{"data":{"skill":{"slug":"metalbear-co-mirrord-db-branching","name":"mirrord-db-branching","icon":"📦","repo":"https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-db-branching","status":"approved","author":"metalbear-co","authorVersion":"2.7","skillstoreRevision":1},"audit":{"id":"b7ad38af-3bbb-4ba5-a851-ddb84a1bea71","skill_id":"a4c1ccf6-5d5a-483b-8179-db5ac0407e36","version":1,"content_hash":"v3:bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2:82cf6c37e84c2fb4f27afbf2ed63ca398b75cdc854cc0f4ee2628bc60b0a4d29:23c7139189cecd185b971fdcb55cbb9329b2e433ac9bb698f9872d5f3c3e350e:736b696c6c732f6d6574616c626561722d636f2f6d6972726f72642d64622d6272616e6368696e67:795bf770dac0b4fcc7c3de8d418f888c","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 400 presented static matches are false positives involving documentation, configuration references, or Kubernetes variable expansion. Two semantic risks remain: credential-bearing diagnostic output and a predictable administrator password in a generic branch example. The analyzer reports 59 additional matches outside this catalog; they still require manual review before automatic publication. Static review was capped at 400/459 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.","remediation":[{"issue":"Static review capped","severity":"medium","suggestion":"Manually review the omitted 59 static analyzer matches or reduce bundled generated/vendor/reference content before enabling automatic publication."},{"issue":"Troubleshooting prints credential-bearing environment values.","severity":"high","suggestion":"Replace the environment dump with variable-name inspection that never outputs values. Redact connection strings before any diagnostic output reaches logs or agent transcripts."},{"issue":"The generic InfluxDB example assigns a fixed administrator password.","severity":"medium","suggestion":"Replace the literal password with a Kubernetes Secret-backed parameter containing a unique credential. Restrict branch network access to authorized sessions."},{"issue":"The supplied catalog excludes 59 static matches.","severity":"medium","suggestion":"Complete manual adjudication of the remaining matches before automatic publication. Preserve the existing publication hold until that review finishes."}],"risk_factor_evidence":[{"factor":"env_access","evidence":[{"file":"README.md","line_end":62,"line_start":62},{"file":"references/db-branches-schema.json","line_end":1587,"line_start":1587},{"file":"references/db-branches-schema.json","line_end":1641,"line_start":1641},{"file":"references/db-branches-schema.json","line_end":203,"line_start":203},{"file":"references/db-branches-schema.json","line_end":969,"line_start":969},{"file":"references/db-branches-schema.json","line_end":1257,"line_start":1257},{"file":"references/troubleshooting.md","line_end":100,"line_start":100},{"file":"references/troubleshooting.md","line_end":101,"line_start":101},{"file":"references/troubleshooting.md","line_end":102,"line_start":102},{"file":"references/troubleshooting.md","line_end":62,"line_start":62},{"file":"references/troubleshooting.md","line_end":83,"line_start":83},{"file":"references/troubleshooting.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":414,"line_start":414},{"file":"SKILL.md","line_end":437,"line_start":437},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":200,"line_start":200},{"file":"SKILL.md","line_end":203,"line_start":203},{"file":"SKILL.md","line_end":216,"line_start":216},{"file":"SKILL.md","line_end":229,"line_start":229},{"file":"SKILL.md","line_end":231,"line_start":231},{"file":"SKILL.md","line_end":232,"line_start":232},{"file":"SKILL.md","line_end":234,"line_start":234},{"file":"SKILL.md","line_end":245,"line_start":245},{"file":"SKILL.md","line_end":260,"line_start":260},{"file":"SKILL.md","line_end":398,"line_start":398},{"file":"SKILL.md","line_end":451,"line_start":451},{"file":"SKILL.md","line_end":647,"line_start":647},{"file":"SKILL.md","line_end":660,"line_start":660},{"file":"SKILL.md","line_end":689,"line_start":689},{"file":"SKILL.md","line_end":755,"line_start":755},{"file":"SKILL.md","line_end":422,"line_start":422}]},{"factor":"external_commands","evidence":[{"file":"references/db-branches-schema.json","line_end":4,"line_start":4},{"file":"references/db-branches-schema.json","line_end":31,"line_start":31},{"file":"references/db-branches-schema.json","line_end":93,"line_start":93},{"file":"references/db-branches-schema.json","line_end":116,"line_start":116},{"file":"references/db-branches-schema.json","line_end":203,"line_start":203},{"file":"references/db-branches-schema.json","line_end":206,"line_start":206},{"file":"references/db-branches-schema.json","line_end":251,"line_start":242},{"file":"references/db-branches-schema.json","line_end":278,"line_start":251},{"file":"references/db-branches-schema.json","line_end":278,"line_start":278},{"file":"references/db-branches-schema.json","line_end":301,"line_start":301},{"file":"references/db-branches-schema.json","line_end":335,"line_start":326},{"file":"references/db-branches-schema.json","line_end":362,"line_start":335},{"file":"references/db-branches-schema.json","line_end":362,"line_start":362},{"file":"references/db-branches-schema.json","line_end":429,"line_start":390},{"file":"references/db-branches-schema.json","line_end":443,"line_start":429},{"file":"references/db-branches-schema.json","line_end":453,"line_start":443},{"file":"references/db-branches-schema.json","line_end":464,"line_start":453},{"file":"references/db-branches-schema.json","line_end":473,"line_start":464},{"file":"references/db-branches-schema.json","line_end":500,"line_start":473},{"file":"references/db-branches-schema.json","line_end":500,"line_start":500},{"file":"references/db-branches-schema.json","line_end":559,"line_start":541},{"file":"references/db-branches-schema.json","line_end":568,"line_start":559},{"file":"references/db-branches-schema.json","line_end":595,"line_start":568},{"file":"references/db-branches-schema.json","line_end":595,"line_start":595},{"file":"references/db-branches-schema.json","line_end":640,"line_start":631},{"file":"references/db-branches-schema.json","line_end":667,"line_start":640},{"file":"references/db-branches-schema.json","line_end":667,"line_start":667},{"file":"references/db-branches-schema.json","line_end":714,"line_start":696},{"file":"references/db-branches-schema.json","line_end":723,"line_start":714},{"file":"references/db-branches-schema.json","line_end":750,"line_start":723},{"file":"references/db-branches-schema.json","line_end":750,"line_start":750},{"file":"references/db-branches-schema.json","line_end":809,"line_start":791},{"file":"references/db-branches-schema.json","line_end":818,"line_start":809},{"file":"references/db-branches-schema.json","line_end":845,"line_start":818},{"file":"references/db-branches-schema.json","line_end":845,"line_start":845},{"file":"references/db-branches-schema.json","line_end":854,"line_start":854},{"file":"references/db-branches-schema.json","line_end":913,"line_start":894},{"file":"references/db-branches-schema.json","line_end":913,"line_start":913},{"file":"references/db-branches-schema.json","line_end":932,"line_start":923},{"file":"references/db-branches-schema.json","line_end":959,"line_start":932},{"file":"references/db-branches-schema.json","line_end":959,"line_start":959},{"file":"references/db-branches-schema.json","line_end":969,"line_start":969},{"file":"references/db-branches-schema.json","line_end":1012,"line_start":1012},{"file":"references/db-branches-schema.json","line_end":1049,"line_start":1049},{"file":"references/db-branches-schema.json","line_end":1070,"line_start":1061},{"file":"references/db-branches-schema.json","line_end":1096,"line_start":1070},{"file":"references/db-branches-schema.json","line_end":1096,"line_start":1096},{"file":"references/db-branches-schema.json","line_end":1119,"line_start":1119},{"file":"references/db-branches-schema.json","line_end":1147,"line_start":1138},{"file":"references/db-branches-schema.json","line_end":1174,"line_start":1147}]},{"factor":"network","evidence":[{"file":"references/db-branches-schema.json","line_end":2,"line_start":2},{"file":"references/db-branches-schema.json","line_end":4,"line_start":4},{"file":"references/db-branches-schema.json","line_end":203,"line_start":203},{"file":"references/db-branches-schema.json","line_end":2435,"line_start":2435},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":187,"line_start":187},{"file":"SKILL.md","line_end":230,"line_start":230},{"file":"SKILL.md","line_end":363,"line_start":363},{"file":"SKILL.md","line_end":502,"line_start":502},{"file":"SKILL.md","line_end":507,"line_start":507}]},{"factor":"filesystem","evidence":[{"file":"references/db-branches-schema.json","line_end":2234,"line_start":2234},{"file":"SKILL.md","line_end":118,"line_start":118},{"file":"SKILL.md","line_end":231,"line_start":231}]}],"critical_findings":[],"high_findings":[{"title":"Troubleshooting Can Expose Database Credentials","locations":[{"file":"references/troubleshooting.md","line_end":78,"line_start":74}],"confidence":0.98,"description":"The troubleshooting command runs `env | grep -iE 'database|postgres|mysql|redis|mongo'` through mirrord, printing matching values rather than names. Database URLs can contain credentials, which may enter terminal logs or an agent transcript without redaction.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The command directly prints matching environment entries without removing their values. Exposure depends on the target environment, but no output redaction is shown."}],"medium_findings":[{"title":"Predictable Administrator Password in Branch Example","locations":[{"file":"references/db-branches-schema.json","line_end":362,"line_start":362}],"confidence":0.97,"description":"The generic InfluxDB example sets DOCKER_INFLUXDB_INIT_USERNAME to admin and DOCKER_INFLUXDB_INIT_PASSWORD to mirrord-branch. Reusing this example creates a predictable administrator credential, allowing unauthorized access wherever the branch service is reachable.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The schema description explicitly supplies a fixed administrator username and password in an executable configuration example. Exploitability depends on network reachability and example reuse."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":3619,"audit_model":"codex","audited_at":"2026-09-29T21:35:48.738+00:00","created_at":"2026-09-30T13:38:34.372664+00:00","static_findings":[{"id":"sensitive:references/db-branches-schema.json:362:environment-file-access","file":"references/db-branches-schema.json","pattern":"Environment file access","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"sensitive","line_end":362,"severity":"high","line_start":362},{"id":"sensitive:SKILL.md:398:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"The Job automatically inherits the target container's `env`/`envFrom`, and the operator redirects th","category":"sensitive","line_end":398,"severity":"high","line_start":398},{"id":"obfuscation:references/db-branches-schema.json:203:heuristic-extremely-long-line-4126-chars-likely-","file":"references/db-branches-schema.json","pattern":"[HEURISTIC] Extremely long line (4126 chars) - likely obfuscated","snippet":"      \"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my","category":"obfuscation","line_end":203,"severity":"high","line_start":203},{"id":"obfuscation:references/db-branches-schema.json:362:heuristic-extremely-long-line-4874-chars-likely-","file":"references/db-branches-schema.json","pattern":"[HEURISTIC] Extremely long line (4874 chars) - likely obfuscated","snippet":"          \"description\": \"When branching a database, cache, or any other stateful service that mirro","category":"obfuscation","line_end":362,"severity":"high","line_start":362},{"id":"env_access:references/db-branches-schema.json:1587:aws-credential-environment-variables","file":"references/db-branches-schema.json","pattern":"AWS credential environment variables","snippet":"\"description\": \"For AWS RDS/Aurora IAM authentication, set `type` to `\\\"aws_rds\\\"`.\\n\\nExample:\\n```","category":"env_access","line_end":1587,"severity":"high","line_start":1587},{"id":"env_access:references/troubleshooting.md:100:aws-credential-environment-variables","file":"references/troubleshooting.md","pattern":"AWS credential environment variables","snippet":"- `AWS_ACCESS_KEY_ID`","category":"env_access","line_end":100,"severity":"high","line_start":100},{"id":"env_access:references/troubleshooting.md:101:aws-credential-environment-variables","file":"references/troubleshooting.md","pattern":"AWS credential environment variables","snippet":"- `AWS_SECRET_ACCESS_KEY`","category":"env_access","line_end":101,"severity":"high","line_start":101},{"id":"env_access:references/troubleshooting.md:102:aws-credential-environment-variables","file":"references/troubleshooting.md","pattern":"AWS credential environment variables","snippet":"- `AWS_SESSION_TOKEN` (if using temporary credentials)","category":"env_access","line_end":102,"severity":"high","line_start":102},{"id":"env_access:SKILL.md:414:aws-credential-environment-variables","file":"SKILL.md","pattern":"AWS credential environment variables","snippet":"Default env vars from the target pod: `AWS_REGION`/`AWS_DEFAULT_REGION`, `AWS_ACCESS_KEY_ID`, `AWS_S","category":"env_access","line_end":414,"severity":"high","line_start":414},{"id":"env_access:README.md:62:database-connection-strings","file":"README.md","pattern":"Database connection strings","snippet":"\"connection\": { \"url\": \"DATABASE_URL\" },","category":"env_access","line_end":62,"severity":"high","line_start":62},{"id":"env_access:references/db-branches-schema.json:203:database-connection-strings","file":"references/db-branches-schema.json","pattern":"Database connection strings","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"env_access","line_end":203,"severity":"high","line_start":203},{"id":"env_access:references/db-branches-schema.json:969:database-connection-strings","file":"references/db-branches-schema.json","pattern":"Database connection strings","snippet":"\"description\": \"Configuration for a local Redis branch.\\n\\nExample with URL-based connection:\\n```js","category":"env_access","line_end":969,"severity":"high","line_start":969},{"id":"env_access:references/db-branches-schema.json:1257:database-connection-strings","file":"references/db-branches-schema.json","pattern":"Database connection strings","snippet":"\"description\": \"Different ways of connecting to the source database.