{"data":{"skill":{"slug":"metalbear-co-mirrord-config","name":"mirrord-config","icon":"📦","repo":"https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-config","status":"approved","author":"metalbear-co","authorVersion":"1.25","skillstoreRevision":1},"audit":{"id":"e9d18c99-04e4-4a24-b621-3979e9f441a0","skill_id":"4f6b66e5-9fdb-49e9-88dc-f1ee225655b5","version":1,"content_hash":"v3:bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2:9d465ebbbfb678d7c786419557d62b66869d45d37b87d7f0bcf8c83f022fff71:cb6c84112a89d4137641ed2138eddcd06987466cc7cc4844565a9ab8eecdde54:736b696c6c732f6d6574616c626561722d636f2f6d6972726f72642d636f6e666967:0d0d3d2695ab97c8d01531601f2a7b36","risk_level":"safe","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 400 static matches were reviewed against the source documentation and schema. They are false positives caused by configuration examples, schema descriptions, path names, URLs, and command examples rather than executable security behavior. No prompt injection, data-exfiltration intent, or net-new semantic finding was identified. Static review was capped at 400/624 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.","remediation":[{"issue":"Static review capped","severity":"medium","suggestion":"Manually review the omitted 224 static analyzer matches or reduce bundled generated/vendor/reference content before enabling automatic publication."},{"issue":"Generated configurations can request broad environment, filesystem, or network access.","severity":"medium","suggestion":"Use the minimum mirrord features required for each task, and review env, fs, and network settings before running a session."},{"issue":"Configuration documentation includes paths for credentials, certificates, keys, and Kubernetes files.","severity":"high","suggestion":"Do not prefetch or expose sensitive files unless required. Apply least-privilege filesystem rules and redact sensitive values from shared configurations."},{"issue":"Optional CLI validation may process user-provided configuration content.","severity":"medium","suggestion":"Keep validation local, use the official mirrord binary, and never execute shell commands or fetch URLs derived from configuration values."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/configuration.md","line_end":1669,"line_start":1669},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":28,"line_start":28},{"file":"references/schema.json","line_end":110,"line_start":110},{"file":"references/schema.json","line_end":122,"line_start":122},{"file":"references/schema.json","line_end":130,"line_start":130},{"file":"references/schema.json","line_end":138,"line_start":138},{"file":"references/schema.json","line_end":154,"line_start":154},{"file":"references/schema.json","line_end":162,"line_start":162},{"file":"references/schema.json","line_end":174,"line_start":174},{"file":"references/schema.json","line_end":182,"line_start":182},{"file":"references/schema.json","line_end":194,"line_start":194},{"file":"references/schema.json","line_end":256,"line_start":206},{"file":"references/schema.json","line_end":266,"line_start":256},{"file":"references/schema.json","line_end":266,"line_start":266},{"file":"references/schema.json","line_end":271,"line_start":271},{"file":"references/schema.json","line_end":283,"line_start":283},{"file":"references/schema.json","line_end":305,"line_start":305},{"file":"references/schema.json","line_end":317,"line_start":317},{"file":"references/schema.json","line_end":338,"line_start":328},{"file":"references/schema.json","line_end":338,"line_start":338},{"file":"references/schema.json","line_end":350,"line_start":350},{"file":"references/schema.json","line_end":374,"line_start":374},{"file":"references/schema.json","line_end":379,"line_start":379},{"file":"references/schema.json","line_end":425,"line_start":425},{"file":"references/schema.json","line_end":463,"line_start":447},{"file":"references/schema.json","line_end":463,"line_start":463},{"file":"references/schema.json","line_end":489,"line_start":471},{"file":"references/schema.json","line_end":489,"line_start":489},{"file":"references/schema.json","line_end":501,"line_start":501},{"file":"references/schema.json","line_end":509,"line_start":509},{"file":"references/schema.json","line_end":520,"line_start":520},{"file":"references/schema.json","line_end":538,"line_start":538},{"file":"references/schema.json","line_end":546,"line_start":546},{"file":"references/schema.json","line_end":557,"line_start":557},{"file":"references/schema.json","line_end":585,"line_start":585},{"file":"references/schema.json","line_end":601,"line_start":601},{"file":"references/schema.json","line_end":609,"line_start":609},{"file":"references/schema.json","line_end":620,"line_start":620},{"file":"references/schema.json","line_end":628,"line_start":628},{"file":"references/schema.json","line_end":644,"line_start":636},{"file":"references/schema.json","line_end":644,"line_start":644},{"file":"references/schema.json","line_end":668,"line_start":668},{"file":"references/schema.json","line_end":686,"line_start":676},{"file":"references/schema.json","line_end":686,"line_start":686},{"file":"references/schema.json","line_end":713,"line_start":697},{"file":"references/schema.json","line_end":720,"line_start":713},{"file":"references/schema.json","line_end":763,"line_start":720},{"file":"references/schema.json","line_end":763,"line_start":763},{"file":"references/schema.json","line_end":800,"line_start":800}]},{"factor":"network","evidence":[{"file":"references/configuration.md","line_end":1272,"line_start":1272},{"file":"references/configuration.md","line_end":1816,"line_start":1816},{"file":"references/configuration.md","line_end":87,"line_start":87},{"file":"references/configuration.md","line_end":121,"line_start":121},{"file":"references/configuration.md","line_end":129,"line_start":129},{"file":"references/configuration.md","line_end":339,"line_start":339},{"file":"references/configuration.md","line_end":453,"line_start":453},{"file":"references/configuration.md","line_end":654,"line_start":654},{"file":"references/configuration.md","line_end":968,"line_start":968},{"file":"references/configuration.md","line_end":976,"line_start":976},{"file":"references/configuration.md","line_end":1025,"line_start":1025},{"file":"references/configuration.md","line_end":1451,"line_start":1451},{"file":"references/configuration.md","line_end":1477,"line_start":1477},{"file":"references/schema.json","line_end":256,"line_start":256},{"file":"references/schema.json","line_end":5857,"line_start":5857},{"file":"references/schema.json","line_end":2,"line_start":2},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":36,"line_start":36},{"file":"references/schema.json","line_end":240,"line_start":240},{"file":"references/schema.json","line_end":248,"line_start":248},{"file":"references/schema.json","line_end":266,"line_start":266},{"file":"references/schema.json","line_end":283,"line_start":283},{"file":"references/schema.json","line_end":447,"line_start":447},{"file":"references/schema.json","line_end":501,"line_start":501},{"file":"references/schema.json","line_end":509,"line_start":509},{"file":"references/schema.json","line_end":763,"line_start":763},{"file":"references/schema.json","line_end":1208,"line_start":1208},{"file":"references/schema.json","line_end":1276,"line_start":1276},{"file":"references/schema.json","line_end":2929,"line_start":2929},{"file":"references/schema.json","line_end":3042,"line_start":3042},{"file":"references/schema.json","line_end":3074,"line_start":3074},{"file":"references/schema.json","line_end":3148,"line_start":3148},{"file":"references/schema.json","line_end":3156,"line_start":3156},{"file":"references/schema.json","line_end":3241,"line_start":3241},{"file":"references/schema.json","line_end":3246,"line_start":3246},{"file":"references/schema.json","line_end":3407,"line_start":3407},{"file":"references/schema.json","line_end":3560,"line_start":3560},{"file":"references/schema.json","line_end":3576,"line_start":3576},{"file":"references/schema.json","line_end":3584,"line_start":3584},{"file":"references/schema.json","line_end":3739,"line_start":3739},{"file":"references/schema.json","line_end":3868,"line_start":3868},{"file":"references/schema.json","line_end":3909,"line_start":3909},{"file":"references/schema.json","line_end":3923,"line_start":3923},{"file":"references/schema.json","line_end":4350,"line_start":4350},{"file":"references/schema.json","line_end":4600,"line_start":4600},{"file":"references/schema.json","line_end":4648,"line_start":4648},{"file":"references/schema.json","line_end":4689,"line_start":4689},{"file":"references/schema.json","line_end":5617,"line_start":5617},{"file":"references/schema.json","line_end":5679,"line_start":5679},{"file":"references/schema.json","line_end":5734,"line_start":5734}]},{"factor":"filesystem","evidence":[{"file":"references/configuration.md","line_end":931,"line_start":931},{"file":"references/configuration.md","line_end":936,"line_start":936},{"file":"references/configuration.md","line_end":913,"line_start":913},{"file":"references/configuration.md","line_end":138,"line_start":138},{"file":"references/configuration.md","line_end":1646,"line_start":1646},{"file":"references/configuration.md","line_end":138,"line_start":138},{"file":"references/configuration.md","line_end":1646,"line_start":1646},{"file":"references/configuration.md","line_end":554,"line_start":554},{"file":"references/configuration.md","line_end":904,"line_start":904},{"file":"references/configuration.md","line_end":910,"line_start":910},{"file":"references/schema.json","line_end":337,"line_start":337},{"file":"references/schema.json","line_end":349,"line_start":349},{"file":"references/schema.json","line_end":361,"line_start":361},{"file":"references/schema.json","line_end":4231,"line_start":4231},{"file":"references/schema.json","line_end":283,"line_start":283},{"file":"references/schema.json","line_end":2427,"line_start":2427},{"file":"references/schema.json","line_end":2586,"line_start":2586},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":28,"line_start":28},{"file":"references/schema.json","line_end":130,"line_start":130},{"file":"references/schema.json","line_end":3139,"line_start":3139},{"file":"references/schema.json","line_end":4239,"line_start":4239},{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":28,"line_start":28},{"file":"references/schema.json","line_end":130,"line_start":130},{"file":"references/schema.json","line_end":3139,"line_start":3139},{"file":"references/schema.json","line_end":4239,"line_start":4239},{"file":"references/schema.json","line_end":5271,"line_start":5271},{"file":"references/schema.json","line_end":3074,"line_start":3074},{"file":"references/schema.json","line_end":3164,"line_start":3164},{"file":"references/schema.json","line_end":283,"line_start":283},{"file":"references/schema.json","line_end":800,"line_start":800},{"file":"references/schema.json","line_end":805,"line_start":805},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":79,"line_start":79}]},{"factor":"env_access","evidence":[{"file":"references/schema.json","line_end":4,"line_start":4},{"file":"references/schema.json","line_end":585,"line_start":585},{"file":"references/schema.json","line_end":3609,"line_start":3609},{"file":"references/schema.json","line_end":3663,"line_start":3663},{"file":"references/schema.json","line_end":1276,"line_start":1276},{"file":"references/schema.json","line_end":2246,"line_start":2246},{"file":"references/schema.json","line_end":2628,"line_start":2628},{"file":"references/schema.json","line_end":2552,"line_start":2552},{"file":"references/schema.json","line_end":2586,"line_start":2586}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":8303,"audit_model":"codex","audited_at":"2026-09-29T21:32:10.244+00:00","created_at":"2026-09-30T13:38:24.910424+00:00","static_findings":[{"id":"sensitive:references/configuration.md:884:gcp-credentials-directory","file":"references/configuration.md","pattern":"GCP credentials directory","snippet":"\"not_found\": [ \"\\\\.config/gcloud\" ]","category":"sensitive","line_end":884,"severity":"critical","line_start":884},{"id":"sensitive:references/schema.json:266:gcp-credentials-directory","file":"references/schema.json","pattern":"GCP credentials directory","snippet":"\"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"read\\\"","category":"sensitive","line_end":266,"severity":"critical","line_start":266},{"id":"sensitive:references/configuration.md:138:kubernetes-config-file","file":"references/configuration.md","pattern":"Kubernetes config file","snippet":"\"kubeconfig\": \"~/.kube/config\",","category":"sensitive","line_end":138,"severity":"critical","line_start":138},{"id":"sensitive:references/configuration.md:1646:kubernetes-config-file","file":"references/configuration.md","pattern":"Kubernetes config file","snippet":"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/config`, or","category":"sensitive","line_end":1646,"severity":"critical","line_start":1646},{"id":"sensitive:references/schema.json:4:kubernetes-config-file","file":"references/schema.json","pattern":"Kubernetes config file","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"sensitive","line_end":4,"severity":"critical","line_start":4},{"id":"sensitive:references/schema.json:130:kubernetes-config-file","file":"references/schema.json","pattern":"Kubernetes config file","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"sensitive","line_end":130,"severity":"critical","line_start":130},{"id":"sensitive:references/configuration.md:1300:certificate-key-files","file":"references/configuration.md","pattern":"Certificate/key files","snippet":"\"trust_roots\": [\"/path/to/cert.pem\", \"/path/to/cert/dir\"]","category":"sensitive","line_end":1300,"severity":"high","line_start":1300},{"id":"sensitive:references/configuration.md:1308:certificate-key-files","file":"references/configuration.md","pattern":"Certificate/key files","snippet":"\"server_cert\": \"/path/to/cert.pem\"","category":"sensitive","line_end":1308,"severity":"high","line_start":1308},{"id":"sensitive:references/schema.json:1152:certificate-key-files","file":"references/schema.json","pattern":"Certificate/key files","snippet":"\"description\": \"When using`mirrord container` with external_proxy TLS enabled (is enabled by default","category":"sensitive","line_end":1152,"severity":"high","line_start":1152},{"id":"sensitive:references/schema.json:4171:certificate-key-files","file":"references/schema.json","pattern":"Certificate/key files","snippet":"\"description\": \"Stolen TLS traffic can be delivered to the local application either as TLS or as pla","category":"sensitive","line_end":4171,"severity":"high","line_start":4171},{"id":"sensitive:references/configuration.md:1340:crypto-seed-private-key-mention","file":"references/configuration.md","pattern":"Crypto seed/private key mention","snippet":"It can contain entries of other types, e.g private keys, which are ignored.","category":"sensitive","line_end":1340,"severity":"high","line_start":1340},{"id":"sensitive:references/configuration.md:1355:crypto-seed-private-key-mention","file":"references/configuration.md","pattern":"Crypto seed/private key mention","snippet":"The files can contain entries of other types, e.g private keys, which are ignored.","category":"sensitive","line_end":1355,"severity":"high","line_start":1355},{"id":"sensitive:references/schema.json:4184:crypto-seed-private-key-mention","file":"references/schema.json","pattern":"Crypto seed/private key mention","snippet":"\"description\": \"Path to a PEM file containing the private key of `client_cert`.