-home-directory","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:209:hidden-file-in-home-directory","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:210:hidden-file-in-home-directory","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:234:hidden-file-in-home-directory","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:235:hidden-file-in-home-directory","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:247:non-standard-device-file-access","reason":"The /dev segment is inside example home-directory development paths. It does not address a device under the system /dev directory.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:247:path-traversal-sequence","reason":"The schema explicitly says path mappings do not apply to relative paths such as ../dev. This is a documented limitation, not a traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/troubleshooting.md:15:sudo-privilege-escalation","reason":"The command uses sudo to remove a copied binary's signature for SIP troubleshooting. This weakens binary integrity protections despite its legitimate compatibility purpose.","verdict":"confirmed","confidence":0.98},{"id":"sensitive:references/schema.json:897:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:917:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:925:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:933:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:941:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:955:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:973:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:993:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1001:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1009:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1017:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1031:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1049:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1069:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1077:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1089:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1097:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1105:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1119:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1136:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1154:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1163:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1183:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:1673:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2849:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2860:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2873:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2886:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2897:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2906:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2919:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2968:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2977:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2987:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:2999:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:3007:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:3017:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/schema.json:3026:sqlite-database-file","reason":"The match is a feature.db_branches schema title for database branching configuration. No SQLite file path or database file read appears here.","verdict":"false_positive","confidence":0.99},{"id":"network:references/schema.json:4:hardcoded-ip-address","reason":"The addresses describe sample metrics binding and network filters. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:491:hardcoded-ip-address","reason":"The addresses describe an optional Prometheus metrics listener. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:772:hardcoded-ip-address","reason":"The addresses describe local container gateway addressing. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:1325:hardcoded-ip-address","reason":"The addresses describe DNS routing filter examples. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:1595:hardcoded-ip-address","reason":"The addresses describe local container proxy binding. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:1657:hardcoded-ip-address","reason":"The addresses describe example network routing filters. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:2453:hardcoded-ip-address","reason":"The addresses describe example incoming and outgoing network settings. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:2501:hardcoded-ip-address","reason":"The addresses describe outbound traffic filter examples. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:2556:hardcoded-ip-address","reason":"The addresses describe destination filter examples. No hardcoded attacker endpoint or secret-bearing request is demonstrated by this schema text.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:4:hidden-file-access","reason":"The schema names conventional .mirrord and kubeconfig locations used for explicit configuration. Hidden path syntax alone is not evidence of persistence or credential collection.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:110:hidden-file-access","reason":"The schema names conventional .mirrord and kubeconfig locations used for explicit configuration. Hidden path syntax alone is not evidence of persistence or credential collection.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:2969:hidden-file-access","reason":"The .local path is an example location for a user-installed Podman executable. The schema does not search hidden files or execute this example.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:173:hidden-file-access","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:174:hidden-file-access","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:209:hidden-file-access","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:210:hidden-file-access","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:234:hidden-file-access","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:235:hidden-file-access","reason":"The example creates the conventional .kube directory or writes the supplied CI kubeconfig secret there. This is intended authentication setup, not hidden persistence.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:280:node-js-fs-operations","reason":"feature.fs names mirrord filesystem configuration options. These are not Node.js fs API calls, and the cited text performs no filesystem operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:292:node-js-fs-operations","reason":"feature.fs names mirrord filesystem configuration options. These are not Node.js fs API calls, and the cited text performs no filesystem operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:304:node-js-fs-operations","reason":"feature.fs names mirrord filesystem configuration options. These are not Node.js fs API calls, and the cited text performs no filesystem operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/troubleshooting.md:70:node-js-fs-operations","reason":"feature.fs names mirrord filesystem configuration options. These are not Node.js fs API calls, and the cited text performs no filesystem operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/troubleshooting.md:71:node-js-fs-operations","reason":"feature.fs names mirrord filesystem configuration options. These are not Node.js fs API calls, and the cited text performs no filesystem operation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:4:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:94:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:102:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:110:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:126:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:134:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:146:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:154:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:166:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:178:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:220:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:230:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:247:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:317:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:322:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:359:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:381:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:397:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:405:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:417:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:425:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:436:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:444:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:452:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:463:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:491:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:507:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:515:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:526:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:534:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:542:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:566:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:574:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:584:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:595:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