\\n\\nAccepts three formats:\\n\\nLe","category":"env_access","line_end":1257,"severity":"high","line_start":1257},{"id":"env_access:references/troubleshooting.md:62:database-connection-strings","file":"references/troubleshooting.md","pattern":"Database connection strings","snippet":"{ \"id\": \"my-stable-branch\", \"ttl_mins\": 15, \"type\": \"pg\", \"connection\": { \"url\": \"DATABASE_URL\" } }","category":"env_access","line_end":62,"severity":"high","line_start":62},{"id":"env_access:references/troubleshooting.md:83:database-connection-strings","file":"references/troubleshooting.md","pattern":"Database connection strings","snippet":"{ \"connection\": { \"url\": \"DATABASE_URL\" } }","category":"env_access","line_end":83,"severity":"high","line_start":83},{"id":"env_access:references/troubleshooting.md:170:database-connection-strings","file":"references/troubleshooting.md","pattern":"Database connection strings","snippet":"\"password\": { \"secret\": \"rds-credentials\", \"key\": \"password\", \"env_var_name\": \"DB_PASSWORD\" }","category":"env_access","line_end":170,"severity":"high","line_start":170},{"id":"env_access:SKILL.md:82:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"url\": \"DATABASE_URL\"","category":"env_access","line_end":82,"severity":"high","line_start":82},{"id":"env_access:SKILL.md:200:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"{ \"connection\": { \"url\": \"DATABASE_URL\" } }","category":"env_access","line_end":200,"severity":"high","line_start":200},{"id":"env_access:SKILL.md:203:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"Equivalent explicit forms (all valid): `{ \"url\": { \"type\": \"env\", \"variable\": \"DATABASE_URL\" } }` an","category":"env_access","line_end":203,"severity":"high","line_start":203},{"id":"env_access:SKILL.md:216:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"password\": \"DB_PASSWORD\",","category":"env_access","line_end":216,"severity":"high","line_start":216},{"id":"env_access:SKILL.md:229:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"- **Kubernetes Secret** (params only): `{ \"secret\": \"rds-credentials\", \"key\": \"password\", \"env_var_n","category":"env_access","line_end":229,"severity":"high","line_start":229},{"id":"env_access:SKILL.md:231:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"- **Google Secret Manager** (url or params; uses the target pod's GKE Workload Identity): url → `{ \"","category":"env_access","line_end":231,"severity":"high","line_start":231},{"id":"env_access:SKILL.md:232:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"- **AWS Secrets Manager** (url or params; uses the target pod's service account via IRSA / EKS Pod I","category":"env_access","line_end":232,"severity":"high","line_start":232},{"id":"env_access:SKILL.md:234:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"- **Literal value** (user-supplied only): `{ \"env_var_name\": \"DB_PASSWORD\", \"value\": \"...\" }` — stor","category":"env_access","line_end":234,"severity":"high","line_start":234},{"id":"env_access:SKILL.md:245:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"password\": { \"secret\": \"db-creds\", \"key\": \"password\", \"env_var_name\": \"DB_PASSWORD\" }","category":"env_access","line_end":245,"severity":"high","line_start":245},{"id":"env_access:SKILL.md:260:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"connection\": { \"url\": \"DATABASE_URL\" },","category":"env_access","line_end":260,"severity":"high","line_start":260},{"id":"env_access:SKILL.md:398:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"The Job automatically inherits the target container's `env`/`envFrom`, and the operator redirects th","category":"env_access","line_end":398,"severity":"high","line_start":398},{"id":"env_access:SKILL.md:451:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"connection\": { \"url\": \"REDIS_URL\" },","category":"env_access","line_end":451,"severity":"high","line_start":451},{"id":"env_access:SKILL.md:647:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"connection\": { \"url\": \"DATABASE_URL\" },","category":"env_access","line_end":647,"severity":"high","line_start":647},{"id":"env_access:SKILL.md:660:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"connection\": { \"url\": \"DATABASE_URL\" },","category":"env_access","line_end":660,"severity":"high","line_start":660},{"id":"env_access:SKILL.md:689:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"connection\": { \"url\": \"DATABASE_URL\" },","category":"env_access","line_end":689,"severity":"high","line_start":689},{"id":"env_access:SKILL.md:755:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"\"connection\": { \"url\": \"REDIS_URL\" },","category":"env_access","line_end":755,"severity":"high","line_start":755},{"id":"env_access:references/db-branches-schema.json:1641:gcp-credential-environment-variables","file":"references/db-branches-schema.json","pattern":"GCP credential environment variables","snippet":"\"description\": \"For GCP Cloud SQL IAM authentication, set `type` to `\\\"gcp_cloud_sql\\\"`.\\n\\nExample ","category":"env_access","line_end":1641,"severity":"high","line_start":1641},{"id":"env_access:SKILL.md:437:gcp-credential-environment-variables","file":"SKILL.md","pattern":"GCP credential environment variables","snippet":"Defaults: `credentials_path` ← `GOOGLE_APPLICATION_CREDENTIALS`; `project` ← `GOOGLE_CLOUD_PROJECT`/","category":"env_access","line_end":437,"severity":"high","line_start":437},{"id":"env_access:SKILL.md:422:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"\"secret_access_key\": { \"type\": \"env\", \"variable\": \"MY_SECRET_KEY\" }","category":"env_access","line_end":422,"severity":"high","line_start":422},{"id":"filesystem:SKILL.md:118:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| `name` | most | Source database name to clone. The override URL becomes `.../<name>`. If omitted, ","category":"filesystem","line_end":118,"severity":"high","line_start":118},{"id":"filesystem:SKILL.md:231:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Google Secret Manager** (url or params; uses the target pod's GKE Workload Identity): url → `{ \"","category":"filesystem","line_end":231,"severity":"high","line_start":231},{"id":"sensitive:README.md:8:sqlite-database-file","file":"README.md","pattern":"SQLite database file","snippet":"- **Generate** valid `feature.db_branches` configs for mirrord.json","category":"sensitive","line_end":8,"severity":"medium","line_start":8},{"id":"sensitive:references/db-branches-schema.json:4:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"description\": \"JSON Schema for the feature.db_branches configuration in mirrord.json. Extracted ver","category":"sensitive","line_end":4,"severity":"medium","line_start":4},{"id":"sensitive:references/db-branches-schema.json:203:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"sensitive","line_end":203,"severity":"medium","line_start":203},{"id":"sensitive:references/db-branches-schema.json:300:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: dynamodb) {#feature-db_branches-dynamodb-iam_auth}\",","category":"sensitive","line_end":300,"severity":"medium","line_start":300},{"id":"sensitive:references/db-branches-schema.json:362:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"sensitive","line_end":362,"severity":"medium","line_start":362},{"id":"sensitive:references/db-branches-schema.json:522:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: mariadb) {#feature-db_branches-mariadb-iam_auth}\",","category":"sensitive","line_end":522,"severity":"medium","line_start":522},{"id":"sensitive:references/db-branches-schema.json:772:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: mysql) {#feature-db_branches-mysql-iam_auth}\",","category":"sensitive","line_end":772,"severity":"medium","line_start":772},{"id":"sensitive:references/db-branches-schema.json:853:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection_settings (type: pg) {#feature-db_branches-pg-connection_s","category":"sensitive","line_end":853,"severity":"medium","line_start":853},{"id":"sensitive:references/db-branches-schema.json:875:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].iam_auth (type: pg) {#feature-db_branches-pg-iam_auth}\",","category":"sensitive","line_end":875,"severity":"medium","line_start":875},{"id":"sensitive:references/db-branches-schema.json:912:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].query_params (type: pg) {#feature-db_branches-pg-query_params}\",","category":"sensitive","line_end":912,"severity":"medium","line_start":912},{"id":"sensitive:references/db-branches-schema.json:913:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"description\": \"Query parameters set on the branch connection your application receives (not the\\nco","category":"sensitive","line_end":913,"severity":"medium","line_start":913},{"id":"sensitive:references/db-branches-schema.json:973:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection (type: redis) {#feature-db_branches-redis-connection}\",","category":"sensitive","line_end":973,"severity":"medium","line_start":973},{"id":"sensitive:references/db-branches-schema.json:987:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].id (type: redis) {#feature-db_branches-redis-id}\",","category":"sensitive","line_end":987,"severity":"medium","line_start":987},{"id":"sensitive:references/db-branches-schema.json:996:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local (type: redis) {#feature-db_branches-redis-local}\",","category":"sensitive","line_end":996,"severity":"medium","line_start":996},{"id":"sensitive:references/db-branches-schema.json:1012:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"description\": \"#### feature.db_branches[].location (type: redis) {#feature-db_branches-redis-locati","category":"sensitive","line_end":1012,"severity":"medium","line_start":1012},{"id":"sensitive:references/db-branches-schema.json:1027:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].copy (type: redis) {#feature-db_branches-redis-copy}\",","category":"sensitive","line_end":1027,"severity":"medium","line_start":1027},{"id":"sensitive:references/db-branches-schema.json:1049:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"description\": \"#### feature.db_branches[].location (type: redis) {#feature-db_branches-redis-locati","category":"sensitive","line_end":1049,"severity":"medium","line_start":1049},{"id":"sensitive:references/db-branches-schema.json:1118:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].emulator_host (type: spanner) {#feature-db_branches-spanner-emulator","category":"sensitive","line_end":1118,"severity":"medium","line_start":1118},{"id":"sensitive:references/db-branches-schema.json:1182:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].provider (type: s3) {#feature-db_branches-s3-provider}\",","category":"sensitive","line_end":1182,"severity":"medium","line_start":1182},{"id":"sensitive:references/db-branches-schema.json:1195:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].source (type: s3) {#feature-db_branches-s3-source}\",","category":"sensitive","line_end":1195,"severity":"medium","line_start":1195},{"id":"sensitive:references/db-branches-schema.json:2110:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.database (type: redis)\",","category":"sensitive","line_end":2110,"severity":"medium","line_start":2110},{"id":"sensitive:references/db-branches-schema.json:2122:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.host (type: redis)\",","category":"sensitive","line_end":2122,"severity":"medium","line_start":2122},{"id":"sensitive:references/db-branches-schema.json:2135:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.password (type: redis)\",","category":"sensitive","line_end":2135,"severity":"medium","line_start":2135},{"id":"sensitive:references/db-branches-schema.json:2148:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.port (type: redis)\",","category":"sensitive","line_end":2148,"severity":"medium","line_start":2148},{"id":"sensitive:references/db-branches-schema.json:2160:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.tls (type: redis)\",","category":"sensitive","line_end":2160,"severity":"medium","line_start":2160},{"id":"sensitive:references/db-branches-schema.json:2169:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.url (type: redis)\",","category":"sensitive","line_end":2169,"severity":"medium","line_start":2169},{"id":"sensitive:references/db-branches-schema.json:2182:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].connection.username (type: redis)\",","category":"sensitive","line_end":2182,"severity":"medium","line_start":2182},{"id":"sensitive:references/db-branches-schema.json:2233:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.container_command (type: redis)\",","category":"sensitive","line_end":2233,"severity":"medium","line_start":2233},{"id":"sensitive:references/db-branches-schema.json:2242:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.container_runtime (type: redis)\",","category":"sensitive","line_end":2242,"severity":"medium","line_start":2242},{"id":"sensitive:references/db-branches-schema.json:2248:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.options (type: redis)\",","category":"sensitive","line_end":2248,"severity":"medium","line_start":2248},{"id":"sensitive:references/db-branches-schema.json:2256:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.port (type: redis)\",","category":"sensitive","line_end":2256,"severity":"medium","line_start":2256},{"id":"sensitive:references/db-branches-schema.json:2265:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.runtime (type: redis)\",","category":"sensitive","line_end":2265,"severity":"medium","line_start":2265},{"id":"sensitive:references/db-branches-schema.json:2271:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.server_command (type: redis)\",","category":"sensitive","line_end":2271,"severity":"medium","line_start":2271},{"id":"sensitive:references/db-branches-schema.json:2280:sqlite-database-file","file":"references/db-branches-schema.json","pattern":"SQLite database file","snippet":"\"title\": \"feature.db_branches[].local.version (type: redis)\",","category":"sensitive","line_end":2280,"severity":"medium","line_start":2280},{"id":"sensitive:SKILL.md:46:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"- `references/db-branches-schema.json` — authoritative JSON Schema for `db_branches` (extracted from","category":"sensitive","line_end":46,"severity":"medium","line_start":46},{"id":"sensitive:SKILL.md:161:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"Since operator **3.194.0**, each branch (other than local Redis, which runs on your machine) gets it","category":"sensitive","line_end":161,"severity":"medium","line_start":161},{"id":"sensitive:SKILL.md:183:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"To keep an engine's branches on node-local storage instead, set `dbPod.storage.kind: \"emptyDir\"` — t","category":"sensitive","line_end":183,"severity":"medium","line_start":183},{"id":"sensitive:SKILL.md:187:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"Also cluster-admin Helm config, not a `db_branches` field: `pgBranchConfig.dbPod.dbServerArgs` is a ","category":"sensitive","line_end":187,"severity":"medium","line_start":187},{"id":"sensitive:SKILL.md:265:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"Cluster admins can set the same overrides for everyone via `pgBranchConfig.dbPod.queryParams` in the","category":"sensitive","line_end":265,"severity":"medium","line_start":265},{"id":"sensitive:SKILL.md:484:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"With `copy.mode: \"all\"`, the branch pod connects to the **source** Redis to read its keys. If the so","category":"sensitive","line_end":484,"severity":"medium","line_start":484},{"id":"filesystem:references/db-branches-schema.json:2234:hidden-file-access","file":"references/db-branches-schema.json","pattern":"Hidden file access","snippet":"\"description\": \"Custom path to the container command.