\\n\\nThis file must co","category":"sensitive","line_end":4184,"severity":"high","line_start":4184},{"id":"sensitive:references/schema.json:4197:crypto-seed-private-key-mention","file":"references/schema.json","pattern":"Crypto seed/private key mention","snippet":"\"description\": \"Path to a PEM file containing the certificate chain used by the local application's\\","category":"sensitive","line_end":4197,"severity":"high","line_start":4197},{"id":"sensitive:references/schema.json:4213:crypto-seed-private-key-mention","file":"references/schema.json","pattern":"Crypto seed/private key mention","snippet":"\"description\": \"Paths to PEM files and directories with PEM files containing allowed root certificat","category":"sensitive","line_end":4213,"severity":"high","line_start":4213},{"id":"sensitive:references/configuration.md:708:environment-file-access","file":"references/configuration.md","pattern":"Environment file access","snippet":"## feature.env {#feature-env}","category":"sensitive","line_end":708,"severity":"high","line_start":708},{"id":"sensitive:references/configuration.md:748:environment-file-access","file":"references/configuration.md","pattern":"Environment file access","snippet":"### feature.env.exclude {#feature-env-exclude}","category":"sensitive","line_end":748,"severity":"high","line_start":748},{"id":"sensitive:references/configuration.md:760:environment-file-access","file":"references/configuration.md","pattern":"Environment file access","snippet":"### feature.env.include {#feature-env-include}","category":"sensitive","line_end":760,"severity":"high","line_start":760},{"id":"sensitive:references/configuration.md:771:environment-file-access","file":"references/configuration.md","pattern":"Environment file access","snippet":"### feature.env.load_from_process {#feature-env-load_from_process}","category":"sensitive","line_end":771,"severity":"high","line_start":771},{"id":"sensitive:references/configuration.md:779:environment-file-access","file":"references/configuration.md","pattern":"Environment file access","snippet":"### feature.env.mapping {#feature-env-mapping}","category":"sensitive","line_end":779,"severity":"high","line_start":779},{"id":"sensitive:references/configuration.md:802:environment-file-access","file":"references/configuration.md","pattern":"Environment file access","snippet":"### feature.env.override {#feature-env-override}","category":"sensitive","line_end":802,"severity":"high","line_start":802},{"id":"sensitive:references/configuration.md:811:environment-file-access","file":"references/configuration.md","pattern":"Environment file access","snippet":"### feature.env.unset {#feature-env-unset}","category":"sensitive","line_end":811,"severity":"high","line_start":811},{"id":"sensitive:references/schema.json:1560:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"sensitive","line_end":1560,"severity":"high","line_start":1560},{"id":"sensitive:references/schema.json:2933:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.env_file {#feature-env-env-file}\",","category":"sensitive","line_end":2933,"severity":"high","line_start":2933},{"id":"sensitive:references/schema.json:2941:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.exclude {#feature-env-exclude}\",","category":"sensitive","line_end":2941,"severity":"high","line_start":2941},{"id":"sensitive:references/schema.json:2953:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.include {#feature-env-include}\",","category":"sensitive","line_end":2953,"severity":"high","line_start":2953},{"id":"sensitive:references/schema.json:2965:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.load_from_process {#feature-env-load_from_process}\",","category":"sensitive","line_end":2965,"severity":"high","line_start":2965},{"id":"sensitive:references/schema.json:2973:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.mapping {#feature-env-mapping}\",","category":"sensitive","line_end":2973,"severity":"high","line_start":2973},{"id":"sensitive:references/schema.json:2984:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.override {#feature-env-override}\",","category":"sensitive","line_end":2984,"severity":"high","line_start":2984},{"id":"sensitive:references/schema.json:2995:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env.unset {#feature-env-unset}\",","category":"sensitive","line_end":2995,"severity":"high","line_start":2995},{"id":"sensitive:references/schema.json:3269:environment-file-access","file":"references/schema.json","pattern":"Environment file access","snippet":"\"title\": \"feature.env {#feature-env}\",","category":"sensitive","line_end":3269,"severity":"high","line_start":3269},{"id":"sensitive:SKILL.md:61:yarn-config-file","file":"SKILL.md","pattern":"Yarn config file","snippet":"- Runtime and package-manager paths: `/node_modules`, `/package.json`, `.yarnrc*`, `.tool-versions`","category":"sensitive","line_end":61,"severity":"high","line_start":61},{"id":"obfuscation:references/schema.json:2628:heuristic-extremely-long-line-2173-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2173 chars) - likely obfuscated","snippet":"      \"description\": \"Different ways of connecting to the source database.\\n\\nAccepts three formats:","category":"obfuscation","line_end":2628,"severity":"high","line_start":2628},{"id":"obfuscation:references/schema.json:4945:heuristic-extremely-long-line-2207-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2207 chars) - likely obfuscated","snippet":"          \"description\": \"Files to mount into the preview pod at session start, stored as a\\nKuberne","category":"obfuscation","line_end":4945,"severity":"high","line_start":4945},{"id":"obfuscation:references/schema.json:317:heuristic-extremely-long-line-2227-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2227 chars) - likely obfuscated","snippet":"          \"description\": \"Remote paths to download from the target before the local process starts.\\","category":"obfuscation","line_end":317,"severity":"high","line_start":317},{"id":"obfuscation:references/schema.json:4171:heuristic-extremely-long-line-2402-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2402 chars) - likely obfuscated","snippet":"      \"description\": \"Stolen TLS traffic can be delivered to the local application either as TLS or ","category":"obfuscation","line_end":4171,"severity":"high","line_start":4171},{"id":"obfuscation:references/schema.json:4871:heuristic-extremely-long-line-2405-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2405 chars) - likely obfuscated","snippet":"          \"description\": \"Files to mount into the preview pod at session start.\\n\\nEach entry projec","category":"obfuscation","line_end":4871,"severity":"high","line_start":4871},{"id":"obfuscation:references/schema.json:6212:heuristic-extremely-long-line-2479-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2479 chars) - likely obfuscated","snippet":"      \"description\": \"Quantity is a fixed-point representation of a number. It provides convenient m","category":"obfuscation","line_end":6212,"severity":"high","line_start":6212},{"id":"obfuscation:references/schema.json:3521:heuristic-extremely-long-line-2856-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2856 chars) - likely obfuscated","snippet":"      \"description\": \"Filter configuration for the HTTP traffic stealer feature.\\n\\nAllows the user ","category":"obfuscation","line_end":3521,"severity":"high","line_start":3521},{"id":"obfuscation:references/schema.json:5617:heuristic-extremely-long-line-2902-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2902 chars) - likely obfuscated","snippet":"                \"description\": \"When this field is specified, for each message, the jq filter runs o","category":"obfuscation","line_end":5617,"severity":"high","line_start":5617},{"id":"obfuscation:references/schema.json:5679:heuristic-extremely-long-line-2902-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (2902 chars) - likely obfuscated","snippet":"                \"description\": \"When this field is specified, for each message, the jq filter runs o","category":"obfuscation","line_end":5679,"severity":"high","line_start":5679},{"id":"obfuscation:references/schema.json:266:heuristic-extremely-long-line-3907-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (3907 chars) - likely obfuscated","snippet":"      \"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"","category":"obfuscation","line_end":266,"severity":"high","line_start":266},{"id":"obfuscation:references/schema.json:1560:heuristic-extremely-long-line-5684-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (5684 chars) - likely obfuscated","snippet":"          \"description\": \"When branching a database, cache, or any other stateful service that mirro","category":"obfuscation","line_end":1560,"severity":"high","line_start":1560},{"id":"obfuscation:references/schema.json:4:heuristic-extremely-long-line-6665-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (6665 chars) - likely obfuscated","snippet":"  \"description\": \"mirrord allows for a high degree of customization when it comes to which features ","category":"obfuscation","line_end":4,"severity":"high","line_start":4},{"id":"obfuscation:references/schema.json:1276:heuristic-extremely-long-line-9956-chars-likely-","file":"references/schema.json","pattern":"[HEURISTIC] Extremely long line (9956 chars) - likely obfuscated","snippet":"      \"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my","category":"obfuscation","line_end":1276,"severity":"high","line_start":1276},{"id":"env_access:references/schema.json:3609:aws-credential-environment-variables","file":"references/schema.json","pattern":"AWS credential environment variables","snippet":"\"description\": \"For AWS RDS/Aurora IAM authentication, set `type` to `\\\"aws_rds\\\"`.\\n\\nCredentials f","category":"env_access","line_end":3609,"severity":"high","line_start":3609},{"id":"env_access:references/schema.json:1276:database-connection-strings","file":"references/schema.json","pattern":"Database connection strings","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"env_access","line_end":1276,"severity":"high","line_start":1276},{"id":"env_access:references/schema.json:2246:database-connection-strings","file":"references/schema.json","pattern":"Database connection strings","snippet":"\"description\": \"Configuration for a local Redis branch.\\n\\nExample with URL-based connection:\\n```js","category":"env_access","line_end":2246,"severity":"high","line_start":2246},{"id":"env_access:references/schema.json:2628:database-connection-strings","file":"references/schema.json","pattern":"Database connection strings","snippet":"\"description\": \"Different ways of connecting to the source database.\\n\\nAccepts three formats:\\n\\nLe","category":"env_access","line_end":2628,"severity":"high","line_start":2628},{"id":"env_access:references/schema.json:3663:gcp-credential-environment-variables","file":"references/schema.json","pattern":"GCP credential environment variables","snippet":"\"description\": \"For GCP Cloud SQL IAM authentication, set `type` to `\\\"gcp_cloud_sql\\\"`.\\n\\nExample ","category":"env_access","line_end":3663,"severity":"high","line_start":3663},{"id":"env_access:references/schema.json:2552:generic-api-secret-keys","file":"references/schema.json","pattern":"Generic API/secret keys","snippet":"\"description\": \"When configuring a branch for a turbopuffer namespace, set `type` to `turbopuffer`.\\","category":"env_access","line_end":2552,"severity":"high","line_start":2552},{"id":"env_access:references/schema.json:2586:generic-api-secret-keys","file":"references/schema.json","pattern":"Generic API/secret keys","snippet":"\"description\": \"Where to read the source namespace, the API key and the region from, in the same\\npa","category":"env_access","line_end":2586,"severity":"high","line_start":2586},{"id":"filesystem:references/configuration.md:138:hidden-file-in-home-directory","file":"references/configuration.md","pattern":"Hidden file in home directory","snippet":"\"kubeconfig\": \"~/.kube/config\",","category":"filesystem","line_end":138,"severity":"high","line_start":138},{"id":"filesystem:references/configuration.md:1646:hidden-file-in-home-directory","file":"references/configuration.md","pattern":"Hidden file in home directory","snippet":"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/config`, or","category":"filesystem","line_end":1646,"severity":"high","line_start":1646},{"id":"filesystem:references/schema.json:4:hidden-file-in-home-directory","file":"references/schema.json","pattern":"Hidden file in home directory","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"filesystem","line_end":4,"severity":"high","line_start":4},{"id":"filesystem:references/schema.json:28:hidden-file-in-home-directory","file":"references/schema.json","pattern":"Hidden file in home directory","snippet":"\"description\": \"Enables the local session monitor API server.\\n\\nWhen enabled, mirrord exposes a Uni","category":"filesystem","line_end":28,"severity":"high","line_start":28},{"id":"filesystem:references/schema.json:130:hidden-file-in-home-directory","file":"references/schema.json","pattern":"Hidden file in home directory","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"filesystem","line_end":130,"severity":"high","line_start":130},{"id":"filesystem:references/schema.json:3139:hidden-file-in-home-directory","file":"references/schema.json","pattern":"Hidden file in home directory","snippet":"\"description\": \"Extract pre-built SIP utility binaries into `~/.mirrord/binaries` on macOS and uses\\","category":"filesystem","line_end":3139,"severity":"high","line_start":3139},{"id":"filesystem:references/schema.json:4239:hidden-file-in-home-directory","file":"references/schema.json","pattern":"Hidden file in home directory","snippet":"\"description\": \"The AWS CLI prefers local credentials (e.g. `~/.aws`, `AWS_PROFILE`) over the remote","category":"filesystem","line_end":4239,"severity":"high","line_start":4239},{"id":"filesystem:references/configuration.md:904:non-standard-device-file-access","file":"references/configuration.md","pattern":"Non-standard device file access","snippet":"\"^/home/(?<user>\\\\S+)/dev/config/(?<app>\\\\S+)\": \"/mnt/configs/${user}-$app\"","category":"filesystem","line_end":904,"severity":"high","line_start":904},{"id":"filesystem:references/configuration.md:910:non-standard-device-file-access","file":"references/configuration.md","pattern":"Non-standard device file access","snippet":"`/home/johndoe/dev/config/api/app.conf` => `/mnt/configs/johndoe-api/app.conf`","category":"filesystem","line_end":910,"severity":"high","line_start":910},{"id":"filesystem:references/schema.json:283:non-standard-device-file-access","file":"references/schema.json","pattern":"Non-standard device file access","snippet":"\"description\": \"Specify map of patterns that if matched will replace the path according to specifica","category":"filesystem","line_end":283,"severity":"high","line_start":283},{"id":"filesystem:references/configuration.md:913:path-traversal-sequence","file":"references/configuration.md","pattern":"Path traversal sequence","snippet":"`../dev`.","category":"filesystem","line_end":913,"severity":"high","line_start":913},{"id":"filesystem:references/schema.json:283:path-traversal-sequence","file":"references/schema.json","pattern":"Path traversal sequence","snippet":"\"description\": \"Specify map of patterns that if matched will replace the path according to specifica","category":"filesystem","line_end":283,"severity":"high","line_start":283},{"id":"filesystem:references/schema.json:2427:path-traversal-sequence","file":"references/schema.json","pattern":"Path traversal sequence","snippet":"\"description\": \"Where to read the source bucket's name from, in the same params shape the other engi","category":"filesystem","line_end":2427,"severity":"high","line_start":2427},{"id":"filesystem:references/schema.json:2586:path-traversal-sequence","file":"references/schema.json","pattern":"Path traversal sequence","snippet":"\"description\": \"Where to read the source namespace, the API key and the region from, in the same\\npa","category":"filesystem","line_end":2586,"severity":"high","line_start":2586},{"id":"sensitive:references/schema.json:1276:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"sensitive","line_end":1276,"severity":"medium","line_start":1276},{"id":"sensitive:references/schema.json:1484:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: dynamodb) {#feature-db_branches-dynamodb-iam_auth}\",","category":"sensitive","line_end":1484,"severity":"medium","line_start":1484},{"id":"sensitive:references/schema.json:1560:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"sensitive","line_end":1560,"severity":"medium","line_start":1560},{"id":"sensitive:references/schema.json:1720:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: mariadb) {#feature-db_branches-mariadb-iam_auth}\",","category":"sensitive","line_end":1720,"severity":"medium","line_start":1720},{"id":"sensitive:references/schema.json:1829:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: mongodb) {#feature-db_branches-mongodb-iam_auth}\",","category":"sensitive","line_end":1829,"severity":"medium","line_start":1829},{"id":"sensitive:references/schema.json:2024:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: mysql) {#feature-db_branches-mysql-iam_auth}\",","category":"sensitive","line_end":2024,"severity":"medium","line_start":2024},{"id":"sensitive:references/schema.json:2119:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection_settings (type: pg) {#feature-db_branches-pg-connection_s","category":"sensitive","line_end":2119,"severity":"medium","line_start":2119},{"id":"sensitive:references/schema.json:2141:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: pg) {#feature-db_branches-pg-iam_auth}\",","category":"sensitive","line_end":2141,"severity":"medium","line_start":2141},{"id":"sensitive:references/schema.json:2192:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].query_params (type: pg) {#feature-db_branches-pg-query_params}\",","category":"sensitive","line_end":2192,"severity":"medium","line_start":2192},{"id":"sensitive:references/schema.json:2250:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection (type: redis) {#feature-db_branches-redis-connection}\",","category":"sensitive","line_end":2250,"severity":"medium","line_start":2250},{"id":"sensitive:references/schema.json:2264:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].id (type: redis) {#feature-db_branches-redis-id}\",","category":"sensitive","line_end":2264,"severity":"medium","line_start":2264},{"id":"sensitive:references/schema.json:2273:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local (type: redis) {#feature-db_branches-redis-local}\",","category":"sensitive","line_end":2273,"severity":"medium","line_start":2273},{"id":"sensitive:references/schema.json:2289:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"description\": \"#### feature.db_branches[].location (type: redis) {#feature-db_branches-redis-locati","category":"sensitive","line_end":2289,"severity":"medium","line_start":2289},{"id":"sensitive:references/schema.json:2304:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].copy (type: redis) {#feature-db_branches-redis-copy}\",","category":"sensitive","line_end":2304,"severity":"medium","line_start":2304},{"id":"sensitive:references/schema.json:2333:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"description\": \"#### feature.db_branches[].location (type: redis) {#feature-db_branches-redis-locati","category":"sensitive","line_end":2333,"severity":"medium","line_start":2333},{"id":"sensitive:references/schema.json:2391:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].copy (type: s3) {#feature-db_branches-s3-copy}\",","category":"sensitive","line_end":2391,"severity":"medium","line_start":2391},{"id":"sensitive:references/schema.json:2420:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].provider (type: s3) {#feature-db_branches-s3-provider}\",","category":"sensitive","line_end":2420,"severity":"medium","line_start":2420},{"id":"sensitive:references/schema.json:2426:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].source (type: s3) {#feature-db_branches-s3-source}\",","category":"sensitive","line_end":2426,"severity":"medium","line_start":2426},{"id":"sensitive:references/schema.json:2482:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].emulator_host (type: spanner) {#feature-db_branches-spanner-emulator","category":"sensitive","line_end":2482,"severity":"medium","line_start":2482},{"id":"sensitive:references/schema.json:2556:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].copy (type: turbopuffer) {#feature-db_branches-turbopuffer-copy}\",","category":"sensitive","line_end":2556,"severity":"medium","line_start":2556},{"id":"sensitive:references/schema.json:2585:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].source (type: turbopuffer) {#feature-db_branches-turbopuffer-source}","category":"sensitive","line_end":2585,"severity":"medium","line_start":2585},{"id":"sensitive:references/schema.json:3257:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches {#feature-db_branches}\",","category":"sensitive","line_end":3257,"severity":"medium","line_start":3257},{"id":"sensitive:references/schema.json:5147:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.database (type: redis)\",","category":"sensitive","line_end":5147,"severity":"medium","line_start":5147},{"id":"sensitive:references/schema.json:5159:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.host (type: redis)\",","category":"sensitive","line_end":5159,"severity":"medium","line_start":5159},{"id":"sensitive:references/schema.json:5172:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.password (type: redis)\",","category":"sensitive","line_end":5172,"severity":"medium","line_start":5172},{"id":"sensitive:references/schema.json:5185:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.port (type: redis)\",","category":"sensitive","line_end":5185,"severity":"medium","line_start":5185},{"id":"sensitive:references/schema.json:5197:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.tls (type: redis)\",","category":"sensitive","line_end":5197,"severity":"medium","line_start":5197},{"id":"sensitive:references/schema.json:5206:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.url (type: redis)\",","category":"sensitive","line_end":5206,"severity":"medium","line_start":5206},{"id":"sensitive:references/schema.json:5219:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.username (type: redis)\",","category":"sensitive","line_end":5219,"severity":"medium","line_start":5219},{"id":"sensitive:references/schema.json:5270:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.container_command (type: redis)\",","category":"sensitive","line_end":5270,"severity":"medium","line_start":5270},{"id":"sensitive:references/schema.json:5279:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.container_runtime (type: redis)\",","category":"sensitive","line_end":5279,"severity":"medium","line_start":5279},{"id":"sensitive:references/schema.json:5285:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.options (type: redis)\",","category":"sensitive","line_end":5285,"severity":"medium","line_start":5285},{"id":"sensitive:references/schema.json:5293:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.port (type: redis)\",","category":"sensitive","line_end":5293,"severity":"medium","line_start":5293},{"id":"sensitive:references/schema.json:5302:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.runtime (type: redis)\",","category":"sensitive","line_end":5302,"severity":"medium","line_start":5302},{"id":"sensitive:references/schema.json:5308:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.server_command (type: redis)\",","category":"sensitive","line_end":5308,"severity":"medium","line_start":5308},{"id":"sensitive:references/schema.json:5317:sqlite-database-file","file":"references/schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.version (type: redis)\",","category":"sensitive","line_end":5317,"severity":"medium","line_start":5317},{"id":"network:references/configuration.md:87:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"metrics\": \"0.0.0.0:9000\",","category":"network","line_end":87,"severity":"medium","line_start":87},{"id":"network:references/configuration.md:121:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"local\": [\"tcp://1.1.1.0/24:1337\", \"1.1.5.0/24\", \"google.com\", \":53\"]","category":"network","line_end":121,"severity":"medium","line_start":121},{"id":"network:references/configuration.md:129:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"local\": [\"1.1.1.0/24:1337\", \"1.1.5.0/24\", \"google.com\"]","category":"network","line_end":129,"severity":"medium","line_start":129},{"id":"network:references/configuration.md:339:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"metrics\": \"0.0.0.0:9000\"","category":"network","line_end":339,"severity":"medium","line_start":339},{"id":"network:references/configuration.md:453:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"connect_tcp\": \"10.10.0.100:7777\"","category":"network","line_end":453,"severity":"medium","line_start":453},{"id":"network:references/configuration.md:654:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"local\": [\"tcp://1.1.1.0/24:1337\", \"1.1.5.0/24\", \"google.com\", \":53\"]","category":"network","line_end":654,"severity":"medium","line_start":654},{"id":"network:references/configuration.md:968:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"local\": [\"tcp://1.1.1.0/24:1337\", \"1.1.5.0/24\", \"google.com\", \":53\"]","category":"network","line_end":968,"severity":"medium","line_start":968},{"id":"network:references/configuration.md:976:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"local\": [\"1.1.1.0/24:1337\", \"1.1.5.0/24\", \"google.com\"]","category":"network","line_end":976,"severity":"medium","line_start":976},{"id":"network:references/configuration.md:1025:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"remote\": [\"1.1.1.0/24:1337\"]","category":"network","line_end":1025,"severity":"medium","line_start":1025},{"id":"network:references/configuration.md:1451:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"local\": [\"tcp://1.1.1.0/24:1337\", \"1.1.5.0/24\", \"google.com\", \":53\"]","category":"network","line_end":1451,"severity":"medium","line_start":1451},{"id":"network:references/configuration.md:1477:hardcoded-ip-address","file":"references/configuration.md","pattern":"Hardcoded IP address","snippet":"\"remote\": [\"udp://1.1.1.0/24:1337\"]","category":"network","line_end":1477,"severity":"medium","line_start":1477},{"id":"network:references/schema.json:4:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"network","line_end":4,"severity":"medium","line_start":4},{"id":"network:references/schema.json:463:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Fixes passthrough requests failing when the target application listens on the pod's\\","category":"network","line_end":463,"severity":"medium","line_start":463},{"id":"network:references/schema.json:585:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Enables prometheus metrics for the agent pod.\\n\\nYou might need to add annotations t","category":"network","line_end":585,"severity":"medium","line_start":585},{"id":"network:references/schema.json:1168:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Allows to override the IP address for the internal proxy to use\\nwhen connecting to ","category":"network","line_end":1168,"severity":"medium","line_start":1168},{"id":"network:references/schema.json:2848:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"List of addresses/ports/subnets that should be resolved through either the remote po","category":"network","line_end":2848,"severity":"medium","line_start":2848},{"id":"network:references/schema.json:3179:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Specify a custom host ip addr to listen on.\\n\\nThis address must be accessible from ","category":"network","line_end":3179,"severity":"medium","line_start":3179},{"id":"network:references/schema.json:3241:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Controls mirrord features.\\n\\nSee the\\n[technical reference, Technical Reference](ht","category":"network","line_end":3241,"severity":"medium","line_start":3241},{"id":"network:references/schema.json:4247:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Next.js + Turbopack runs transforms (e.g. PostCSS for CSS) in pooled Node worker\\nsu","category":"network","line_end":4247,"severity":"medium","line_start":4247},{"id":"network:references/schema.json:4600:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Controls mirrord network operations.\\n\\nSee the network traffic [reference](https://","category":"network","line_end":4600,"severity":"medium","line_start":4600},{"id":"network:references/schema.json:4648:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"Tunnel outgoing network operations through mirrord.\\n\\nSee the outgoing [reference](","category":"network","line_end":4648,"severity":"medium","line_start":4648},{"id":"network:references/schema.json:4703:hardcoded-ip-address","file":"references/schema.json","pattern":"Hardcoded IP address","snippet":"\"description\": \"List of addresses/ports/subnets that should be sent through either the remote pod or","category":"network","line_end":4703,"severity":"medium","line_start":4703},{"id":"filesystem:references/configuration.md:138:hidden-file-access","file":"references/configuration.md","pattern":"Hidden file access","snippet":"\"kubeconfig\": \"~/.kube/config\",","category":"filesystem","line_end":138,"severity":"medium","line_start":138},{"id":"filesystem:references/configuration.md:1646:hidden-file-access","file":"references/configuration.md","pattern":"Hidden file access","snippet":"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/config`, or","category":"filesystem","line_end":1646,"severity":"medium","line_start":1646},{"id":"filesystem:references/schema.json:4:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"filesystem","line_end":4,"severity":"medium","line_start":4},{"id":"filesystem:references/schema.json:28:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"Enables the local session monitor API server.\\n\\nWhen enabled, mirrord exposes a Uni","category":"filesystem","line_end":28,"severity":"medium","line_start":28},{"id":"filesystem:references/schema.json:130:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"filesystem","line_end":130,"severity":"medium","line_start":130},{"id":"filesystem:references/schema.json:3139:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"Extract pre-built SIP utility binaries into `~/.mirrord/binaries` on macOS and uses\\","category":"filesystem","line_end":3139,"severity":"medium","line_start":3139},{"id":"filesystem:references/schema.json:4239:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"The AWS CLI prefers local credentials (e.g. `~/.aws`, `AWS_PROFILE`) over the remote","category":"filesystem","line_end":4239,"severity":"medium","line_start":4239},{"id":"filesystem:references/schema.json:5271:hidden-file-access","file":"references/schema.json","pattern":"Hidden file access","snippet":"\"description\": \"Custom path to the container command.\\nIf not provided, uses the runtime name from P","category":"filesystem","line_end":5271,"severity":"medium","line_start":5271},{"id":"filesystem:references/configuration.md:931:node-js-fs-operations","file":"references/configuration.md","pattern":"Node.js fs operations","snippet":"### feature.fs.read_only {#feature-fs-read_only}","category":"filesystem","line_end":931,"severity":"medium","line_start":931},{"id":"filesystem:references/configuration.md:936:node-js-fs-operations","file":"references/configuration.md","pattern":"Node.js fs operations","snippet":"### feature.fs.read_write {#feature-fs-read_write}","category":"filesystem","line_end":936,"severity":"medium","line_start":936},{"id":"filesystem:references/schema.json:337:node-js-fs-operations","file":"references/schema.json","pattern":"Node.js fs operations","snippet":"\"title\": \"feature.fs.read_only {#feature-fs-read_only}\",","category":"filesystem","line_end":337,"severity":"medium","line_start":337},{"id":"filesystem:references/schema.json:349:node-js-fs-operations","file":"references/schema.json","pattern":"Node.js fs operations","snippet":"\"title\": \"feature.fs.read_write {#feature-fs-read_write}\",","category":"filesystem","line_end":349,"severity":"medium","line_start":349},{"id":"filesystem:references/schema.json:361:node-js-fs-operations","file":"references/schema.json","pattern":"Node.js fs operations","snippet":"\"title\": \"feature.fs.readonly_file_buffer {#feature-fs-readonly_file_buffer}\",","category":"filesystem","line_end":361,"severity":"medium","line_start":361},{"id":"filesystem:references/schema.json:4231:node-js-fs-operations","file":"references/schema.json","pattern":"Node.js fs operations","snippet":"\"description\": \"Kubernetes mounts ConfigMaps, Secrets, and volumes (e.g. PVCs) into the target conta","category":"filesystem","line_end":4231,"severity":"medium","line_start":4231},{"id":"filesystem:SKILL.md:75:node-js-fs-operations","file":"SKILL.md","pattern":"Node.js fs operations","snippet":"| App must write files that land in the pod | `write`, or list paths in `fs.read_write` |","category":"filesystem","line_end":75,"severity":"medium","line_start":75},{"id":"filesystem:SKILL.md:79:node-js-fs-operations","file":"SKILL.md","pattern":"Node.js fs operations","snippet":"`localwithoverrides` reads only `/etc/resolv.conf`, `/etc/hosts` and `/etc/hostname` remotely by def","category":"filesystem","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:references/schema.json:4:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"external_commands","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:references/schema.json:28:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Enables the local session monitor API server.\\n\\nWhen enabled, mirrord exposes a Uni","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:references/schema.json:110:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"An identifier for a mirrord session.\\n\\nThe key can be referenced in your configurat","category":"external_commands","line_end":110,"severity":"medium","line_start":110},{"id":"external_commands:references/schema.json:122:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Kube context to use from the kubeconfig file.