:610:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:617:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:658:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:683:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:688:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:698:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:724:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:729:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:740:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:756:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:764:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:772:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:781:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:818:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:886:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:889:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:898:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:926:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:934:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:942:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:956:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:965:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:974:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1002:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1010:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1018:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1032:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1041:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1050:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1090:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1098:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1106:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1120:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1129:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1164:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1184:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1203:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1210:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1227:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1280:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1300:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1325:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1328:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1341:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1356:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1369:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1381:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1401:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1412:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1423:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1454:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1462:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1470:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1478:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1502:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1510:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1548:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1556:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1590:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1595:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1604:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1622:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1630:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1638:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1657:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1662:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1708:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1727:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1769:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1807:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1810:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1818:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1828:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1833:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1844:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1867:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1883:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1911:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1923:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1943:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1956:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:1981:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2005:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2030:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2058:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2076:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2105:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2118:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2152:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2157:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2175:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2183:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2191:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2200:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2210:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2245:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2255:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2267:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2311:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2324:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2376:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2441:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2453:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2501:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2518:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2526:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2534:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2556:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2559:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2572:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2587:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2652:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2664:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2667:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2722:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2769:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2845:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2907:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2969:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:2978:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3008:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3018:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3034:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3048:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3086:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3166:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3173:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3178:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3188:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/schema.json:3198:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON Schema description as Markdown formatting for configuration examples. No shell or Ruby interpreter executes this string.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","reason":"These backticks format troubleshooting advice rather than execute a shell expression. Security implications of the recommended configuration changes require separate contextual review.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","reason":"These backticks format troubleshooting advice rather than execute a shell expression. Security implications of the recommended configuration changes require separate contextual review.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","reason":"These backticks format troubleshooting advice rather than execute a shell expression. Security implications of the recommended configuration changes require separate contextual review.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:407:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:414:ruby-shell-backtick-execution","reason":"This line is a Markdown code fence, not a command substitution. Its delimiters do not execute the enclosed example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:421:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:436:ruby-shell-backtick-execution","reason":"Backticks format command names, paths, or configuration terms in the CI guide. They are not executable Ruby or shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:683:temp-directory-access","reason":"The path is the documented directory for CI application stdout and stderr logs. No destructive operation, executable staging, or credential collection is shown.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/schema.json:688:temp-directory-access","reason":"The path is the documented directory for CI application stdout and stderr logs. No destructive operation, executable staging, or credential collection is shown.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:147:temp-directory-access","reason":"The path is the documented directory for CI application stdout and stderr logs. No destructive operation, executable staging, or credential collection is shown.