{"data":{"skill":{"slug":"metalbear-co-mirrord-prev-env","name":"mirrord-prev-env","icon":"📦","repo":"https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-prev-env","status":"approved","author":"metalbear-co","authorVersion":"2.5","skillstoreRevision":1},"audit":{"id":"a319c388-5e25-413a-887b-888d2999837b","skill_id":"0ed52bfb-2f84-4ef8-abfb-48ac2dacba60","version":1,"content_hash":"v3:bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2:d312dce595adb9b42632433fafff435ef1a278d0bb0ac1e80c22a0b4b2773a69:08a04f1c0895961601a269c06d8793c922342be0534628fa2a8c05dfcd649dcf:736b696c6c732f6d6574616c626561722d636f2f6d6972726f72642d707265762d656e76:7a4bde5effda237c73ed27bb0b0149b0","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 162 static matches are false positives involving Markdown syntax, documentation links, or expected setup operations. Four contextual risks remain: persistent CI credentials, mutable Action references, a missing trusted-PR guard, and traffic filters that match key prefixes. No evidence found of prompt injection, credential exfiltration, or malicious intent in the two reviewed files.","remediation":[{"issue":"The CI setup creates a persistent service-account token despite recommending short-lived credentials.","severity":"medium","suggestion":"Make OIDC or expiring TokenRequest credentials the primary example; document expiration, rotation, revocation, and runner cleanup for any stored-token fallback."},{"issue":"Workflow examples run the preview Action from a mutable main branch with cluster credentials available.","severity":"medium","suggestion":"Pin Actions to reviewed commit hashes and use cli_path with a verified CLI in a trusted runner image."},{"issue":"The preview-start example lacks the trusted-PR restriction required by the security guidance.","severity":"high","suggestion":"Add an explicit same-repository or approved-author gate before cluster authentication and deployment; do not grant cluster credentials to untrusted PR jobs."},{"issue":"Example header filters can match environment keys with additional suffixes.","severity":"medium","suggestion":"Escape keys for regex use and require complete baggage-member boundaries; test prefix collisions, extra members, whitespace, and similar keys."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"README.md","line_end":33,"line_start":28},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":74,"line_start":72},{"file":"SKILL.md","line_end":76,"line_start":74},{"file":"SKILL.md","line_end":79,"line_start":76},{"file":"SKILL.md","line_end":83,"line_start":79},{"file":"SKILL.md","line_end":87,"line_start":83},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":105,"line_start":89},{"file":"SKILL.md","line_end":107,"line_start":105},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":113,"line_start":111},{"file":"SKILL.md","line_end":121,"line_start":113},{"file":"SKILL.md","line_end":123,"line_start":121},{"file":"SKILL.md","line_end":125,"line_start":123},{"file":"SKILL.md","line_end":127,"line_start":125},{"file":"SKILL.md","line_end":129,"line_start":127},{"file":"SKILL.md","line_end":150,"line_start":129},{"file":"SKILL.md","line_end":156,"line_start":150},{"file":"SKILL.md","line_end":156,"line_start":156},{"file":"SKILL.md","line_end":158,"line_start":157},{"file":"SKILL.md","line_end":158,"line_start":158},{"file":"SKILL.md","line_end":160,"line_start":159},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":163,"line_start":161},{"file":"SKILL.md","line_end":163,"line_start":163},{"file":"SKILL.md","line_end":168,"line_start":166},{"file":"SKILL.md","line_end":172,"line_start":168},{"file":"SKILL.md","line_end":174,"line_start":172},{"file":"SKILL.md","line_end":176,"line_start":174},{"file":"SKILL.md","line_end":178,"line_start":176},{"file":"SKILL.md","line_end":178,"line_start":178},{"file":"SKILL.md","line_end":190,"line_start":180},{"file":"SKILL.md","line_end":192,"line_start":190},{"file":"SKILL.md","line_end":198,"line_start":192}]},{"factor":"filesystem","evidence":[{"file":"README.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":427,"line_start":427},{"file":"SKILL.md","line_end":501,"line_start":501}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":175,"line_start":175},{"file":"SKILL.md","line_end":234,"line_start":234},{"file":"SKILL.md","line_end":286,"line_start":286},{"file":"SKILL.md","line_end":497,"line_start":497},{"file":"SKILL.md","line_end":498,"line_start":498},{"file":"SKILL.md","line_end":499,"line_start":499},{"file":"SKILL.md","line_end":500,"line_start":500},{"file":"SKILL.md","line_end":501,"line_start":501},{"file":"SKILL.md","line_end":502,"line_start":502}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":463,"line_start":463}]}],"critical_findings":[],"high_findings":[{"title":"Preview Workflow Omits the Required Trusted-PR Gate","locations":[{"file":"SKILL.md","line_end":377,"line_start":357},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":455,"line_start":455}],"confidence":0.85,"description":"The pull_request example starts previews whenever the event is not closed, without checking repository ownership or author approval. Where cluster credentials are available to fork jobs, copying this workflow can deploy untrusted PR images into the shared cluster.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The start condition lacks the trust check explicitly required elsewhere in the skill. Default GitHub fork-secret restrictions mitigate exposure, so exploitation depends on runner credentials and authentication configuration."}],"medium_findings":[{"title":"Persistent Cluster Credentials in the Primary CI Example","locations":[{"file":"SKILL.md","line_end":323,"line_start":294},{"file":"SKILL.md","line_end":333,"line_start":325}],"confidence":0.96,"description":"The setup creates a service-account-token Secret, extracts its token, and stores a reusable kubeconfig in CI. Unlike short-lived authentication, a stolen token remains usable until revoked, extending access to preview-management privileges.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The YAML explicitly creates a persistent service-account-token Secret and instructs storing its derived kubeconfig. OIDC is mentioned, but expiration and rotation are absent from this example."},{"title":"Mutable Action References in Credentialed CI Workflows","locations":[{"file":"README.md","line_end":59,"line_start":45},{"file":"SKILL.md","line_end":387,"line_start":364},{"file":"SKILL.md","line_end":446,"line_start":433},{"file":"SKILL.md","line_end":64,"line_start":64}],"confidence":0.97,"description":"Examples execute metalbear-co/mirrord-preview@main after configuring cluster access. A changed or compromised branch can execute different code with those credentials; the default CLI download adds another unpinned dependency.