\\nWill use current context if not speci","category":"external_commands","line_end":122,"severity":"medium","line_start":122},{"id":"external_commands:references/schema.json:130:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Path to a kubeconfig file, if not specified, will use `KUBECONFIG`, or `~/.kube/conf","category":"external_commands","line_end":130,"severity":"medium","line_start":130},{"id":"external_commands:references/schema.json:138:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls multi-cluster session behavior when connecting to a multi-cluster Primary\\n","category":"external_commands","line_end":138,"severity":"medium","line_start":138},{"id":"external_commands:references/schema.json:154:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Name of the mirrord profile to use.\\n\\nTo select a cluster-wide profile\\n\\n```json\\n","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:references/schema.json:162:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Binaries to patch (macOS SIP).\\n\\nUse this when mirrord isn't loaded to protected bi","category":"external_commands","line_end":162,"severity":"medium","line_start":162},{"id":"external_commands:references/schema.json:174:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip build tools. Useful when running command lines that build and","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:references/schema.json:182:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip the specified build tools. Useful when running command lines ","category":"external_commands","line_end":182,"severity":"medium","line_start":182},{"id":"external_commands:references/schema.json:194:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip unwanted processes.\\n\\nUseful when process A spawns process B","category":"external_commands","line_end":194,"severity":"medium","line_start":194},{"id":"external_commands:references/schema.json:206:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows mirrord to skip patching (macOS SIP) unwanted processes.\\n\\nWhen patching is ","category":"external_commands","line_end":256,"severity":"medium","line_start":206},{"id":"external_commands:references/schema.json:256:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When disabled, mirrord will remove `HTTP[S]_PROXY` env variables before\\ndoing any n","category":"external_commands","line_end":266,"severity":"medium","line_start":256},{"id":"external_commands:references/schema.json:266:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"read\\\"","category":"external_commands","line_end":266,"severity":"medium","line_start":266},{"id":"external_commands:references/schema.json:271:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify file path patterns that if matched will be opened locally.\\n\\n##### Windows\\","category":"external_commands","line_end":271,"severity":"medium","line_start":271},{"id":"external_commands:references/schema.json:283:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify map of patterns that if matched will replace the path according to specifica","category":"external_commands","line_end":283,"severity":"medium","line_start":283},{"id":"external_commands:references/schema.json:305:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify file path patterns that if matched will be treated as non-existent.\\n\\n#####","category":"external_commands","line_end":305,"severity":"medium","line_start":305},{"id":"external_commands:references/schema.json:317:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Remote paths to download from the target before the local process starts.\\n\\nEach pa","category":"external_commands","line_end":317,"severity":"medium","line_start":317},{"id":"external_commands:references/schema.json:328:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How long to wait, in seconds, for each request to the agent made while copying\\n[`pr","category":"external_commands","line_end":338,"severity":"medium","line_start":328},{"id":"external_commands:references/schema.json:338:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify file path patterns that if matched will be read from the remote.\\nif file ma","category":"external_commands","line_end":338,"severity":"medium","line_start":338},{"id":"external_commands:references/schema.json:350:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specify file path patterns that if matched will be read and written to the remote.\\n","category":"external_commands","line_end":350,"severity":"medium","line_start":350},{"id":"external_commands:references/schema.json:374:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for the mirrord-agent pod that is spawned in the Kubernetes cluster.\\n","category":"external_commands","line_end":374,"severity":"medium","line_start":374},{"id":"external_commands:references/schema.json:379:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom annotations for the agent Job and Pod.\\n\\n```json\\n{\\n  \\\"a","category":"external_commands","line_end":379,"severity":"medium","line_start":379},{"id":"external_commands:references/schema.json:425:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"If nothing is disabled here, agent uses:\\n1. `NET_ADMIN`,\\n2. `SYS_PTRACE`,\\n3. `SYS","category":"external_commands","line_end":425,"severity":"medium","line_start":425},{"id":"external_commands:references/schema.json:447:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Runs the agent as an\\n[ephemeral container](https://kubernetes.io/docs/concepts/work","category":"external_commands","line_end":463,"severity":"medium","line_start":447},{"id":"external_commands:references/schema.json:463:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Fixes passthrough requests failing when the target application listens on the pod's\\","category":"external_commands","line_end":463,"severity":"medium","line_start":463},{"id":"external_commands:references/schema.json:471:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Flushes existing connections when starting to steal, might fix issues where connecti","category":"external_commands","line_end":489,"severity":"medium","line_start":471},{"id":"external_commands:references/schema.json:489:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Name of the agent's docker image.\\n\\nUseful when a custom build of mirrord-agent is ","category":"external_commands","line_end":489,"severity":"medium","line_start":489},{"id":"external_commands:references/schema.json:501:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls when a new agent image is downloaded.\\n\\nSupports `\\\"IfNotPresent\\\"`, `\\\"Al","category":"external_commands","line_end":501,"severity":"medium","line_start":501},{"id":"external_commands:references/schema.json:509:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"List of secrets the agent pod has access to.\\n\\nTakes an array of entries with the f","category":"external_commands","line_end":509,"severity":"medium","line_start":509},{"id":"external_commands:references/schema.json:520:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Sets whether `Mirrord-Agent` headers are injected into HTTP\\nresponses that went thr","category":"external_commands","line_end":520,"severity":"medium","line_start":520},{"id":"external_commands:references/schema.json:538:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls whether the agent produces logs in a human-friendly format, or json.\\n\\n```","category":"external_commands","line_end":538,"severity":"medium","line_start":538},{"id":"external_commands:references/schema.json:546:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom labels for the agent Job and Pod.\\n\\n```json\\n{\\n  \\\"agent\\","category":"external_commands","line_end":546,"severity":"medium","line_start":546},{"id":"external_commands:references/schema.json:557:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Log level for the agent.\\n\\n\\nSupports `\\\"trace\\\"`, `\\\"debug\\\"`, `\\\"info\\\"`, `\\\"warn","category":"external_commands","line_end":557,"severity":"medium","line_start":557},{"id":"external_commands:references/schema.json:585:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Enables prometheus metrics for the agent pod.\\n\\nYou might need to add annotations t","category":"external_commands","line_end":585,"severity":"medium","line_start":585},{"id":"external_commands:references/schema.json:601:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Determines which iptables backend will be used for traffic redirection.\\n\\nIf set to","category":"external_commands","line_end":601,"severity":"medium","line_start":601},{"id":"external_commands:references/schema.json:609:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom node selector for the agent Pod. Applies only to targetless","category":"external_commands","line_end":609,"severity":"medium","line_start":609},{"id":"external_commands:references/schema.json:620:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Sets whether the `Cache-Control` header in HTTP responses that went through the agen","category":"external_commands","line_end":620,"severity":"medium","line_start":620},{"id":"external_commands:references/schema.json:628:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Specifies the priority class to assign to the agent pod.\\n\\n```json\\n{\\n  \\\"agent\\\":","category":"external_commands","line_end":628,"severity":"medium","line_start":628},{"id":"external_commands:references/schema.json:636:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Run the mirror agent as privileged container.\\nDefaults to `false`.\\n\\nMight be need","category":"external_commands","line_end":644,"severity":"medium","line_start":636},{"id":"external_commands:references/schema.json:644:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set pod resource requirements. (not with ephemeral agents)\\nDefault is\\n```json\\n{\\n","category":"external_commands","line_end":644,"severity":"medium","line_start":644},{"id":"external_commands:references/schema.json:668:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows setting up custom Service Account for the agent Job and Pod.\\n\\n```json\\n{\\n ","category":"external_commands","line_end":668,"severity":"medium","line_start":668},{"id":"external_commands:references/schema.json:676:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls how long to wait for the agent to finish initialization.\\n\\nIf initializati","category":"external_commands","line_end":686,"severity":"medium","line_start":676},{"id":"external_commands:references/schema.json:686:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Set pod tolerations. (not with ephemeral agents).\\n\\nDefaults to `operator: Exists`.","category":"external_commands","line_end":686,"severity":"medium","line_start":686},{"id":"external_commands:references/schema.json:697:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Controls how long the agent pod persists for after the agent exits (in seconds).\\n\\n","category":"external_commands","line_end":713,"severity":"medium","line_start":697},{"id":"external_commands:references/schema.json:713:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"The shortened version of: `image: \\\"repo/mirrord:latest\\\"`.\",","category":"external_commands","line_end":720,"severity":"medium","line_start":713},{"id":"external_commands:references/schema.json:720:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Expanded version: `image: { registry: \\\"repo/mirrord\\\", tag: \\\"latest\\\" }`.\",","category":"external_commands","line_end":763,"severity":"medium","line_start":720},{"id":"external_commands:references/schema.json:763:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Tries to parse the body as a JSON object and find (a) matching subobjects(s).\\n\\n`qu","category":"external_commands","line_end":763,"severity":"medium","line_start":763},{"id":"external_commands:references/schema.json:800:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for mirrord for CI.\\n\\n```json\\n{\\n  \\\"ci\\\": {\\n    \\\"output_dir\\\": \\\"","category":"external_commands","line_end":800,"severity":"medium","line_start":800},{"id":"external_commands:references/schema.json:805:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Path to a directory where `mirrord ci` will flush application's stdout and stderr.\\n","category":"external_commands","line_end":805,"severity":"medium","line_start":805},{"id":"external_commands:references/schema.json:815:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their ClickHouse branch d","category":"external_commands","line_end":815,"severity":"medium","line_start":815},{"id":"external_commands:references/schema.json:877:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their CockroachDB branch ","category":"external_commands","line_end":877,"severity":"medium","line_start":877},{"id":"external_commands:references/schema.json:939:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"(Operator Only): Allows overriding port locks\\n\\nCan be set to either `\\\"continue\\\"`","category":"external_commands","line_end":939,"severity":"medium","line_start":939},{"id":"external_commands:references/schema.json:959:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"A single file to project into the preview pod's container filesystem.\\n\\nEither `pay","category":"external_commands","line_end":959,"severity":"medium","line_start":959},{"id":"external_commands:references/schema.json:963:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Local filesystem path to read the file from. The contents are loaded\\nat session cre","category":"external_commands","line_end":963,"severity":"medium","line_start":963},{"id":"external_commands:references/schema.json:974:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Inline file contents. Interpretation depends on `type`: for `\\\"text\\\"`,\\nwritten to ","category":"external_commands","line_end":974,"severity":"medium","line_start":974},{"id":"external_commands:references/schema.json:981:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How the `payload` payload should be interpreted when writing it to the\\nfile. `\\\"tex","category":"external_commands","line_end":981,"severity":"medium","line_start":981},{"id":"external_commands:references/schema.json:997:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Encoding of a [`ConfigMount::payload`] payload.\",","category":"external_commands","line_end":1000,"severity":"medium","line_start":997},{"id":"external_commands:references/schema.json:1000:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"`payload` is written to the file verbatim. Used for\\nhuman-readable config files (YA","category":"external_commands","line_end":1005,"severity":"medium","line_start":1000},{"id":"external_commands:references/schema.json:1005:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"`payload` is base64-encoded and is decoded before being\\nwritten. Used for binary fi","category":"external_commands","line_end":1012,"severity":"medium","line_start":1005},{"id":"external_commands:references/schema.json:1012:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Connection parameters specified as individual environment variable names.\\nThe `type","category":"external_commands","line_end":1012,"severity":"medium","line_start":1012},{"id":"external_commands:references/schema.json:1035:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Individual database connection parameter sources.\\nAt least one parameter must be sp","category":"external_commands","line_end":1035,"severity":"medium","line_start":1035},{"id":"external_commands:references/schema.json:1112:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Unstable: `mirrord container` command specific config.\",","category":"external_commands","line_end":1117,"severity":"medium","line_start":1112},{"id":"external_commands:references/schema.json:1117:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Any extra args to use when creating the sidecar mirrord-cli container.\\n\\nThis is us","category":"external_commands","line_end":1117,"severity":"medium","line_start":1117},{"id":"external_commands:references/schema.json:1128:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Tag of the `mirrord-cli` image you want to use.\\n\\nDefaults to `\\\"ghcr.io/metalbear-","category":"external_commands","line_end":1128,"severity":"medium","line_start":1128},{"id":"external_commands:references/schema.json:1144:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Don't add `--rm` to sidecar command to prevent cleanup.