\\nIf not provided, uses the runtime name from P","category":"filesystem","line_end":2234,"severity":"medium","line_start":2234},{"id":"external_commands:references/db-branches-schema.json:4:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"JSON Schema for the feature.db_branches configuration in mirrord.json. Extracted ver","category":"external_commands","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:references/db-branches-schema.json:31:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their ClickHouse branch d","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:references/db-branches-schema.json:93:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Connection parameters specified as individual environment variable names.\\nThe `type","category":"external_commands","line_end":93,"severity":"medium","line_start":93},{"id":"external_commands:references/db-branches-schema.json:116:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Individual database connection parameter sources.\\nAt least one parameter must be sp","category":"external_commands","line_end":116,"severity":"medium","line_start":116},{"id":"external_commands:references/db-branches-schema.json:203:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"external_commands","line_end":203,"severity":"medium","line_start":203},{"id":"external_commands:references/db-branches-schema.json:206:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for ClickHouse, set `type` to `clickhouse`.\",","category":"external_commands","line_end":206,"severity":"medium","line_start":206},{"id":"external_commands:references/db-branches-schema.json:242:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":251,"severity":"medium","line_start":242},{"id":"external_commands:references/db-branches-schema.json:251:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":278,"severity":"medium","line_start":251},{"id":"external_commands:references/db-branches-schema.json:278:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for DynamoDB, set `type` to `dynamodb`.\",","category":"external_commands","line_end":278,"severity":"medium","line_start":278},{"id":"external_commands:references/db-branches-schema.json:301:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"AWS IAM credentials used to read the source DynamoDB tables. DynamoDB has no\\npasswo","category":"external_commands","line_end":301,"severity":"medium","line_start":301},{"id":"external_commands:references/db-branches-schema.json:326:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":335,"severity":"medium","line_start":326},{"id":"external_commands:references/db-branches-schema.json:335:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":362,"severity":"medium","line_start":335},{"id":"external_commands:references/db-branches-schema.json:362:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"external_commands","line_end":362,"severity":"medium","line_start":362},{"id":"external_commands:references/db-branches-schema.json:390:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"One-shot Job that copies schema and data into the branch before it turns Ready. Only","category":"external_commands","line_end":429,"severity":"medium","line_start":390},{"id":"external_commands:references/db-branches-schema.json:429:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Full image reference for the branch container, including the tag. Required unless a\\","category":"external_commands","line_end":443,"severity":"medium","line_start":429},{"id":"external_commands:references/db-branches-schema.json:443:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"The port the branched service listens on. Required unless a `profile` supplies it.\",","category":"external_commands","line_end":453,"severity":"medium","line_start":443},{"id":"external_commands:references/db-branches-schema.json:453:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Readiness check for the branch container. Defaults to a TCP probe on `port`.\",","category":"external_commands","line_end":464,"severity":"medium","line_start":453},{"id":"external_commands:references/db-branches-schema.json:464:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":473,"severity":"medium","line_start":464},{"id":"external_commands:references/db-branches-schema.json:473:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":500,"severity":"medium","line_start":473},{"id":"external_commands:references/db-branches-schema.json:500:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for MariaDB, set `type` to `mariadb`.\\n\\nMariaDB branches ","category":"external_commands","line_end":500,"severity":"medium","line_start":500},{"id":"external_commands:references/db-branches-schema.json:541:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nDocumented on `DatabaseBranchConfig` (shared across SQL engines)","category":"external_commands","line_end":559,"severity":"medium","line_start":541},{"id":"external_commands:references/db-branches-schema.json:559:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":568,"severity":"medium","line_start":559},{"id":"external_commands:references/db-branches-schema.json:568:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":595,"severity":"medium","line_start":568},{"id":"external_commands:references/db-branches-schema.json:595:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for MongoDB, set `type` to `mongodb`.\",","category":"external_commands","line_end":595,"severity":"medium","line_start":595},{"id":"external_commands:references/db-branches-schema.json:631:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":640,"severity":"medium","line_start":631},{"id":"external_commands:references/db-branches-schema.json:640:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":667,"severity":"medium","line_start":640},{"id":"external_commands:references/db-branches-schema.json:667:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for MSSQL, set `type` to `mssql`.\",","category":"external_commands","line_end":667,"severity":"medium","line_start":667},{"id":"external_commands:references/db-branches-schema.json:696:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nDocumented on `DatabaseBranchConfig` (shared across SQL engines)","category":"external_commands","line_end":714,"severity":"medium","line_start":696},{"id":"external_commands:references/db-branches-schema.json:714:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":723,"severity":"medium","line_start":714},{"id":"external_commands:references/db-branches-schema.json:723:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":750,"severity":"medium","line_start":723},{"id":"external_commands:references/db-branches-schema.json:750:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for MySQL, set `type` to `mysql`.\",","category":"external_commands","line_end":750,"severity":"medium","line_start":750},{"id":"external_commands:references/db-branches-schema.json:791:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nDocumented on `DatabaseBranchConfig` (shared across SQL engines)","category":"external_commands","line_end":809,"severity":"medium","line_start":791},{"id":"external_commands:references/db-branches-schema.json:809:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":818,"severity":"medium","line_start":809},{"id":"external_commands:references/db-branches-schema.json:818:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":845,"severity":"medium","line_start":818},{"id":"external_commands:references/db-branches-schema.json:845:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for PostgreSQL, set `type` to `pg`.\",","category":"external_commands","line_end":845,"severity":"medium","line_start":845},{"id":"external_commands:references/db-branches-schema.json:854:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"PostgreSQL settings (GUCs) applied to every source connection mirrord opens while\\nb","category":"external_commands","line_end":854,"severity":"medium","line_start":854},{"id":"external_commands:references/db-branches-schema.json:894:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nDocumented on `DatabaseBranchConfig` (shared across SQL engines)","category":"external_commands","line_end":913,"severity":"medium","line_start":894},{"id":"external_commands:references/db-branches-schema.json:913:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Query parameters set on the branch connection your application receives (not the\\nco","category":"external_commands","line_end":913,"severity":"medium","line_start":913},{"id":"external_commands:references/db-branches-schema.json:923:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":932,"severity":"medium","line_start":923},{"id":"external_commands:references/db-branches-schema.json:932:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":959,"severity":"medium","line_start":932},{"id":"external_commands:references/db-branches-schema.json:959:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for Redis, set `type` to `redis`.\",","category":"external_commands","line_end":959,"severity":"medium","line_start":959},{"id":"external_commands:references/db-branches-schema.json:969:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Configuration for a local Redis branch.\\n\\nExample with URL-based connection:\\n```js","category":"external_commands","line_end":969,"severity":"medium","line_start":969},{"id":"external_commands:references/db-branches-schema.json:1012:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"#### feature.db_branches[].location (type: redis) {#feature-db_branches-redis-locati","category":"external_commands","line_end":1012,"severity":"medium","line_start":1012},{"id":"external_commands:references/db-branches-schema.json:1049:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"#### feature.db_branches[].location (type: redis) {#feature-db_branches-redis-locati","category":"external_commands","line_end":1049,"severity":"medium","line_start":1049},{"id":"external_commands:references/db-branches-schema.json:1061:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1070,"severity":"medium","line_start":1061},{"id":"external_commands:references/db-branches-schema.json:1070:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1096,"severity":"medium","line_start":1070},{"id":"external_commands:references/db-branches-schema.json:1096:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for Google Cloud Spanner, set `type` to `spanner`.\\n\\nThe ","category":"external_commands","line_end":1096,"severity":"medium","line_start":1096},{"id":"external_commands:references/db-branches-schema.json:1119:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"The *name* of the env var mirrord sets on your process to redirect it to the branch\\","category":"external_commands","line_end":1119,"severity":"medium","line_start":1119},{"id":"external_commands:references/db-branches-schema.json:1138:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1147,"severity":"medium","line_start":1138},{"id":"external_commands:references/db-branches-schema.json:1147:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1174,"severity":"medium","line_start":1147},{"id":"external_commands:references/db-branches-schema.json:1174:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"When configuring a branch for an Amazon S3 bucket, set `type` to `s3`.\\n\\nUnlike eve","category":"external_commands","line_end":1174,"severity":"medium","line_start":1174},{"id":"external_commands:references/db-branches-schema.json:1183:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Storage service hosting the branch bucket. Defaults to `\\\"AWS\\\"`, the only provider\\","category":"external_commands","line_end":1196,"severity":"medium","line_start":1183},{"id":"external_commands:references/db-branches-schema.json:1196:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How to locate the source bucket's name. `connection` is accepted as an alias. Takes ","category":"external_commands","line_end":1196,"severity":"medium","line_start":1196},{"id":"external_commands:references/db-branches-schema.json:1200:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Alias for `source`.\",","category":"external_commands","line_end":1224,"severity":"medium","line_start":1200},{"id":"external_commands:references/db-branches-schema.json:1224:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in minutes, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1233,"severity":"medium","line_start":1224},{"id":"external_commands:references/db-branches-schema.json:1233:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Branch TTL in seconds, counted from when the branch is last used. Mutually exclusive","category":"external_commands","line_end":1250,"severity":"medium","line_start":1233},{"id":"external_commands:references/db-branches-schema.json:1250:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"A list of configurations for database branches.\\n\\nUsing a connection URL:\\n```json\\","category":"external_commands","line_end":1250,"severity":"medium","line_start":1250},{"id":"external_commands:references/db-branches-schema.json:1257:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Different ways of connecting to the source database.\\n\\nAccepts three formats:\\n\\nLe","category":"external_commands","line_end":1257,"severity":"medium","line_start":1257},{"id":"external_commands:references/db-branches-schema.json:1299:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nDifferent ways to source the connection options.\\n\\nSupport:\\n- ","category":"external_commands","line_end":1299,"severity":"medium","line_start":1299},{"id":"external_commands:references/db-branches-schema.json:1358:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Name of the env var to set on the local process from the resolved\\nSecret value. Sam","category":"external_commands","line_end":1383,"severity":"medium","line_start":1358},{"id":"external_commands:references/db-branches-schema.json:1383:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Fetched from Google Secret Manager by the branch init container using the\\ntarget po","category":"external_commands","line_end":1407,"severity":"medium","line_start":1383},{"id":"external_commands:references/db-branches-schema.json:1407:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Fetched from AWS Secrets Manager by the branch init container using the target pod's","category":"external_commands","line_end":1407,"severity":"medium","line_start":1407},{"id":"external_commands:references/db-branches-schema.json:1433:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their DynamoDB branch dat","category":"external_commands","line_end":1483,"severity":"medium","line_start":1433},{"id":"external_commands:references/db-branches-schema.json:1483:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nOne-shot Job that copies schema and data into an empty generic b","category":"external_commands","line_end":1487,"severity":"medium","line_start":1483},{"id":"external_commands:references/db-branches-schema.json:1487:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Full image reference for the copy Job container, including the tag. Goes through the","category":"external_commands","line_end":1491,"severity":"medium","line_start":1487},{"id":"external_commands:references/db-branches-schema.json:1491:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Entrypoint command override for the copy container. Values may reference the same\\n`","category":"external_commands","line_end":1491,"severity":"medium","line_start":1491},{"id":"external_commands:references/db-branches-schema.json:1517:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nReadiness check for a generic branch container. Documented on [`","category":"external_commands","line_end":1520,"severity":"medium","line_start":1517},{"id":"external_commands:references/db-branches-schema.json:1520:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"TCP probe on the branch `port` (the default when `readiness` is not set).