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:153:temp-directory-access","reason":"The path is the documented directory for CI application stdout and stderr logs. No destructive operation, executable staging, or credential collection is shown.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:353:temp-directory-access","reason":"The path is the documented directory for CI application stdout and stderr logs. No destructive operation, executable staging, or credential collection is shown.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:references/schema.json:134:unix-shell-invocation","reason":"The schema lists bash and python as example binary names for optional SIP patching. It does not invoke a shell or concatenate executable input.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1595:network-reconnaissance","reason":"The description explains how to bind a container proxy to a reachable local address. It performs no network scan or host enumeration.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:9:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:417:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:515:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:658:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:925:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1001:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1089:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1154:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1325:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1657:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1706:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1707:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1708:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:1956:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:2267:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:2291:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:2556:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:2861:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/schema.json:3475:system-reconnaissance","reason":"The match is schema terminology or a documented configuration example, not a system discovery command. No reconnaissance output is collected or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:40:system-reconnaissance","reason":"This sentence describes the schema's configuration coverage. It contains no system discovery command or collection instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:380:system-reconnaissance","reason":"This heading concerns NODE_ENV configuration for application frameworks. It contains no system reconnaissance operation.","verdict":"false_positive","confidence":0.99},{"id":"network:references/schema.json:2:hardcoded-url","reason":"The URL identifies the JSON Schema draft used by this document. It is schema metadata, not an exfiltration destination.","verdict":"false_positive","confidence":0.99},{"id":"network:references/schema.json:4:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:212:hardcoded-url","reason":"The URL links to vendor telemetry documentation for an explicit configuration option. The cited line contains no secret-bearing request or covert transmission instruction.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:230:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:381:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:417:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:425:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:658:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:818:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1356:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1462:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1494:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1564:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1572:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1657:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1662:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1807:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1867:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1875:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1883:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:1935:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:2058:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:2105:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:2118:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:2453:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:2501:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:2542:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:3447:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:3454:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:3490:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:31:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:179:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:205:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:441:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:442:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:443:hardcoded-url","reason":"The URL is a documentation, issue, or specification reference supporting the described configuration. The cited text does not upload local data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/schema.json:220:python-http-libraries","reason":"The schema describes HTTP proxy environment handling. It neither imports a Python HTTP library nor executes a request.","verdict":"false_positive","confidence":0.99},{"id":"network:references/schema.json:3173:python-http-libraries","reason":"The schema describes retries for expected Kubernetes API requests. The word requests is prose, not a Python library invocation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/schema.json:1580:standard-device-file-access","reason":"The schema describes /dev/null as a backing location for fake local files. This conventional null device is not a sensitive data source.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Troubleshooting Recommends Disabling Certificate Validation","severity":"high","locations":[{"file":"SKILL.md","line_end":367,"line_start":367},{"file":"references/troubleshooting.md","line_end":119,"line_start":107}],"confidence":0.99,"description":"The guidance recommends \"trust_any_certificate\": true for certificate errors and states that every certificate becomes trusted. This can expose application connections to server impersonation and interception.","confidence_reasoning":"The troubleshooting example explicitly enables universal certificate trust without limiting it to an isolated diagnostic session or requiring restoration."},{"title":"Permission Troubleshooting Broadens Container Privileges","severity":"high","locations":[{"file":"SKILL.md","line_end":365,"line_start":365},{"file":"references/troubleshooting.md","line_end":101,"line_start":91}],"confidence":0.97,"description":"The instructions recommend \"privileged\": true for permission or DNS failures. Privileged agents weaken container isolation and can expose the host when compromised.","confidence_reasoning":"The advice directly enables privileged execution without requiring administrator approval or evaluating narrower permissions. Actual exposure depends on deployment policy."},{"title":"CI Troubleshooting Changes Cluster-Wide Networking","severity":"medium","locations":[{"file":"references/troubleshooting.md","line_end":60,"line_start":49}],"confidence":0.96,"description":"The Cilium workaround upgrades the release in kube-system and restarts its DaemonSet. Applying it without administrator review can disrupt networking for unrelated workloads.","confidence_reasoning":"The commands directly change cluster networking infrastructure, but the surrounding instructions provide no change approval, maintenance window, or rollback requirement."},{"title":"Isolation Assurance Omits Shared Dependency Side Effects","severity":"medium","locations":[{"file":"SKILL.md","line_end":56,"line_start":51},{"file":"SKILL.md","line_end":189,"line_start":182},{"file":"references/schema.json","line_end":2501,"line_start":2501}],"confidence":0.92,"description":"The skill promises isolated execution without workload interference, but its examples connect directly to shared services without configuring database or traffic isolation. Tests can therefore modify shared data or trigger downstream effects.","confidence_reasoning":"The unconditional assurance exceeds the protections configured in the examples. The schema documents outbound traffic tunneling, which does not itself isolate dependency writes."}],"subject_marketplace_commit_sha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","subject_content_hash":"73bc8a4f38bfe2f15b5e34ff9f2db653101add3e0349c29f3116725555e247bf","subject_tree_hash":"a848c7cf96b3dd6f461a7b01a4fcda1d38d667e7139c6c7be42b866fc699014d","subject_plugin_path":"skills/metalbear-co/mirrord-ci","audit_payload_hash":"7d75381d6f122d0ef2199faece974919","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","contentHash":"73bc8a4f38bfe2f15b5e34ff9f2db653101add3e0349c29f3116725555e247bf","treeHash":"a848c7cf96b3dd6f461a7b01a4fcda1d38d667e7139c6c7be42b866fc699014d","pluginPath":"skills/metalbear-co/mirrord-ci","auditPayloadHash":"7d75381d6f122d0ef2199faece974919"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/metalbear-co-mirrord-ci/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":4,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}