\",","category":"external_commands","line_end":1152,"severity":"medium","line_start":1144},{"id":"external_commands:references/schema.json:1152:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When using`mirrord container` with external_proxy TLS enabled (is enabled by default","category":"external_commands","line_end":1152,"severity":"medium","line_start":1152},{"id":"external_commands:references/schema.json:1160:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Connects the internal proxy sidecar to the external proxy through the container\\nrun","category":"external_commands","line_end":1160,"severity":"medium","line_start":1160},{"id":"external_commands:references/schema.json:1168:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows to override the IP address for the internal proxy to use\\nwhen connecting to ","category":"external_commands","line_end":1168,"severity":"medium","line_start":1168},{"id":"external_commands:references/schema.json:1177:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Platform specification for the target container (e.g., \\\"linux/amd64\\\", \\\"linux/arm6","category":"external_commands","line_end":1177,"severity":"medium","line_start":1177},{"id":"external_commands:references/schema.json:1208:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Allows the user to target a pod created dynamically from the original [`target`](#ta","category":"external_commands","line_end":1208,"severity":"medium","line_start":1208},{"id":"external_commands:references/schema.json:1276:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"external_commands","line_end":1276,"severity":"medium","line_start":1276},{"id":"external_commands:references/schema.json:1279:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for ClickHouse, set `type` to `clickhouse`.\",","category":"external_commands","line_end":1279,"severity":"medium","line_start":1279},{"id":"external_commands:references/schema.json:1308:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Full image reference for the branch container, including the tag. Overrides the\\nope","category":"external_commands","line_end":1329,"severity":"medium","line_start":1308},{"id":"external_commands:references/schema.json:1329:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1338,"severity":"medium","line_start":1329},{"id":"external_commands:references/schema.json:1338:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1365,"severity":"medium","line_start":1338},{"id":"external_commands:references/schema.json:1365:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for CockroachDB, set `type` to `cockroachdb`.\\n\\nCockroach","category":"external_commands","line_end":1365,"severity":"medium","line_start":1365},{"id":"external_commands:references/schema.json:1394:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Full image reference for the branch container, including the tag. Overrides the\\nope","category":"external_commands","line_end":1401,"severity":"medium","line_start":1394},{"id":"external_commands:references/schema.json:1401:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nDocumented on `DatabaseBranchConfig` (shared across SQL engines)","category":"external_commands","line_end":1426,"severity":"medium","line_start":1401},{"id":"external_commands:references/schema.json:1426:ruby-shell-backtick-execution","file":"references/schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1435,"severity":"medium","line_start":1426},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Generate and validate `mirrord.json` configuration files:","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Schema validation (`references/schema.json`) is sufficient; `mirrord verify-config` is an **option","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read BOTH reference files from this skill's `references/` directory:","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `references/schema.json` - Authoritative JSON Schema","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `references/configuration.md` - Configuration reference","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If using absolute paths, these are located relative to this skill's installation directory. Search f","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":38,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":40,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If `mirrord` is not available:","category":"external_commands","line_end":43,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Continue with schema-based validation from `references/schema.json` until CLI validation is possib","category":"external_commands","line_end":47,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Validate against `references/schema.json` first (required)","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Optional:** If `mirrord` is already installed locally, the user may run `mirrord verify-config /","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"## Your code is local by default — do not \"fix\" this with `fs.mode`","category":"external_commands","line_end":55,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**The single most common wrong config.** An agent reasons \"the app must run my local source, so I ne","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A built-in local-by-default list applies in all modes (`mirrord/layer-lib/src/file/unix/read_local_b","category":"external_commands","line_end":61,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Runtime and package-manager paths: `/node_modules`, `/package.json`, `.yarnrc*`, `.tool-versions`","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Source and build artifacts by extension: `.js`, `.py`, `.pyc`, `.rb`, `.jar`, `.class`, `.so`, `.d","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- System paths: `/usr`, `/lib`, `/bin`, `/etc`, `/home`, `/opt`, `/tmp`, `/proc`, `/sys`, `/dev`","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Hidden files under `$HOME`","category":"external_commands","line_end":66,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"So `ts-node`, `nodemon`, `python -m`, `go run`, `dotnet watch` etc. all load local source under the ","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Consequences of getting this wrong:** setting `local` or `localwithoverrides` silently cuts the ap","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Read pod config/secrets/volumes (almost always) | `read` — the default, so omit `fs` entirely |","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| App must write files that land in the pod | `write`, or list paths in `fs.read_write` |","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Reading the pod's FS actively breaks the app, and you need nothing from it | `local` |","category":"external_commands","line_end":77,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Same as `local`, but cluster DNS must keep working | `localwithoverrides` |","category":"external_commands","line_end":77,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`localwithoverrides` reads only `/etc/resolv.conf`, `/etc/hosts` and `/etc/hostname` remotely by def","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Outgoing traffic is already remote by default (`network.outgoing.tcp`/`udp` default to `true`). An","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":122,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":136,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"target\": \"pod/name\"` or `{\"path\": \"pod/name\", \"namespace\": \"staging\"}`","category":"external_commands","line_end":136,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Set `operator` if using operator mode","category":"external_commands","line_end":138,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Specify `kube_context` if needed","category":"external_commands","line_end":141,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"env\": true` - Mirror environment variables","category":"external_commands","line_end":142,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"env\": {\"include\": \"VAR1;VAR2\"}` - Selective inclusion","category":"external_commands","line_end":143,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"fs\": \"read\"` - Read pod files, write locally. **This is the default — omit it unless overriding*","category":"external_commands","line_end":144,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"network\": true` - Enable network mirroring","category":"external_commands","line_end":145,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"network\": {\"incoming\": {\"mode\": \"steal\"}}` - Steal incoming traffic","category":"external_commands","line_end":148,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Check schema for valid `incoming.mode` values (e.g., \"steal\", \"mirror\", \"off\")","category":"external_commands","line_end":153,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Example: `\"target\": \"{{ get_env(name=\\\"TARGET\\\", default=\\\"pod/fallback\\\") }}\"`","category":"external_commands","line_end":155,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- When a user provides a literal placeholder like `{{key}}`, use it verbatim — do **not** expand it ","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- No `additionalProperties` where schema forbids them","category":"external_commands","line_end":170,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use JSON Pointer style: `/feature/network/incoming/mode`","category":"external_commands","line_end":178,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- \"I need it to run my local code\" → No `fs` setting required; local code is already local in every ","category":"external_commands","line_end":178,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Unexplained timeout or hang → Diagnose before configuring. Do not invent an `outgoing.filter` or a","category":"external_commands","line_end":179,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Validate config against `references/schema.json`","category":"external_commands","line_end":202,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. If `mirrord` is installed, save config to temporary file and run `mirrord verify-config <file>`","category":"external_commands","line_end":202,"severity":"medium","line_start":202},{"id":"external_commands:references/schema.json:1276:shell-command-substitution","file":"references/schema.json","pattern":"Shell command substitution","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"external_commands","line_end":1276,"severity":"medium","line_start":1276},{"id":"external_commands:references/schema.json:1560:shell-command-substitution","file":"references/schema.json","pattern":"Shell command substitution","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"external_commands","line_end":1560,"severity":"medium","line_start":1560},{"id":"external_commands:references/schema.json:5833:shell-command-substitution","file":"references/schema.json","pattern":"Shell command substitution","snippet":"\"description\": \"Extra environment variables for the migration container. Values can reference the\\ni","category":"external_commands","line_end":5833,"severity":"medium","line_start":5833},{"id":"filesystem:references/schema.json:800:temp-directory-access","file":"references/schema.json","pattern":"Temp directory access","snippet":"\"description\": \"Configuration for mirrord for CI.\\n\\n```json\\n{\\n  \\\"ci\\\": {\\n    \\\"output_dir\\\": \\\"","category":"filesystem","line_end":800,"severity":"medium","line_start":800},{"id":"filesystem:references/schema.json:805:temp-directory-access","file":"references/schema.json","pattern":"Temp directory access","snippet":"\"description\": \"Path to a directory where `mirrord ci` will flush application's stdout and stderr.\\n","category":"filesystem","line_end":805,"severity":"medium","line_start":805},{"id":"external_commands:references/schema.json:1276:template-literal-with-command-substitution","file":"references/schema.json","pattern":"Template literal with command substitution","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"external_commands","line_end":1276,"severity":"medium","line_start":1276},{"id":"external_commands:references/schema.json:1560:template-literal-with-command-substitution","file":"references/schema.json","pattern":"Template literal with command substitution","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"external_commands","line_end":1560,"severity":"medium","line_start":1560},{"id":"external_commands:references/schema.json:5833:template-literal-with-command-substitution","file":"references/schema.json","pattern":"Template literal with command substitution","snippet":"\"description\": \"Extra environment variables for the migration container. Values can reference the\\ni","category":"external_commands","line_end":5833,"severity":"medium","line_start":5833},{"id":"external_commands:references/configuration.md:1669:unix-shell-invocation","file":"references/configuration.md","pattern":"Unix shell invocation","snippet":"while `/usr/bin/bash` would apply only for that binary).","category":"external_commands","line_end":1669,"severity":"medium","line_start":1669},{"id":"external_commands:references/schema.json:162:unix-shell-invocation","file":"references/schema.json","pattern":"Unix shell invocation","snippet":"\"description\": \"Binaries to patch (macOS SIP).\\n\\nUse this when mirrord isn't loaded to protected bi","category":"external_commands","line_end":162,"severity":"medium","line_start":162},{"id":"blocker:references/schema.json:3179:network-reconnaissance","file":"references/schema.json","pattern":"Network reconnaissance","snippet":"\"description\": \"Specify a custom host ip addr to listen on.\\n\\nThis address must be accessible from ","category":"blocker","line_end":3179,"severity":"low","line_start":3179},{"id":"blocker:SKILL.md:42:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Ask the user to install mirrord themselves via their approved process","category":"blocker","line_end":43,"severity":"low","line_start":42},{"id":"blocker:README.md:8:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"- **Generate** valid `mirrord.json` configs from natural language","category":"blocker","line_end":8,"severity":"low","line_start":8},{"id":"blocker:README.md:10:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"- **Fix** invalid configurations with explanations","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:references/configuration.md:149:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"Controls whether or not mirrord accepts invalid TLS certificates (e.g. self-signed","category":"blocker","line_end":149,"severity":"low","line_start":149},{"id":"blocker:references/configuration.md:268:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"Supports `\"IfNotPresent\"`, `\"Always\"`, `\"Never\"`, or any valid kubernetes","category":"blocker","line_end":268,"severity":"low","line_start":268},{"id":"blocker:references/configuration.md:372:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"\"node_selector\": { \"kubernetes.io/hostname\": \"node1\" }","category":"blocker","line_end":372,"severity":"low","line_start":372},{"id":"blocker:references/configuration.md:662:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"\"hostname\": true","category":"blocker","line_end":662,"severity":"low","line_start":662},{"id":"blocker:references/configuration.md:940:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"## feature.hostname {#feature-hostname}","category":"blocker","line_end":940,"severity":"low","line_start":940},{"id":"blocker:references/configuration.md:942:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"Should mirrord return the hostname of the target pod when calling `gethostname`","category":"blocker","line_end":942,"severity":"low","line_start":942},{"id":"blocker:references/configuration.md:1012:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"- Only queries for hostname `my-service-in-cluster` will go through the remote pod.","category":"blocker","line_end":1012,"severity":"low","line_start":1012},{"id":"blocker:references/configuration.md:1029:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"- Only queries for hostname `google.com` with service port `1337` or `7331` will go through the","category":"blocker","line_end":1029,"severity":"low","line_start":1029},{"id":"blocker:references/configuration.md:1054:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"Valid values follow this pattern: `[name|address|subnet/mask][:port]`.","category":"blocker","line_end":1054,"severity":"low","line_start":1054},{"id":"blocker:references/configuration.md:1323:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"1. If `server_cert` is given, and the found end-entity certificate contains a valid server name,","category":"blocker","line_end":1323,"severity":"low","line_start":1323},{"id":"blocker:references/configuration.md:1327:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"3. Otherwise, if the stolen request's URL contains a valid server name, that server name will be","category":"blocker","line_end":1327,"severity":"low","line_start":1327},{"id":"blocker:references/configuration.md:1346:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"Must be a valid DNS name or an IP address.","category":"blocker","line_end":1346,"severity":"low","line_start":1346},{"id":"blocker:references/configuration.md:1365:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"and you want to avoid redirecting traffic from some ports (for example, traffic from","category":"blocker","line_end":1365,"severity":"low","line_start":1365},{"id":"blocker:references/configuration.md:1374:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"we fallback to random ports to avoid port conflicts.","category":"blocker","line_end":1374,"severity":"low","line_start":1374},{"id":"blocker:references/configuration.md:1505:system-reconnaissance","file":"references/configuration.md","pattern":"System reconnaissance","snippet":"Valid values follow this pattern: `[protocol]://[name|address|subnet/mask]:[port]`.","category":"blocker","line_end":1505,"severity":"low","line_start":1505},{"id":"blocker:references/schema.json:4:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"blocker","line_end":4,"severity":"low","line_start":4},{"id":"blocker:references/schema.json:9:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Controls whether or not mirrord accepts invalid TLS certificates (e.g. self-signed\\n","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"blocker:references/schema.json:463:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Fixes passthrough requests failing when the target application listens on the pod's\\","category":"blocker","line_end":463,"severity":"low","line_start":463},{"id":"blocker:references/schema.json:501:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Controls when a new agent image is downloaded.