\",","category":"external_commands","line_end":1520,"severity":"medium","line_start":1520},{"id":"external_commands:references/db-branches-schema.json:1555:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"HTTP GET probe; ready on a 2xx/3xx response. `port` defaults to the branch `port`.\",","category":"external_commands","line_end":1555,"severity":"medium","line_start":1555},{"id":"external_commands:references/db-branches-schema.json:1584:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"IAM authentication for the source database.\\nUse this when your source database (AWS","category":"external_commands","line_end":1584,"severity":"medium","line_start":1584},{"id":"external_commands:references/db-branches-schema.json:1587:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"For AWS RDS/Aurora IAM authentication, set `type` to `\\\"aws_rds\\\"`.\\n\\nExample:\\n```","category":"external_commands","line_end":1587,"severity":"medium","line_start":1587},{"id":"external_commands:references/db-branches-schema.json:1641:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"For GCP Cloud SQL IAM authentication, set `type` to `\\\"gcp_cloud_sql\\\"`.\\n\\nExample ","category":"external_commands","line_end":1641,"severity":"medium","line_start":1641},{"id":"external_commands:references/db-branches-schema.json:1687:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their MariaDB branch data","category":"external_commands","line_end":1687,"severity":"medium","line_start":1687},{"id":"external_commands:references/db-branches-schema.json:1776:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their MongoDB branch data","category":"external_commands","line_end":1826,"severity":"medium","line_start":1776},{"id":"external_commands:references/db-branches-schema.json:1826:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their MSSQL branch databa","category":"external_commands","line_end":1888,"severity":"medium","line_start":1826},{"id":"external_commands:references/db-branches-schema.json:1888:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their MySQL branch databa","category":"external_commands","line_end":1888,"severity":"medium","line_start":1888},{"id":"external_commands:references/db-branches-schema.json:1977:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Users can choose from the following copy mode to bootstrap their PostgreSQL branch d","category":"external_commands","line_end":1977,"severity":"medium","line_start":1977},{"id":"external_commands:references/db-branches-schema.json:2066:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How a Redis branch is seeded from its source.\\n\\n- `empty` (default): Start a fresh,","category":"external_commands","line_end":2066,"severity":"medium","line_start":2066},{"id":"external_commands:references/db-branches-schema.json:2106:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Supports either a complete URL or separated connection parameters.\\nIf both are prov","category":"external_commands","line_end":2106,"severity":"medium","line_start":2106},{"id":"external_commands:references/db-branches-schema.json:2170:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Complete Redis URL (e.g., `redis://user:pass@host:6379/0`).\\nCan be sourced from an ","category":"external_commands","line_end":2234,"severity":"medium","line_start":2170},{"id":"external_commands:references/db-branches-schema.json:2234:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Custom path to the container command.\\nIf not provided, uses the runtime name from P","category":"external_commands","line_end":2234,"severity":"medium","line_start":2234},{"id":"external_commands:references/db-branches-schema.json:2243:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Which container runtime to use (Docker, Podman, or nerdctl).\\nOnly applies when `run","category":"external_commands","line_end":2243,"severity":"medium","line_start":2243},{"id":"external_commands:references/db-branches-schema.json:2266:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Runtime backend for local Redis: `container`, `redis_server`, or `auto`.\",","category":"external_commands","line_end":2266,"severity":"medium","line_start":2266},{"id":"external_commands:references/db-branches-schema.json:2272:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Custom path to the redis-server binary.\\nIf not provided, uses \\\"redis-server\\\" from","category":"external_commands","line_end":2289,"severity":"medium","line_start":2272},{"id":"external_commands:references/db-branches-schema.json:2289:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Example:\\n```json\\n{\\n  \\\"args\\\": [\\\"--maxmemory\\\", \\\"256mb\\\", \\\"--appendonly\\\", \\\"y","category":"external_commands","line_end":2289,"severity":"medium","line_start":2289},{"id":"external_commands:references/db-branches-schema.json:2304:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"For container-based runtimes, mirrord spawns the Redis image in a container.\\nFor `r","category":"external_commands","line_end":2304,"severity":"medium","line_start":2304},{"id":"external_commands:references/db-branches-schema.json:2324:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"How an S3 branch bucket is seeded from its source:\\n\\n- `empty` (default): clone the","category":"external_commands","line_end":2324,"severity":"medium","line_start":2324},{"id":"external_commands:references/db-branches-schema.json:2432:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"<!--${internal}-->\\nRuns schema migrations on a SQL branch. Documented on [`Database","category":"external_commands","line_end":2461,"severity":"medium","line_start":2432},{"id":"external_commands:references/db-branches-schema.json:2461:ruby-shell-backtick-execution","file":"references/db-branches-schema.json","pattern":"Ruby/shell backtick execution","snippet":"\"description\": \"Run your own image as the migration Job. The Job inherits the target container's\\n`e","category":"external_commands","line_end":2461,"severity":"medium","line_start":2461},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Generate and validate `mirrord.json` configurations for database branching:","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Generate** valid `db_branches` configs from natural language descriptions","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **No hardcoded credentials:** Never put actual credentials, passwords, connection strings, or secr","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **IAM credentials:** Prefer standard credential discovery (the target pod's existing env vars / se","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read the reference files from this skill's `references/` directory:","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/db-branches-schema.json` — authoritative JSON Schema for `db_branches` (extracted from","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/troubleshooting.md` — common issues and solutions","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If using absolute paths, search for the schema using patterns like `**/mirrord-db-branching/referenc","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Each engine has minimum operator, mirrord CLI, and Helm chart versions, and a per-engine Helm value ","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":64,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":68,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`db_branches` is an array **under the top-level `feature` object**:","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":91,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":93,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **Common mistake:** placing `db_branches` at the top level. It must be nested inside `feature`.","category":"external_commands","line_end":93,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Database | `type` | Branch location | Copy modes | Notes |","category":"external_commands","line_end":99,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| MySQL | `\"mysql\"` | Remote | empty, schema, all, filtered | IAM auth, migrations, `dump_args` |","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| MariaDB | `\"mariadb\"` | Remote | empty, schema, all, filtered | IAM auth, migrations |","category":"external_commands","line_end":101,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| PostgreSQL | `\"pg\"` | Remote | empty, schema, all, filtered | IAM auth, migrations, `dump_args`, `","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| MSSQL | `\"mssql\"` | Remote | empty, schema, all, filtered | migrations (no `dump_args`) |","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| MongoDB | `\"mongodb\"` | Remote | empty, all, collection filters | schema-less (no `schema` mode) |","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Redis | `\"redis\"` | Remote **or** local | empty, all, `patterns` | `name` = DB **index** |","category":"external_commands","line_end":104,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| DynamoDB | `\"dynamodb\"` | Remote (local emulator pod) | empty, all, table filters | `iam_auth` **r","category":"external_commands","line_end":105,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| ClickHouse | `\"clickhouse\"` | Remote | empty, schema, all, filtered | |","category":"external_commands","line_end":107,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Google Spanner | `\"spanner\"` | Remote (emulator pod) | empty, schema, all, filtered | uses `SPANNE","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Amazon S3 | `\"s3\"` | Remote (provider — your AWS account) | empty, all, `objects` regex | Not a po","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Generic | `\"generic\"` | Remote | none (always empty) | any service, your own image |","category":"external_commands","line_end":115,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `type` | all | Database engine (see table above). |","category":"external_commands","line_end":116,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `connection` | all (optional for DynamoDB) | How mirrord locates the source connection details. Se","category":"external_commands","line_end":117,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `id` | all | Reuse/share a branch: same `id` reattaches to an existing branch while its TTL hasn't","category":"external_commands","line_end":117,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `name` | most | Source database name to clone. The override URL becomes `.../<name>`. If omitted, ","category":"external_commands","line_end":118,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `version` | all except generic, s3 | Engine image version (e.g. `\"8.0\"`, `\"16\"`). For generic, the","category":"external_commands","line_end":119,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `provider` | s3 | Storage service hosting the branch bucket. Only `\"AWS\"` (default). |","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `source` | s3 | Where to read the source bucket's name from (`connection` is accepted as an alias)","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ttl_secs` / `ttl_mins` | all | Branch time-to-live, counted from when no session is using it. Def","category":"external_commands","line_end":122,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `creation_timeout_secs` | all | How long to wait for the branch to become ready. Default 60. Unrec","category":"external_commands","line_end":123,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `copy` | all except generic | How the branch is cloned. See [Copy Modes](#copy-modes). |","category":"external_commands","line_end":125,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `iam_auth` | mysql, mariadb, pg, dynamodb | IAM auth for AWS RDS / GCP Cloud SQL. See [IAM Authent","category":"external_commands","line_end":126,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `migrations` | mysql, mariadb, pg, mssql | Run schema migrations on the branch at creation. See [S","category":"external_commands","line_end":127,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `connection_settings` | pg | PostgreSQL session settings applied while reading the source (e.g. fo","category":"external_commands","line_end":128,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `query_params` | pg | Query parameters on the **branch** connection the app receives (e.g. `sslmod","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `emulator_host` | spanner | Name of the env var mirrord sets to the emulator address (default `SPA","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `location` | redis | `\"remote\"` (default) or `\"local\"`. |","category":"external_commands","line_end":130,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `local` | redis | Local Redis runtime config (see [Redis](#redis)). |","category":"external_commands","line_end":132,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `image` / `port` / `command` / `args` / `env` / `readiness` / `copy` / `profile` | generic | See [","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| MySQL | 3.129.0 | 3.160.0 | 1.37.0 | `operator.mysqlBranching: true` |","category":"external_commands","line_end":141,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| PostgreSQL | 3.131.0 | 3.175.0 | 1.40.2 | `operator.pgBranching: true` |","category":"external_commands","line_end":142,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| MSSQL | 3.150.0 | 3.195.0 | 1.57.0 | `operator.mssqlBranching: true` |","category":"external_commands","line_end":143,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| MongoDB | 3.137.0 | 3.183.0 | 1.44.0 | `operator.mongoBranching: true` |","category":"external_commands","line_end":144,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Redis (remote) | 3.168.0 | 3.217.0 | 3.168.0 | `operator.redisBranching: true` |","category":"external_commands","line_end":146,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| DynamoDB | 3.179.0 | 3.228.0 | 3.179.0 | `operator.dynamodbBranching: true` |","category":"external_commands","line_end":147,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| ClickHouse | 3.182.0 | 3.230.0 | 3.182.0 | `operator.clickhouseBranching: true` |","category":"external_commands","line_end":148,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Google