\\n\\nSupports `\\\"IfNotPresent\\\"`, `\\\"Al","category":"blocker","line_end":501,"severity":"low","line_start":501},{"id":"blocker:references/schema.json:609:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Allows setting up custom node selector for the agent Pod. Applies only to targetless","category":"blocker","line_end":609,"severity":"low","line_start":609},{"id":"blocker:references/schema.json:763:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Tries to parse the body as a JSON object and find (a) matching subobjects(s).\\n\\n`qu","category":"blocker","line_end":763,"severity":"low","line_start":763},{"id":"blocker:references/schema.json:1160:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Connects the internal proxy sidecar to the external proxy through the container\\nrun","category":"blocker","line_end":1160,"severity":"low","line_start":1160},{"id":"blocker:references/schema.json:1276:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"blocker","line_end":1276,"severity":"low","line_start":1276},{"id":"blocker:references/schema.json:1301:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1301,"severity":"low","line_start":1301},{"id":"blocker:references/schema.json:1387:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1387,"severity":"low","line_start":1387},{"id":"blocker:references/schema.json:1496:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1496,"severity":"low","line_start":1496},{"id":"blocker:references/schema.json:1560:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"blocker","line_end":1560,"severity":"low","line_start":1560},{"id":"blocker:references/schema.json:1613:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1613,"severity":"low","line_start":1613},{"id":"blocker:references/schema.json:1732:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1732,"severity":"low","line_start":1732},{"id":"blocker:references/schema.json:1841:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1841,"severity":"low","line_start":1841},{"id":"blocker:references/schema.json:1927:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1927,"severity":"low","line_start":1927},{"id":"blocker:references/schema.json:2036:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":2036,"severity":"low","line_start":2036},{"id":"blocker:references/schema.json:2153:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":2153,"severity":"low","line_start":2153},{"id":"blocker:references/schema.json:2264:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.db_branches[].id (type: redis) {#feature-db_branches-redis-id}\",","category":"blocker","line_end":2264,"severity":"low","line_start":2264},{"id":"blocker:references/schema.json:2319:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":2319,"severity":"low","line_start":2319},{"id":"blocker:references/schema.json:2406:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":2406,"severity":"low","line_start":2406},{"id":"blocker:references/schema.json:2488:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":2488,"severity":"low","line_start":2488},{"id":"blocker:references/schema.json:2571:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":2571,"severity":"low","line_start":2571},{"id":"blocker:references/schema.json:2848:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"List of addresses/ports/subnets that should be resolved through either the remote po","category":"blocker","line_end":2848,"severity":"low","line_start":2848},{"id":"blocker:references/schema.json:3241:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Controls mirrord features.\\n\\nSee the\\n[technical reference, Technical Reference](ht","category":"blocker","line_end":3241,"severity":"low","line_start":3241},{"id":"blocker:references/schema.json:3290:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"hostname\": {","category":"blocker","line_end":3290,"severity":"low","line_start":3290},{"id":"blocker:references/schema.json:3291:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.hostname {#feature-hostname}\",","category":"blocker","line_end":3291,"severity":"low","line_start":3291},{"id":"blocker:references/schema.json:3292:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Should mirrord return the hostname of the target pod when calling `gethostname`\",","category":"blocker","line_end":3292,"severity":"low","line_start":3292},{"id":"blocker:references/schema.json:3761:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Mapping for local ports to actually used local ports.\\nWhen application listens on a","category":"blocker","line_end":3761,"severity":"low","line_start":3761},{"id":"blocker:references/schema.json:4086:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Only supported with `queue_type` of `Kafka`.\\n\\nDecodes the raw protobuf bytes in th","category":"blocker","line_end":4086,"severity":"low","line_start":4086},{"id":"blocker:references/schema.json:4171:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Stolen TLS traffic can be delivered to the local application either as TLS or as pla","category":"blocker","line_end":4171,"severity":"low","line_start":4171},{"id":"blocker:references/schema.json:4205:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Server name to use when making a connection.\\n\\nMust be a valid DNS name or an IP ad","category":"blocker","line_end":4205,"severity":"low","line_start":4205},{"id":"blocker:references/schema.json:4703:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"List of addresses/ports/subnets that should be sent through either the remote pod or","category":"blocker","line_end":4703,"severity":"low","line_start":4703},{"id":"blocker:references/schema.json:4871:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Files to mount into the preview pod at session start.\\n\\nEach entry projects a singl","category":"blocker","line_end":4871,"severity":"low","line_start":4871},{"id":"blocker:references/schema.json:4945:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Files to mount into the preview pod at session start, stored as a\\nKubernetes `Secre","category":"blocker","line_end":4945,"severity":"low","line_start":4945},{"id":"blocker:references/schema.json:5160:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Redis host/hostname.\\nCan be sourced from an environment variable.\",","category":"blocker","line_end":5160,"severity":"low","line_start":5160},{"id":"blocker:references/schema.json:5491:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Targets a serverless remote workload, i.e. an application running outside Kubernetes","category":"blocker","line_end":5491,"severity":"low","line_start":5491},{"id":"blocker:references/schema.json:5601:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"One queue to split: which broker it is on, which of its messages reach the local app","category":"blocker","line_end":5601,"severity":"low","line_start":5601},{"id":"blocker:references/schema.json:5617:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"When this field is specified, for each message, the jq filter runs on a JSON\\nrepres","category":"blocker","line_end":5617,"severity":"low","line_start":5617},{"id":"blocker:references/schema.json:5663:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"One queue to split: which broker it is on, which of its messages reach the local app","category":"blocker","line_end":5663,"severity":"low","line_start":5663},{"id":"blocker:references/schema.json:5679:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"When this field is specified, for each message, the jq filter runs on a JSON\\nrepres","category":"blocker","line_end":5679,"severity":"low","line_start":5679},{"id":"blocker:references/schema.json:5708:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.split_queues.{}.queue_id {#feature-split_queues-queue_id-queue_id}\",","category":"blocker","line_end":5708,"severity":"low","line_start":5708},{"id":"blocker:references/schema.json:5709:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"The id of the queue to split, as it appears in the target's split configuration. Lis","category":"blocker","line_end":5709,"severity":"low","line_start":5709},{"id":"blocker:references/schema.json:6197:system-reconnaissance","file":"references/schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Operator represents a key's relationship to the value. Valid operators are Exists an","category":"blocker","line_end":6197,"severity":"low","line_start":6197},{"id":"blocker:SKILL.md:3:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"description: Helps users generate, edit, and validate mirrord.json configuration files for mirrord (","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"blocker:SKILL.md:14:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Generate** valid configs from natural language descriptions","category":"blocker","line_end":14,"severity":"low","line_start":14},{"id":"blocker:SKILL.md:16:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Fix** invalid configurations with explanations","category":"blocker","line_end":16,"severity":"low","line_start":16},{"id":"blocker:SKILL.md:79:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"`localwithoverrides` reads only `/etc/resolv.conf`, `/etc/hosts` and `/etc/hostname` remotely by def","category":"blocker","line_end":79,"severity":"low","line_start":79},{"id":"blocker:SKILL.md:95:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Create minimal valid config using only schema-defined keys","category":"blocker","line_end":95,"severity":"low","line_start":95},{"id":"blocker:SKILL.md:100:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Parse strictly (catch trailing commas, comments, invalid syntax)","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:SKILL.md:114:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. Valid JSON config in code block","category":"blocker","line_end":114,"severity":"low","line_start":114},{"id":"blocker:SKILL.md:127:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. **Warnings** (valid but potentially wrong behavior)","category":"blocker","line_end":127,"severity":"low","line_start":127},{"id":"blocker:SKILL.md:148:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Check schema for valid `incoming.mode` values (e.g., \"steal\", \"mirror\", \"off\")","category":"blocker","line_end":148,"severity":"low","line_start":148},{"id":"blocker:SKILL.md:154:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Templates must remain valid JSON","category":"blocker","line_end":154,"severity":"low","line_start":154},{"id":"blocker:SKILL.md:215:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"✓ **Valid JSON**: Always parseable, no comments","category":"blocker","line_end":215,"severity":"low","line_start":215},{"id":"blocker:SKILL.md:224:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**User provides invalid JSON with trailing comma**","category":"blocker","line_end":224,"severity":"low","line_start":224},{"id":"env_access:references/schema.json:4:configuration-library","file":"references/schema.json","pattern":"Configuration library","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"env_access","line_end":4,"severity":"low","line_start":4},{"id":"env_access:references/schema.json:585:configuration-library","file":"references/schema.json","pattern":"Configuration library","snippet":"\"description\": \"Enables prometheus metrics for the agent pod.\\n\\nYou might need to add annotations t","category":"env_access","line_end":585,"severity":"low","line_start":585},{"id":"network:references/schema.json:2:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:references/schema.json:4:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"mirrord allows for a high degree of customization when it comes to which features yo","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"network:references/schema.json:36:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"OpenTelemetry (OTel) / W3C baggage propagator. This is used in HTTP requests sent to","category":"network","line_end":36,"severity":"low","line_start":36},{"id":"network:references/schema.json:240:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls whether or not mirrord sends telemetry data to MetalBear cloud.\\nTelemetry ","category":"network","line_end":240,"severity":"low","line_start":240},{"id":"network:references/schema.json:248:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"OpenTelemetry (OTel) / W3C trace context. This is used in HTTP requests sent to the\\","category":"network","line_end":248,"severity":"low","line_start":248},{"id":"network:references/schema.json:266:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Allows the user to specify the default behavior for file operations:\\n\\n1. `\\\"read\\\"","category":"network","line_end":266,"severity":"low","line_start":266},{"id":"network:references/schema.json:283:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Specify map of patterns that if matched will replace the path according to specifica","category":"network","line_end":283,"severity":"low","line_start":283},{"id":"network:references/schema.json:447:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Runs the agent as an\\n[ephemeral container](https://kubernetes.io/docs/concepts/work","category":"network","line_end":447,"severity":"low","line_start":447},{"id":"network:references/schema.json:501:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls when a new agent image is downloaded.\\n\\nSupports `\\\"IfNotPresent\\\"`, `\\\"Al","category":"network","line_end":501,"severity":"low","line_start":501},{"id":"network:references/schema.json:509:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"List of secrets the agent pod has access to.\\n\\nTakes an array of entries with the f","category":"network","line_end":509,"severity":"low","line_start":509},{"id":"network:references/schema.json:763:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Tries to parse the body as a JSON object and find (a) matching subobjects(s).\\n\\n`qu","category":"network","line_end":763,"severity":"low","line_start":763},{"id":"network:references/schema.json:1208:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Allows the user to target a pod created dynamically from the original [`target`](#ta","category":"network","line_end":1208,"severity":"low","line_start":1208},{"id":"network:references/schema.json:1276:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"network","line_end":1276,"severity":"low","line_start":1276},{"id":"network:references/schema.json:2929:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Allows the user to set or override the local process' environment variables with the","category":"network","line_end":2929,"severity":"low","line_start":2929},{"id":"network:references/schema.json:3042:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Disables the `SO_REUSEADDR` socket option on sockets that mirrord steals/mirrors.