Spanner | 3.182.0 | 3.230.0 | 3.182.0 | `operator.spannerBranching: true` |","category":"external_commands","line_end":149,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Amazon S3 | 3.208.0 | 3.252.0 | 3.208.0 | `operator.s3Branching: true` |","category":"external_commands","line_end":150,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Generic | 3.183.0 | 3.232.0 | 3.183.0 | `operator.genericBranching: true` |","category":"external_commands","line_end":152,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Schema migrations: inherited target env (`container` flavor) | 3.191.0 | 3.238.0 | 3.191.0 | (per ","category":"external_commands","line_end":153,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Schema migrations: Liquibase (`liquibase` flavor) | 3.207.0 | 3.257.0 | 3.207.0 | (per engine abov","category":"external_commands","line_end":154,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Branch query params (`query_params`, pg only) | 3.197.0 | 3.250.0 | 3.197.0 | `operator.pgBranchin","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"This is cluster-admin Helm config, not something a `db_branches` config author sets — mention it whe","category":"external_commands","line_end":161,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Since operator **3.194.0**, each branch (other than local Redis, which runs on your machine) gets it","category":"external_commands","line_end":161,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":181,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":183,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"To keep an engine's branches on node-local storage instead, set `dbPod.storage.kind: \"emptyDir\"` — t","category":"external_commands","line_end":183,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Also cluster-admin Helm config, not a `db_branches` field: `pgBranchConfig.dbPod.dbServerArgs` is a ","category":"external_commands","line_end":187,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`connection` describes where mirrord reads the source connection details. The optional `type` contro","category":"external_commands","line_end":191,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"env\"` (default): a direct `env` entry in the target pod spec.","category":"external_commands","line_end":192,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `\"env_from\"`: from the pod's `envFrom` (`secretRef` / `configMapRef`).","category":"external_commands","line_end":193,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":201,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":203,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Equivalent explicit forms (all valid): `{ \"url\": { \"type\": \"env\", \"variable\": \"DATABASE_URL\" } }` an","category":"external_commands","line_end":203,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":221,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":223,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Each param is individually optional; mirrord fills engine defaults for any not specified. Defaults —","category":"external_commands","line_end":223,"severity":"medium","line_start":223},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Any param (and, where noted, the `url`) can be sourced beyond a plain env var:","category":"external_commands","line_end":229,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Kubernetes Secret** (params only): `{ \"secret\": \"rds-credentials\", \"key\": \"password\", \"env_var_n","category":"external_commands","line_end":230,"severity":"medium","line_start":229},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **ConfigMap** (params only): read a value out of a config file mounted from a ConfigMap, instead o","category":"external_commands","line_end":230,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Google Secret Manager** (url or params; uses the target pod's GKE Workload Identity): url → `{ \"","category":"external_commands","line_end":231,"severity":"medium","line_start":231},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **AWS Secrets Manager** (url or params; uses the target pod's service account via IRSA / EKS Pod I","category":"external_commands","line_end":232,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `env_var_name` is normally optional on these three sources, but becomes **required** when the conn","category":"external_commands","line_end":233,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Literal value** (user-supplied only): `{ \"env_var_name\": \"DB_PASSWORD\", \"value\": \"...\" }` — stor","category":"external_commands","line_end":235,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Composite env var** (`value_pattern`): extract one part of a packed value, e.g. `host` and `port","category":"external_commands","line_end":235,"severity":"medium","line_start":235},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Multiple sources** (array): both `url` and each param accept an array. The **first** entry is us","category":"external_commands","line_end":237,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Custom params**: beyond the fixed slots, `params` accepts any key an engine needs — Google Spann","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":249,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":253,"severity":"medium","line_start":249},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The connection the app receives points at the **branch** pod, not the source, so its query parameter","category":"external_commands","line_end":253,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"To override the automatic values or add other driver parameters, set `query_params` on the branch co","category":"external_commands","line_end":255,"severity":"medium","line_start":255},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":263,"severity":"medium","line_start":257},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":265,"severity":"medium","line_start":263},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Cluster admins can set the same overrides for everyone via `pgBranchConfig.dbPod.queryParams` in the","category":"external_commands","line_end":265,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`query_params` only affects the branch connection; the copy connection to the source keeps the sourc","category":"external_commands","line_end":267,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`copy.mode` controls what is cloned. Default is `\"empty\"`.","category":"external_commands","line_end":271,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `\"empty\"` (default) | Nothing — empty DB | For apps that run migrations / init schema on startup |","category":"external_commands","line_end":276,"severity":"medium","line_start":275},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `\"schema\"` | Table structures only, no data | Not available for MongoDB, Redis, DynamoDB |","category":"external_commands","line_end":277,"severity":"medium","line_start":276},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `\"all\"` | Schema **and** all data | **Small DBs only** — large copies are slow and storage-heavy |","category":"external_commands","line_end":281,"severity":"medium","line_start":277},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Copy schema plus filtered rows per table. Combine with `\"empty\"` to copy **only** the listed tables.","category":"external_commands","line_end":281,"severity":"medium","line_start":281},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":293,"severity":"medium","line_start":283},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":295,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### MongoDB / DynamoDB — `collections`","category":"external_commands","line_end":297,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"MongoDB and DynamoDB use `collections` instead of `tables` and support only `empty` / `all`.","category":"external_commands","line_end":297,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- MongoDB filter is a MongoDB query as an escaped JSON string: `\"{\\\"name\\\": {\\\"$in\\\": [\\\"alice\\\", \\\"","category":"external_commands","line_end":299,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- DynamoDB filter is a `Scan` `FilterExpression` string, e.g. `\"active = true\"`. It **cannot** use `","category":"external_commands","line_end":299,"severity":"medium","line_start":299},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":303,"severity":"medium","line_start":301},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":305,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"With `\"empty\"` + filters, only the listed collections/tables are created.","category":"external_commands","line_end":307,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Redis — `patterns`","category":"external_commands","line_end":309,"severity":"medium","line_start":307},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Redis supports `empty` / `all` (remote only; local always starts empty). Narrow `all` with `SCAN MAT","category":"external_commands","line_end":309,"severity":"medium","line_start":309},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":313,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":315,"severity":"medium","line_start":313},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Custom dump arguments (`dump_args`) — MySQL & PostgreSQL only","category":"external_commands","line_end":317,"severity":"medium","line_start":315},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Customize `mysqldump` / `pg_dump`. Available in all copy modes. **MSSQL, MongoDB, ClickHouse do not ","category":"external_commands","line_end":317,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- MySQL: default passes no args (tool uses its `--opt` defaults). Listed args are passed as-is; `[]`","category":"external_commands","line_end":318,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- PostgreSQL: setting `dump_args` **replaces** defaults entirely (defaults are `--no-owner --no-acl`","category":"external_commands","line_end":319,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":323,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":327,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`migrations` runs your schema migrations against the branch at creation, before it becomes ready — s","category":"external_commands","line_end":327,"severity":"medium","line_start":327},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`flavor` selects what the Job runs: `\"flyway\"` for versioned SQL files run through Flyway, `\"liquiba","category":"external_commands","line_end":329,"severity":"medium","line_start":329},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`\"copy\": { \"mode\": \"schema\" }` copies table definitions only, not rows — including the table (or tab","category":"external_commands","line_end":331,"severity":"medium","line_start":331},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":335,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":339,"severity":"medium","line_start":335},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":341,"severity":"medium","line_start":339},{"id":"external_commands:SKILL.md:341:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":345,"severity":"medium","line_start":341},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":353,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":355,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `path`: local directory of migration files, relative to the working directory. Mutually exclusive ","category":"external_commands","line_end":355,"severity":"medium","line_start":355},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `locations`: Flyway locations inside `image` holding the migration files, for images with the SQL ","category":"external_commands","line_end":356,"severity":"medium","line_start":356},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `image`: optional runner image override (default `flyway/flyway:12`; required with `locations`).","category":"external_commands","line_end":357,"severity":"medium","line_start":357},{"id":"external_commands:SKILL.md:359:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Exactly one of `path` or `locations` is required.","category":"external_commands","line_end":359,"severity":"medium","line_start":359},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Runs [Liquibase](https://docs.liquibase.com) changelogs (XML, YAML, JSON, or formatted SQL). Liquiba","category":"external_commands","line_end":363,"severity":"medium","line_start":363},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":373,"severity":"medium","line_start":365},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":375,"severity":"medium","line_start":373},{"id":"external_commands:SKILL.md:375:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `changelog_file`: root changelog file, resolved inside the search root. Recorded in `DATABASECHANG","category":"external_commands","line_end":375,"severity":"medium","line_start":375},{"id":"external_commands:SKILL.md:376:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `path`: local directory of changelog files, relative to the working directory. Mutually exclusive ","category":"external_commands","line_end":376,"severity":"medium","line_start":376},{"id":"external_commands:SKILL.md:377:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `search_path`: Liquibase search path inside `image`, joined into `LIQUIBASE_SEARCH_PATH`. Mutually","category":"external_commands","line_end":377,"severity":"medium","line_start":377},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `image`: optional runner image override (default `liquibase/liquibase:4.33`; required with `search","category":"external_commands","line_end":378,"severity":"medium","line_start":378},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Exactly one of `path` or `search_path` is required.","category":"external_commands","line_end":380,"severity":"medium","line_start":380},{"id":"external_commands:SKILL.md:384:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":392,"severity":"medium","line_start":384},{"id":"external_commands:SKILL.md:392:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":394,"severity":"medium","line_start":392},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `image`: full image reference for the migration container, including the tag.","category":"external_commands","line_end":395,"severity":"medium","line_start":394},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `command` / `args`: optional entrypoint override; when unset the image's own entrypoint runs.","category":"external_commands","line_end":395,"severity":"medium","line_start":395},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `env`: optional extra env vars; entries override inherited values of the same name.","category":"external_commands","line_end":398,"severity":"medium","line_start":396},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The Job automatically inherits the target container's `env`/`envFrom`, and the operator redirects th","category":"external_commands","line_end":398,"severity":"medium","line_start":398},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Authenticate to the **source** database with IAM instead of a password. Credentials are read from th","category":"external_commands","line_end":402,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:406:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"IAM only authenticates against the **real** cloud database — the branch is a plain database pod the ","category":"external_commands","line_end":406,"severity":"medium","line_start":406},{"id":"external_commands:SKILL.md:410:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":412,"severity":"medium","line_start":410},{"id":"external_commands:SKILL.md:412:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":414,"severity":"medium","line_start":412},{"id":"external_commands:SKILL.md:414:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Default env vars from the target pod: `AWS_REGION`/`AWS_DEFAULT_REGION`, `AWS_ACCESS_KEY_ID`, `AWS_S","category":"external_commands","line_end":414,"severity":"medium","line_start":414},{"id":"external_commands:SKILL.md:416:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":425,"severity":"medium","line_start":416},{"id":"external_commands:SKILL.md:425:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":427,"severity":"medium","line_start":425},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> DynamoDB reuses the `aws_rds` type name: `{ \"iam_auth\": { \"type\": \"aws_rds\" } }`.","category":"external_commands","line_end":427,"severity":"medium","line_start":427},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Requires TLS** — the connection URL must include `sslmode=require`. This only applies to the **sou","category":"external_commands","line_end":431,"severity":"medium","line_start":431},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":435,"severity":"medium","line_start":433},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":437,"severity":"medium","line_start":435},{"id":"external_commands:SKILL.md:437:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Defaults: `credentials_path` ← `GOOGLE_APPLICATION_CREDENTIALS`; `project` ← `GOOGLE_CLOUD_PROJECT`/","category":"external_commands","line_end":437,"severity":"medium","line_start":437},{"id":"external_commands:SKILL.md:439:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Google **Spanner** does not use `iam_auth`. It authenticates as the target pod's own Google identi","category":"external_commands","line_end":439,"severity":"medium","line_start":439},{"id":"external_commands:SKILL.md:447:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":455,"severity":"medium","line_start":447},{"id":"external_commands:SKILL.md:455:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":457,"severity":"medium","line_start":455},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`name` is the numeric DB **index** (default `0`).","category":"external_commands","line_end":457,"severity":"medium","line_start":457},{"id":"external_commands:SKILL.md:461:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Spawns a Redis instance on your machine and redirects the app's Redis traffic to it. Always starts e","category":"external_commands","line_end":463,"severity":"medium","line_start":461},{"id":"external_commands:SKILL.md:463:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":476,"severity":"medium","line_start":463},{"id":"external_commands:SKILL.md:476:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":478,"severity":"medium","line_start":476},{"id":"external_commands:SKILL.md:478:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `local.runtime`: `\"container\"` (default), `\"redis_server\"`, or `\"auto\"`.","category":"external_commands","line_end":478,"severity":"medium","line_start":478},{"id":"external_commands:SKILL.md:479:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `local.container_runtime`: `\"docker\"` (default), `\"podman\"`, or `\"nerdctl\"`.","category":"external_commands","line_end":479,"severity":"medium","line_start":479},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `local.port`: sessions on the same port share one local Redis DB; a new session on that port repla","category":"external_commands","line_end":484,"severity":"medium","line_start":480},{"id":"external_commands:SKILL.md:484:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"With `copy.mode: \"all\"`, the branch pod connects to the **source** Redis to read its keys. If the so","category":"external_commands","line_end":484,"severity":"medium","line_start":484},{"id":"external_commands:SKILL.md:488:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Unlike every other engine, an S3 branch is **not a pod**: the operator has the storage provider crea","category":"external_commands","line_end":490,"severity":"medium","line_start":488},{"id":"external_commands:SKILL.md:490:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":500,"severity":"medium","line_start":490},{"id":"external_commands:SKILL.md:500:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":502,"severity":"medium","line_start":500},{"id":"external_commands:SKILL.md:502:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `provider`: which storage service hosts the branch bucket. Optional, defaults to `\"AWS\"` ([Amazon ","category":"external_commands","line_end":502,"severity":"medium","line_start":502},{"id":"external_commands:SKILL.md:503:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `source` (alias `connection`, so configs mirroring other engines work too): locates the source buc","category":"external_commands","line_end":503,"severity":"medium","line_start":503},{"id":"external_commands:SKILL.md:504:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `copy.mode`: `\"empty\"` (default) clones the bucket and its settings with no objects; `\"all\"` also ","category":"external_commands","line_end":504,"severity":"medium","line_start":504},{"id":"external_commands:SKILL.md:505:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Fields that **don't apply** (rejected, or a config error): `version`, `image` (no container to run","category":"external_commands","line_end":505,"severity":"medium","line_start":505},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Bucket settings are cloned **best-effort**: object ownership controls, public access block, tags, ","category":"external_commands","line_end":506,"severity":"medium","line_start":506},{"id":"external_commands:SKILL.md:507:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Permissions: the operator clones with its **own** AWS credentials (IAM role assumption via `sa.rol","category":"external_commands","line_end":507,"severity":"medium","line_start":507},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the operator doesn't support S3 branching, the session fails immediately: an older operator repor","category":"external_commands","line_end":509,"severity":"medium","line_start":509},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For any stateful service mirrord has no built-in engine for (InfluxDB, Valkey, Cassandra, an interna","category":"external_commands","line_end":513,"severity":"medium","line_start":513},{"id":"external_commands:SKILL.md:515:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"You declare the params your service needs under `connection.params` (the fixed slots plus **any** cu","category":"external_commands","line_end":515,"severity":"medium","line_start":515},{"id":"external_commands:SKILL.md:519:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `image` | Unless a `profile` supplies it | Full image reference including tag. `version` is not al","category":"external_commands","line_end":519,"severity":"medium","line_start":519},{"id":"external_commands:references/db-branches-schema.json:362:shell-command-substitution","file":"references/db-branches-schema.json","pattern":"Shell command substitution","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"external_commands","line_end":362,"severity":"medium","line_start":362},{"id":"external_commands:references/db-branches-schema.json:1491:shell-command-substitution","file":"references/db-branches-schema.json","pattern":"Shell command substitution","snippet":"\"description\": \"Entrypoint command override for the copy container. Values may reference the same\\n`","category":"external_commands","line_end":1491,"severity":"medium","line_start":1491},{"id":"external_commands:SKILL.md:515:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"You declare the params your service needs under `connection.params` (the fixed slots plus **any** cu","category":"external_commands","line_end":515,"severity":"medium","line_start":515},{"id":"external_commands:SKILL.md:521:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"| `command` / `args` | No | Entrypoint override; may reference `$(MIRRORD_PARAM_<NAME>)`. |","category":"external_commands","line_end":521,"severity":"medium","line_start":521},{"id":"external_commands:SKILL.md:546:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"\"args\": [\"valkey-server\", \"--requirepass\", \"$(MIRRORD_PARAM_PASSWORD)\"]","category":"external_commands","line_end":546,"severity":"medium","line_start":546},{"id":"external_commands:SKILL.md:566:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"- `copy.command` / `copy.args` (optional): entrypoint override; may reference the branch container's","category":"external_commands","line_end":566,"severity":"medium","line_start":566},{"id":"external_commands:SKILL.md:587:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"**Security & ops notes:** generic branching is off by default and lets branch creators run arbitrary","category":"external_commands","line_end":587,"severity":"medium","line_start":587},{"id":"external_commands:references/db-branches-schema.json:362:template-literal-with-command-substitution","file":"references/db-branches-schema.json","pattern":"Template literal with command substitution","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"external_commands","line_end":362,"severity":"medium","line_start":362},{"id":"external_commands:references/db-branches-schema.json:1491:template-literal-with-command-substitution","file":"references/db-branches-schema.json","pattern":"Template literal with command substitution","snippet":"\"description\": \"Entrypoint command override for the copy container. Values may reference the same\\n`","category":"external_commands","line_end":1491,"severity":"medium","line_start":1491},{"id":"external_commands:SKILL.md:515:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"You declare the params your service needs under `connection.params` (the fixed slots plus **any** cu","category":"external_commands","line_end":515,"severity":"medium","line_start":515},{"id":"external_commands:SKILL.md:521:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"| `command` / `args` | No | Entrypoint override; may reference `$(MIRRORD_PARAM_<NAME>)`. |","category":"external_commands","line_end":521,"severity":"medium","line_start":521},{"id":"external_commands:SKILL.md:531:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```json","category":"external_commands","line_end":549,"severity":"medium","line_start":531},{"id":"external_commands:SKILL.md:566:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"- `copy.command` / `copy.args` (optional): entrypoint override; may reference the branch container's","category":"external_commands","line_end":566,"severity":"medium","line_start":566},{"id":"external_commands:SKILL.md:587:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"**Security & ops notes:** generic branching is off by default and lets branch creators run arbitrary","category":"external_commands","line_end":587,"severity":"medium","line_start":587},{"id":"blocker:README.md:8:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"- **Generate** valid `feature.db_branches` configs for mirrord.json","category":"blocker","line_end":8,"severity":"low","line_start":8},{"id":"blocker:references/db-branches-schema.json:203:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"blocker","line_end":203,"severity":"low","line_start":203},{"id":"blocker:references/db-branches-schema.json:228:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":228,"severity":"low","line_start":228},{"id":"blocker:references/db-branches-schema.json:312:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":312,"severity":"low","line_start":312},{"id":"blocker:references/db-branches-schema.json:362:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"When branching a database, cache, or any other stateful service that mirrord has no ","category":"blocker","line_end":362,"severity":"low","line_start":362},{"id":"blocker:references/db-branches-schema.json:422:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":422,"severity":"low","line_start":422},{"id":"blocker:references/db-branches-schema.json:534:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":534,"severity":"low","line_start":534},{"id":"blocker:references/db-branches-schema.json:617:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":617,"severity":"low","line_start":617},{"id":"blocker:references/db-branches-schema.json:689:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":689,"severity":"low","line_start":689},{"id":"blocker:references/db-branches-schema.json:784:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":784,"severity":"low","line_start":784},{"id":"blocker:references/db-branches-schema.json:887:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":887,"severity":"low","line_start":887},{"id":"blocker:references/db-branches-schema.json:987:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"title\": \"feature.db_branches[].id (type: redis) {#feature-db_branches-redis-id}\",","category":"blocker","line_end":987,"severity":"low","line_start":987},{"id":"blocker:references/db-branches-schema.json:1042:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1042,"severity":"low","line_start":1042},{"id":"blocker:references/db-branches-schema.json:1124:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1124,"severity":"low","line_start":1124},{"id":"blocker:references/db-branches-schema.json:1217:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Optional stable id for reusing or sharing a branch across users.\",","category":"blocker","line_end":1217,"severity":"low","line_start":1217},{"id":"blocker:references/db-branches-schema.json:2123:system-reconnaissance","file":"references/db-branches-schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Redis host/hostname.\\nCan be sourced from an environment variable.