\\nO","category":"network","line_end":3042,"severity":"low","line_start":3042},{"id":"network:references/schema.json:3074:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Ensures the standard fds (0-2) are open when the layer initializes, pointing any clo","category":"network","line_end":3074,"severity":"low","line_start":3074},{"id":"network:references/schema.json:3148:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"<https://github.com/metalbear-co/mirrord/issues/2421#issuecomment-2093200904>\",","category":"network","line_end":3148,"severity":"low","line_start":3148},{"id":"network:references/schema.json:3156:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Enables trusting any certificate on macOS, useful for <https://github.com/golang/go/","category":"network","line_end":3156,"severity":"low","line_start":3156},{"id":"network:references/schema.json:3241:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls mirrord features.\\n\\nSee the\\n[technical reference, Technical Reference](ht","category":"network","line_end":3241,"severity":"low","line_start":3241},{"id":"network:references/schema.json:3246:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Creates a new copy of the target. mirrord will use this copy instead of the original","category":"network","line_end":3246,"severity":"low","line_start":3246},{"id":"network:references/schema.json:3407:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Changes file operations behavior based on user configuration.\\n\\nSee the file operat","category":"network","line_end":3407,"severity":"low","line_start":3407},{"id":"network:references/schema.json:3560:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the\\n[`fancy-regex`](https://docs.rs/fancy-regex/lates","category":"network","line_end":3560,"severity":"low","line_start":3560},{"id":"network:references/schema.json:3576:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports standard [HTTP methods](https://developer.mozilla.org/en-US/docs/Web/HTTP/R","category":"network","line_end":3576,"severity":"low","line_start":3576},{"id":"network:references/schema.json:3584:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the\\n[`fancy-regex`](https://docs.rs/fancy-regex/lates","category":"network","line_end":3584,"severity":"low","line_start":3584},{"id":"network:references/schema.json:3739:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Consider removing when adding <https://github.com/metalbear-co/mirrord/issues/702>\",","category":"network","line_end":3739,"severity":"low","line_start":3739},{"id":"network:references/schema.json:3868:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls the incoming TCP traffic feature.\\n\\nSee the incoming [reference](https://m","category":"network","line_end":3868,"severity":"low","line_start":3868},{"id":"network:references/schema.json:3909:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the\\n[`fancy-regex`](https://docs.rs/fancy-regex/lates","category":"network","line_end":3909,"severity":"low","line_start":3909},{"id":"network:references/schema.json:3923:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Supports regexes validated by the\\n[`fancy-regex`](https://docs.rs/fancy-regex/lates","category":"network","line_end":3923,"severity":"low","line_start":3923},{"id":"network:references/schema.json:4350:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"A regex matched against each message attribute rendered as `<name>: <value>`. Suppor","category":"network","line_end":4350,"severity":"low","line_start":4350},{"id":"network:references/schema.json:4600:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Controls mirrord network operations.\\n\\nSee the network traffic [reference](https://","category":"network","line_end":4600,"severity":"low","line_start":4600},{"id":"network:references/schema.json:4648:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Tunnel outgoing network operations through mirrord.\\n\\nSee the outgoing [reference](","category":"network","line_end":4648,"severity":"low","line_start":4648},{"id":"network:references/schema.json:4689:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Connect to these unix streams remotely (and to all other paths locally).\\n\\nYou can ","category":"network","line_end":4689,"severity":"low","line_start":4689},{"id":"network:references/schema.json:5617:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"When this field is specified, for each message, the jq filter runs on a JSON\\nrepres","category":"network","line_end":5617,"severity":"low","line_start":5617},{"id":"network:references/schema.json:5679:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"When this field is specified, for each message, the jq filter runs on a JSON\\nrepres","category":"network","line_end":5679,"severity":"low","line_start":5679},{"id":"network:references/schema.json:5734:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Apply migrations with [Flyway](https://documentation.red-gate.com/flyway).\",","category":"network","line_end":5734,"severity":"low","line_start":5734},{"id":"network:references/schema.json:5769:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Apply migrations with [Liquibase](https://docs.liquibase.com).\",","category":"network","line_end":5769,"severity":"low","line_start":5769},{"id":"network:references/schema.json:6169:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Limits describes the maximum amount of compute resources allowed. More info: https:/","category":"network","line_end":6169,"severity":"low","line_start":6169},{"id":"network:references/schema.json:6176:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Requests describes the minimum amount of compute resources required. If Requests is ","category":"network","line_end":6176,"severity":"low","line_start":6176},{"id":"network:references/schema.json:6212:hardcoded-url","file":"references/schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Quantity is a fixed-point representation of a number. It provides convenient marshal","category":"network","line_end":6212,"severity":"low","line_start":6212},{"id":"network:SKILL.md:22:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Never** embed Homebrew tap install one-liners as mandatory steps; if the user needs the CLI, poi","category":"network","line_end":22,"severity":"low","line_start":22},{"id":"network:references/configuration.md:1272:python-http-libraries","file":"references/configuration.md","pattern":"Python HTTP libraries","snippet":"requests. Note that stealing HTTPS requests requires mirrord Operator support.","category":"network","line_end":1272,"severity":"low","line_start":1272},{"id":"network:references/configuration.md:1816:python-http-libraries","file":"references/configuration.md","pattern":"Python HTTP libraries","snippet":"doing any network requests. This is useful when the system sets a proxy","category":"network","line_end":1816,"severity":"low","line_start":1816},{"id":"network:references/schema.json:256:python-http-libraries","file":"references/schema.json","pattern":"Python HTTP libraries","snippet":"\"description\": \"When disabled, mirrord will remove `HTTP[S]_PROXY` env variables before\\ndoing any n","category":"network","line_end":256,"severity":"low","line_start":256},{"id":"network:references/schema.json:5857:python-http-libraries","file":"references/schema.json","pattern":"Python HTTP libraries","snippet":"\"description\": \"Controls how many times, and how often mirrord retries its initial Kubernetes API re","category":"network","line_end":5857,"severity":"low","line_start":5857},{"id":"filesystem:references/configuration.md:554:standard-device-file-access","file":"references/configuration.md","pattern":"Standard device file access","snippet":"Uses /dev/null for creating local fake files (should be better than using /tmp)","category":"filesystem","line_end":554,"severity":"low","line_start":554},{"id":"filesystem:references/schema.json:3074:standard-device-file-access","file":"references/schema.json","pattern":"Standard device file access","snippet":"\"description\": \"Ensures the standard fds (0-2) are open when the layer initializes, pointing any clo","category":"filesystem","line_end":3074,"severity":"low","line_start":3074},{"id":"filesystem:references/schema.json:3164:standard-device-file-access","file":"references/schema.json","pattern":"Standard device file access","snippet":"\"description\": \"Uses /dev/null for creating local fake files (should be better than using /tmp)\",","category":"filesystem","line_end":3164,"severity":"low","line_start":3164}],"finding_verdicts":[{"id":"sensitive:references/configuration.md:884:gcp-credentials-directory","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:266:gcp-credentials-directory","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:138:kubernetes-config-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:1646:kubernetes-config-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:4:kubernetes-config-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:130:kubernetes-config-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:1300:certificate-key-files","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:1308:certificate-key-files","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:1152:certificate-key-files","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:4171:certificate-key-files","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:1340:crypto-seed-private-key-mention","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:1355:crypto-seed-private-key-mention","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:4184:crypto-seed-private-key-mention","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:4197:crypto-seed-private-key-mention","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:4213:crypto-seed-private-key-mention","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:708:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:748:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:760:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:771:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:779:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:802:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/configuration.md:811:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:1560:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2933:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2941:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2953:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2965:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2973:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2984:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2995:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:3269:environment-file-access","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:SKILL.md:61:yarn-config-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"obfuscation:references/schema.json:2628:heuristic-extremely-long-line-2173-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:4945:heuristic-extremely-long-line-2207-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:317:heuristic-extremely-long-line-2227-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:4171:heuristic-extremely-long-line-2402-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:4871:heuristic-extremely-long-line-2405-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:6212:heuristic-extremely-long-line-2479-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:3521:heuristic-extremely-long-line-2856-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:5617:heuristic-extremely-long-line-2902-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:5679:heuristic-extremely-long-line-2902-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:266:heuristic-extremely-long-line-3907-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:1560:heuristic-extremely-long-line-5684-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:4:heuristic-extremely-long-line-6665-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/schema.json:1276:heuristic-extremely-long-line-9956-chars-likely-","reason":"The long line is a verbose JSON Schema description with escaped documentation and examples. It is readable schema content, not an encoded or hidden payload.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/schema.json:3609:aws-credential-environment-variables","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:1276:database-connection-strings","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:2246:database-connection-strings","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:2628:database-connection-strings","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:3663:gcp-credential-environment-variables","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:2552:generic-api-secret-keys","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:2586:generic-api-secret-keys","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:138:hidden-file-in-home-directory","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:1646:hidden-file-in-home-directory","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:4:hidden-file-in-home-directory","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:28:hidden-file-in-home-directory","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:130:hidden-file-in-home-directory","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:3139:hidden-file-in-home-directory","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:4239:hidden-file-in-home-directory","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:904:non-standard-device-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:910:non-standard-device-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:283:non-standard-device-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:913:path-traversal-sequence","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:283:path-traversal-sequence","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:2427:path-traversal-sequence","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:2586:path-traversal-sequence","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:1276:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:1484:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:1560:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:1720:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:1829:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2024:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2119:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2141:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2192:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2250:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2264:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2273:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2289:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2304:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2333:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2391:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2420:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2426:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2482:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2556:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:2585:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:3257:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5147:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5159:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5172:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5185:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5197:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5206:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5219:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5270:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5279:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5285:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5293:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5302:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5308:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/schema.json:5317:sqlite-database-file","reason":"The match is a configuration option, path example, or schema description that names sensitive material. It does not contain a credential or code that reads or exfiltrates one, so it