\",","category":"blocker","line_end":2123,"severity":"low","line_start":2123},{"id":"blocker:references/troubleshooting.md:24:system-reconnaissance","file":"references/troubleshooting.md","pattern":"System reconnaissance","snippet":"\"tables\": { \"users\": { \"filter\": \"id < 100\" } }","category":"blocker","line_end":24,"severity":"low","line_start":24},{"id":"blocker:references/troubleshooting.md:120:system-reconnaissance","file":"references/troubleshooting.md","pattern":"System reconnaissance","snippet":"MongoDB uses JSON-based filter syntax, not SQL. Filters must be valid MongoDB query documents as esc","category":"blocker","line_end":120,"severity":"low","line_start":120},{"id":"blocker:SKILL.md:14:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Generate** valid `db_branches` configs from natural language descriptions","category":"blocker","line_end":14,"severity":"low","line_start":14},{"id":"blocker:SKILL.md:117:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| `id` | all | Reuse/share a branch: same `id` reattaches to an existing branch while its TTL hasn't","category":"blocker","line_end":117,"severity":"low","line_start":117},{"id":"blocker:SKILL.md:187:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Also cluster-admin Helm config, not a `db_branches` field: `pgBranchConfig.dbPod.dbServerArgs` is a ","category":"blocker","line_end":187,"severity":"low","line_start":187},{"id":"blocker:SKILL.md:406:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"IAM only authenticates against the **real** cloud database — the branch is a plain database pod the ","category":"blocker","line_end":406,"severity":"low","line_start":406},{"id":"blocker:SKILL.md:529:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Connection must use **params mode** (URL mode is rejected; extract `host`/`port` from URL-shaped var","category":"blocker","line_end":529,"severity":"low","line_start":529},{"id":"blocker:SKILL.md:776:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Valid JSON**: Always parseable, no comments or trailing commas.","category":"blocker","line_end":776,"severity":"low","line_start":776},{"id":"blocker:SKILL.md:779:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Safe defaults**: Default to `\"empty\"` copy mode to avoid long creation times.","category":"blocker","line_end":779,"severity":"low","line_start":779},{"id":"network:references/db-branches-schema.json:2:hardcoded-url","file":"references/db-branches-schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"http://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:references/db-branches-schema.json:4:hardcoded-url","file":"references/db-branches-schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"JSON Schema for the feature.db_branches configuration in mirrord.json. Extracted ver","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"network:references/db-branches-schema.json:203:hardcoded-url","file":"references/db-branches-schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Configuration for a database branch.\\n\\nExample:\\n\\n```json\\n{\\n  \\\"id\\\": \\\"my-branc","category":"network","line_end":203,"severity":"low","line_start":203},{"id":"network:references/db-branches-schema.json:2435:hardcoded-url","file":"references/db-branches-schema.json","pattern":"Hardcoded URL","snippet":"\"description\": \"Apply migrations with [Flyway](https://documentation.red-gate.com/flyway).\",","category":"network","line_end":2435,"severity":"low","line_start":2435},{"id":"network:SKILL.md:35:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [DB Branching Overview](https://metalbear.com/mirrord/docs/sharing-the-cluster/db-branching/)","category":"network","line_end":35,"severity":"low","line_start":35},{"id":"network:SKILL.md:36:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Engines: [MySQL](https://metalbear.com/mirrord/docs/sharing-the-cluster/db-branching/mysql/) · [Po","category":"network","line_end":36,"severity":"low","line_start":36},{"id":"network:SKILL.md:37:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Connection Modes](https://metalbear.com/mirrord/docs/sharing-the-cluster/db-branching/connection/","category":"network","line_end":37,"severity":"low","line_start":37},{"id":"network:SKILL.md:38:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [IAM Authentication](https://metalbear.com/mirrord/docs/sharing-the-cluster/db-branching/iam-authe","category":"network","line_end":38,"severity":"low","line_start":38},{"id":"network:SKILL.md:39:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Schema Migrations](https://metalbear.com/mirrord/docs/sharing-the-cluster/db-branching/migrations","category":"network","line_end":39,"severity":"low","line_start":39},{"id":"network:SKILL.md:40:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Branch Management](https://metalbear.com/mirrord/docs/sharing-the-cluster/db-branching/management","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"network:SKILL.md:50:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"https://raw.githubusercontent.com/metalbear-co/mirrord/main/mirrord-schema.json","category":"network","line_end":50,"severity":"low","line_start":50},{"id":"network:SKILL.md:187:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Also cluster-admin Helm config, not a `db_branches` field: `pgBranchConfig.dbPod.dbServerArgs` is a ","category":"network","line_end":187,"severity":"low","line_start":187},{"id":"network:SKILL.md:230:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **ConfigMap** (params only): read a value out of a config file mounted from a ConfigMap, instead o","category":"network","line_end":230,"severity":"low","line_start":230},{"id":"network:SKILL.md:363:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Runs [Liquibase](https://docs.liquibase.com) changelogs (XML, YAML, JSON, or formatted SQL). Liquiba","category":"network","line_end":363,"severity":"low","line_start":363},{"id":"network:SKILL.md:502:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `provider`: which storage service hosts the branch bucket. Optional, defaults to `\"AWS\"` ([Amazon ","category":"network","line_end":502,"severity":"low","line_start":502},{"id":"network:SKILL.md:507:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Permissions: the operator clones with its **own** AWS credentials (IAM role assumption via `sa.rol","category":"network","line_end":507,"severity":"low","line_start":507}],"finding_verdicts":[{"id":"sensitive:references/db-branches-schema.json:362:environment-file-access","reason":"The env property configures container variables; no environment file is opened. The fixed administrator password in this example is reported separately.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:398:environment-file-access","reason":"The passage describes migration inheritance of Kubernetes env and envFrom settings. It does not open an environment file or request local secrets.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/db-branches-schema.json:203:heuristic-extremely-long-line-4126-chars-likely-","reason":"The long line is a readable JSON description containing escaped newlines and configuration examples. There is no encoded executable payload or obfuscation mechanism.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:references/db-branches-schema.json:362:heuristic-extremely-long-line-4874-chars-likely-","reason":"The long line is a readable JSON description containing escaped newlines and configuration examples. There is no encoded executable payload or obfuscation mechanism.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/db-branches-schema.json:1587:aws-credential-environment-variables","reason":"These are documented target-pod variable names for AWS IAM authentication, not credential values. The passage does not request printing or exporting their contents.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/troubleshooting.md:100:aws-credential-environment-variables","reason":"These are documented target-pod variable names for AWS IAM authentication, not credential values. The passage does not request printing or exporting their contents.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/troubleshooting.md:101:aws-credential-environment-variables","reason":"These are documented target-pod variable names for AWS IAM authentication, not credential values. The passage does not request printing or exporting their contents.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/troubleshooting.md:102:aws-credential-environment-variables","reason":"These are documented target-pod variable names for AWS IAM authentication, not credential values. The passage does not request printing or exporting their contents.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:414:aws-credential-environment-variables","reason":"These are documented target-pod variable names for AWS IAM authentication, not credential values. The passage does not request printing or exporting their contents.","verdict":"false_positive","confidence":0.97},{"id":"env_access:README.md:62:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/db-branches-schema.json:203:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/db-branches-schema.json:969:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/db-branches-schema.json:1257:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/troubleshooting.md:62:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/troubleshooting.md:83:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/troubleshooting.md:170:database-connection-strings","reason":"The example names a secret source and a destination environment variable. It contains no credential value and does not send secrets to an unrelated endpoint.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:82:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:200:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:203:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:216:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:229:database-connection-strings","reason":"The example names a secret source and a destination environment variable. It contains no credential value and does not send secrets to an unrelated endpoint.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:231:database-connection-strings","reason":"The example names a secret source and a destination environment variable. It contains no credential value and does not send secrets to an unrelated endpoint.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:232:database-connection-strings","reason":"The example names a secret source and a destination environment variable. It contains no credential value and does not send secrets to an unrelated endpoint.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:234:database-connection-strings","reason":"The literal value is an ellipsis placeholder, not a password. The text restricts literal values to user-supplied configuration and describes Kubernetes Secret storage.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:245:database-connection-strings","reason":"The example names a secret source and a destination environment variable. It contains no credential value and does not send secrets to an unrelated endpoint.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:260:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:398:database-connection-strings","reason":"This describes intended migration environment inheritance and branch connection rewriting, not credential extraction by the assistant. Only trusted migration images should receive inherited variables.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:451:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:647:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:660:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:689:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:755:database-connection-strings","reason":"The connection example references environment-variable names such as DATABASE_URL, DB_PASSWORD, or REDIS_URL. It does not embed a live credential or instruct credential disclosure.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/db-branches-schema.json:1641:gcp-credential-environment-variables","reason":"The passage documents environment references for GCP authentication in the init container. It does not request disclosure of service-account keys to the assistant.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:437:gcp-credential-environment-variables","reason":"The passage documents environment references for GCP authentication in the init container. It does not request disclosure of service-account keys to the assistant.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:422:generic-api-secret-keys","reason":"MY_SECRET_KEY is an example environment-variable name for the secret_access_key source. No API key value or unauthorized credential collection is present.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:118:path-traversal-sequence","reason":"The text .../<name> abbreviates a database connection URL. It is not a filesystem path or a directory traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:231:path-traversal-sequence","reason":"The projects/../secrets/../versions/latest text is a placeholder Google Secret Manager resource identifier. It is not used for local filesystem traversal.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:README.md:8:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:4:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:203:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:300:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:362:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:522:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:772:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:853:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:875:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:912:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:913:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:973:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:987:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:996:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:1012:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:1027:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:1049:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:1118:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:1182:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:1195:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2110:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2122:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2135:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2148:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2160:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2169:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2182:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2233:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2242:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2248:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2256:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2265:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2271:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/db-branches-schema.json:2280:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:46:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:161:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:183:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:187:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:265:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:484:sqlite-database-file","reason":"The matched text describes mirrord branch configuration fields or schema references. It does not identify or open a SQLite database file.