is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:87:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:121:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:129:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:339:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:453:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:654:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:968:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:976:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:1025:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:1451:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:1477:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:463:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:585:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:1168:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:2848:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3179:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3241:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4247:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4600:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4648:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4703:hardcoded-ip-address","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:138:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:1646:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:4:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:28:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:130:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:3139:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:4239:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:5271:hidden-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:931:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:936:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:337:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:349:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:361:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:4231:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:75:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:79:node-js-fs-operations","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:4:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:28:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:110:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:122:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:130:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:138:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:154:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:162:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:174:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:182:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:194:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:206:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:256:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:266:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:271:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:283:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:305:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:317:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:328:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:338:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:350:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:374:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:379:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:425:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:447:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:463:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:471:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:489:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:501:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:509:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:520:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:538:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:546:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:557:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:585:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:601:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:609:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:620:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:628:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:636:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:644:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:668:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:676:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:686:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:697:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:713:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:720:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:763:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:800:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:805:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:815:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:877:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:939:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:959:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:963:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:974:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:981:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:997:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1000:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1005:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1012:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1035:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1112:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1117:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1128:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1144:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1152:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1160:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1168:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1177:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1208:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1276:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1279:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1308:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1329:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1338:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1365:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1394:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1401:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1426:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1276:shell-command-substitution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1560:shell-command-substitution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:5833:shell-command-substitution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:800:temp-directory-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:805:temp-directory-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1276:template-literal-with-command-substitution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:1560:template-literal-with-command-substitution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:5833:template-literal-with-command-substitution","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/configuration.md:1669:unix-shell-invocation","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/schema.json:162:unix-shell-invocation","reason":"The match is Markdown backticks or command syntax in documentation and examples. It does not show command execution or user-controlled command construction.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:3179:network-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:42:network-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:README.md:8:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:README.md:10:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:149:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:268:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:372:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:662:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:940:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:942:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1012:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1029:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1054:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1323:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1327:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1346:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1365:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1374:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/configuration.md:1505:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:4:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:9:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:463:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:501:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:609:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:763:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1160:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1276:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1301:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1387:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1496:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1560:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1613:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1732:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1841:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:1927:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2036:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2153:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2264:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2319:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2406:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2488:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2571:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:2848:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:3241:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:3290:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:3291:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:3292:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:3761:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:4086:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:4171:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:4205:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:4703:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:4871:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:4945:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5160:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5491:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5601:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5617:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5663:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5679:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5708:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:5709:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/schema.json:6197:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:3:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:14:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:16:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:79:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:95:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:100:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:114:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:127:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:148:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:154:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:215:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:224:system-reconnaissance","reason":"The phrase is ordinary documentation about configuration generation or validation, not reconnaissance code. No system or network discovery routine is present.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:4:configuration-library","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/schema.json:585:configuration-library","reason":"The match documents a configuration field or environment-variable name in the schema. No code reads secret values or sends them elsewhere, so this is a false positive.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:2:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:36:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:240:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:248:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:266:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:283:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:447:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:501:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:509:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:763:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:1208:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:1276:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:2929:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3042:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3074:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3148:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3156:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3241:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3246:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3407:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3560:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3576:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3584:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3739:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3868:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3909:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:3923:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4350:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4600:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4648:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:4689:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:5617:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:5679:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:5734:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:5769:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:6169:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:6176:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:6212:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:22:hardcoded-url","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:1272:python-http-libraries","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/configuration.md:1816:python-http-libraries","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:256:python-http-libraries","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"network:references/schema.json:5857:python-http-libraries","reason":"The match is a documented URL, IP example, or network option. It does not show a network request or data transfer implemented by the skill.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/configuration.md:554:standard-device-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:3074:standard-device-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/schema.json:3164:standard-device-file-access","reason":"The match is a documented path, regular expression, or filesystem option in documentation or schema. The skill contains no implementation that performs the flagged filesystem operation.","verdict":"false_positive","confidence":0.96}],"semantic_findings":[],"subject_marketplace_commit_sha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","subject_content_hash":"9d465ebbbfb678d7c786419557d62b66869d45d37b87d7f0bcf8c83f022fff71","subject_tree_hash":"cb6c84112a89d4137641ed2138eddcd06987466cc7cc4844565a9ab8eecdde54","subject_plugin_path":"skills/metalbear-co/mirrord-config","audit_payload_hash":"0d0d3d2695ab97c8d01531601f2a7b36","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","contentHash":"9d465ebbbfb678d7c786419557d62b66869d45d37b87d7f0bcf8c83f022fff71","treeHash":"cb6c84112a89d4137641ed2138eddcd06987466cc7cc4844565a9ab8eecdde54","pluginPath":"skills/metalbear-co/mirrord-config","auditPayloadHash":"0d0d3d2695ab97c8d01531601f2a7b36"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/metalbear-co-mirrord-config/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}