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/db-branches-schema.json:2234:hidden-file-access","reason":"The .local path is an example location for a user-installed Podman executable. No hidden credentials file is read or disclosed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:4:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:31:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:93:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:116:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:203:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:206:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:242:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:251:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:278:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:301:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:326:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:335:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:362:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:390:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:429:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:443:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:453:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:464:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:473:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:500:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:541:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:559:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:568:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:595:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:631:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:640:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:667:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:696:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:714:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:723:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:750:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:791:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:809:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:818:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:845:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:854:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:894:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:913:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:923:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:932:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:959:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:969:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1012:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1049:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1061:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1070:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1096:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1119:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1138:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1147:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1174:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1183:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1196:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1200:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1224:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1233:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1250:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1257:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1299:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1358:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1383:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1407:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1433:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1483:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1487:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1491:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1517:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1520:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1555:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1584:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1587:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1641:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1687:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1776:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1826:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1888:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1977:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2066:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2106:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2170:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2234:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2243:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2266:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2272:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2289:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2304:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2324:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2432:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:2461:ruby-shell-backtick-execution","reason":"Backticks occur inside a JSON schema description as Markdown formatting for configuration documentation. They are not evaluated as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:341:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:359:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:375:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:376:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:377:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:384:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:392:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:406:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:410:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:412:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:414:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:416:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:425:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:437:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:439:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:447:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:455:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:461:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:463:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:476:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:478:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:479:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:484:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:488:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:490:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:500:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown example block. They are not shell command substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:502:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:503:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:504:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:505:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:507:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:509:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:515:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:519:ruby-shell-backtick-execution","reason":"Backticks mark inline configuration fields, examples, or command names in Markdown prose. This location does not evaluate them as Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:362:shell-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1491:shell-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:515:shell-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:521:shell-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:546:shell-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:566:shell-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:587:shell-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:362:template-literal-with-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/db-branches-schema.json:1491:template-literal-with-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:515:template-literal-with-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:521:template-literal-with-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:531:template-literal-with-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:566:template-literal-with-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:587:template-literal-with-command-substitution","reason":"The example uses Kubernetes $(VAR) environment expansion in container configuration. It is not shell command substitution or an evaluated JavaScript template literal.","verdict":"false_positive","confidence":0.99},{"id":"blocker:README.md:8:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:203:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:228:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:312:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:362:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:422:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:534:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:617:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:689:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:784:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:887:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:987:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:1042:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:1124:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:1217:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/db-branches-schema.json:2123:system-reconnaissance","reason":"The description defines a Redis hostname connection setting. It does not invoke the hostname command or enumerate the host system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/troubleshooting.md:24:system-reconnaissance","reason":"The id token is a database column in an illustrative row filter. No operating-system identity command is executed.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/troubleshooting.md:120:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:14:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:117:system-reconnaissance","reason":"The id field identifies a reusable database branch. It is configuration metadata, not execution of the operating-system id command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:187:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:406:system-reconnaissance","reason":"The paragraph explains PostgreSQL branch authentication behavior. It contains no system enumeration command; trust authentication still requires appropriate network isolation.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:529:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:776:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:779:system-reconnaissance","reason":"The cited text explains configuration validity, branch identifiers, or connection settings. It does not execute host discovery or system reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"network:references/db-branches-schema.json:2:hardcoded-url","reason":"This URI identifies the JSON Schema draft used by the reference file. It is not a credential destination or an instruction to transmit user data.","verdict":"false_positive","confidence":0.98},{"id":"network:references/db-branches-schema.json:4:hardcoded-url","reason":"The GitHub URL identifies the upstream mirrord schema source. No secret-bearing payload or unrelated data-transfer instruction is attached.","verdict":"false_positive","confidence":0.98},{"id":"network:references/db-branches-schema.json:203:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:references/db-branches-schema.json:2435:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:35:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:36:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:37:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:38:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:39:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:40:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:50:hardcoded-url","reason":"The GitHub URL identifies the upstream mirrord schema source. No secret-bearing payload or unrelated data-transfer instruction is attached.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:187:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:230:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:363:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:502:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:507:hardcoded-url","reason":"The URL links to relevant product or database-tool documentation. The cited passage contains no instruction to upload credentials or private project data.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Troubleshooting Can Expose Database Credentials","severity":"high","locations":[{"file":"references/troubleshooting.md","line_end":78,"line_start":74}],"confidence":0.98,"description":"The troubleshooting command runs `env | grep -iE 'database|postgres|mysql|redis|mongo'` through mirrord, printing matching values rather than names. Database URLs can contain credentials, which may enter terminal logs or an agent transcript without redaction.","confidence_reasoning":"The command directly prints matching environment entries without removing their values. Exposure depends on the target environment, but no output redaction is shown."},{"title":"Predictable Administrator Password in Branch Example","severity":"medium","locations":[{"file":"references/db-branches-schema.json","line_end":362,"line_start":362}],"confidence":0.97,"description":"The generic InfluxDB example sets DOCKER_INFLUXDB_INIT_USERNAME to admin and DOCKER_INFLUXDB_INIT_PASSWORD to mirrord-branch. Reusing this example creates a predictable administrator credential, allowing unauthorized access wherever the branch service is reachable.","confidence_reasoning":"The schema description explicitly supplies a fixed administrator username and password in an executable configuration example. Exploitability depends on network reachability and example reuse."}],"subject_marketplace_commit_sha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","subject_content_hash":"82cf6c37e84c2fb4f27afbf2ed63ca398b75cdc854cc0f4ee2628bc60b0a4d29","subject_tree_hash":"23c7139189cecd185b971fdcb55cbb9329b2e433ac9bb698f9872d5f3c3e350e","subject_plugin_path":"skills/metalbear-co/mirrord-db-branching","audit_payload_hash":"795bf770dac0b4fcc7c3de8d418f888c","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","contentHash":"82cf6c37e84c2fb4f27afbf2ed63ca398b75cdc854cc0f4ee2628bc60b0a4d29","treeHash":"23c7139189cecd185b971fdcb55cbb9329b2e433ac9bb698f9872d5f3c3e350e","pluginPath":"skills/metalbear-co/mirrord-db-branching","auditPayloadHash":"795bf770dac0b4fcc7c3de8d418f888c"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/metalbear-co-mirrord-db-branching/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}