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The examples use @main rather than immutable revisions and describe automatic installation of the latest CLI. This establishes a supply-chain exposure, not evidence that upstream code is malicious."},{"title":"Traffic Filters Do Not Enforce Complete Environment Keys","locations":[{"file":"SKILL.md","line_end":145,"line_start":140},{"file":"SKILL.md","line_end":377,"line_start":375},{"file":"README.md","line_end":53,"line_start":51}],"confidence":0.96,"description":"The example regex accepts any suffix after alice-checkout-fix, while CI filters substitute a key without an ending boundary. A longer key sharing that prefix can match another preview filter and misroute requests, weakening the documented session isolation.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The ad-hoc regex explicitly ends its key match with .*, and the CI regex has no complete-member boundary. Prefix collisions follow directly from these documented regex patterns."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":573,"audit_model":"codex","audited_at":"2026-09-29T21:57:00.123+00:00","created_at":"2026-09-30T13:39:06.837496+00:00","static_findings":[{"id":"external_commands:README.md:28:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"\"What config and flags does `mirrord preview start` need?\"","category":"external_commands","line_end":33,"severity":"medium","line_start":28},{"id":"filesystem:README.md:69:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"- [Reference workflow (playground)](https://github.com/metalbear-co/playground/blob/main/.github/wor","category":"filesystem","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Ad-hoc (developer) mode** — a developer runs the `mirrord preview` CLI (`start` / `status` / `s","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **CI mode** — the `metalbear-co/mirrord-preview` GitHub Action wires previews into a PR lifecycle","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- \"`mirrord preview start` — what config and flags do I need?\"","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Only deploy images you trust.** A preview runs an arbitrary container image inside your cluster.","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Scope the traffic filter narrowly.** `steal` mode intercepts matching requests away from the rea","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Always set a TTL** (`ttl_mins`/`ttl_secs`) so an exposed preview environment tears itself down a","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Treat user-provided config (`mirrord.json`), `extra_config`, and CLI/Action inputs as **untrusted ","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `extra_config` is deep-merged into the generated config and can override any field — review it bef","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reaching a preview** requires sending the filter header (e.g. `baggage: mirrord-session=<key>`).","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Local session precedence:** if a developer runs `mirrord exec` against the same deployment with ","category":"external_commands","line_end":53,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Multi-cluster:** with `operator.multiCluster.preview.mode: replicas` set on every cluster (opera","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Service meshes:** on a mesh-injected target, the preview pod gets a sidecar like any other pod, ","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Preview environment vs. a normal mirrord session:** `mirrord exec` runs your *local* process as if","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **License** | Preview environments require the **Enterprise** plan. A [free trial](https://app.met","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **A built, pushed image** | Preview deploys an *image*, not local source. The preview pod is a cop","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":74,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"# Has to be set to `true` in order to use the preview environments feature.","category":"external_commands","line_end":76,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":79,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":83,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":87,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Image (`-i`) and environment key (`-k`) are passed as CLI flags; everything else comes from the conf","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":105,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":107,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If you omit `-k`, mirrord generates an environment key for you (shown in the output and via `mirrord","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`mirrord preview logs` prints the same output `preview start` already shows when it gives up — pass ","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Example `start` output:","category":"external_commands","line_end":113,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":121,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":123,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The `preview URL` line only appears when [link sharing](#sharing-a-preview-via-a-link) is configured","category":"external_commands","line_end":125,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Preview config (`mirrord.json`)","category":"external_commands","line_end":127,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The config sets the **target** and the **traffic filter**; the image and key come from flags. Previe","category":"external_commands","line_end":129,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":150,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":156,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `target.path` | The deployment/pod the preview shadows, e.g. `deployment/my-backend`. |","category":"external_commands","line_end":156,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `target.namespace` | Namespace of the target (defaults to the current kube context namespace). |","category":"external_commands","line_end":158,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `feature.preview.ttl_mins` (or `ttl_secs`) | Auto-teardown after this long. Always set one for sha","category":"external_commands","line_end":158,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `feature.preview.creation_timeout_secs` | How long to wait for the preview pod to come up before f","category":"external_commands","line_end":160,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `feature.network.incoming.mode` | `steal` (intercept matching traffic) or `mirror` (copy it). |","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `feature.network.incoming.http_filter.header_filter` | Regex selecting which requests reach the pr","category":"external_commands","line_end":163,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> You can also set the image in config via `feature.preview.image` instead of `-i`; the CI Action do","category":"external_commands","line_end":163,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":168,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":172,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Only requests matching `header_filter` are routed to the preview pod; everything else continues to t","category":"external_commands","line_end":174,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":176,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":178,"severity":"medium","line_start":176},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Propagate the header across services.** For the preview to receive traffic through a call chain, i","category":"external_commands","line_end":178,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```go","category":"external_commands","line_end":190,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":192,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Using `baggage` (W3C distributed-tracing baggage) means standards-aware libraries propagate it autom","category":"external_commands","line_end":198,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**KEDA caveat:** once queues are split, the target's autoscaler triggers still watch the *original* ","category":"external_commands","line_end":198,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A preview that also uses HTTP filtering or DB branching still needs a running target pod — traffic i","category":"external_commands","line_end":206,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":208,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":212,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Right after creating it, the operator triggers the CronJob once (a Job named `<session>-start`, mark","category":"external_commands","line_end":212,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Override the inherited schedule with `feature.preview.cronjob.schedule` (Kubernetes CronJob syntax):","category":"external_commands","line_end":216,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":226,"severity":"medium","line_start":216},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":228,"severity":"medium","line_start":226},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A CronJob preview has no long-running pod, so `feature.network.incoming` is ignored (with a warning)","category":"external_commands","line_end":228,"severity":"medium","line_start":228},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Requires operator **3.205.0+** and CLI **3.256.0+**, plus `create`/`delete`/`patch` on `batch/cronjo","category":"external_commands","line_end":230,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"By default, reaching a preview requires injecting the `baggage: mirrord-session=<key>` header — fine","category":"external_commands","line_end":234,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Each shareable preview is reachable at its own host, `<slug>.<shareDomain>`, printed by `mirrord p","category":"external_commands","line_end":236,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **The preview URL works with any HTTP filter.** A preview with a custom `http_filter` (a path filt","category":"external_commands","line_end":239,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**How it works:** `mirrord-share-ingress` runs as its own Deployment + Service, watches Preview Envi","category":"external_commands","line_end":239,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Configure the operator with the domain share hosts are minted under (must match the chart's `shar","category":"external_commands","line_end":245,"severity":"medium","line_start":243},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":251,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":253,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Install the `mirrord-share-ingress` chart **before** the first preview (your ingress, DNS, and ce","category":"external_commands","line_end":253,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":259,"severity":"medium","line_start":255},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":261,"severity":"medium","line_start":259},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Point a wildcard DNS record `*.preview.example.com` at your ingress, and create an Ingress with a","category":"external_commands","line_end":261,"severity":"medium","line_start":261},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":266,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":270,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"By default the slug carries a random suffix, so the link only exists once `mirrord preview start` pr","category":"external_commands","line_end":270,"severity":"medium","line_start":270},{"id":"external_commands:SKILL.md:272:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":278,"severity":"medium","line_start":272},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":280,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"With it on, the host is `<sanitized key>.<shareDomain>`: the key lowercased, every other character r","category":"external_commands","line_end":280,"severity":"medium","line_start":280},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Since anyone who knows the key can build the link, it becomes guessable — only turn this on when the","category":"external_commands","line_end":282,"severity":"medium","line_start":282},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[`metalbear-co/mirrord-preview`](https://github.com/metalbear-co/mirrord-preview) installs the mirro","category":"external_commands","line_end":286,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The CI job needs a kubeconfig to run `mirrord preview`, but **not** cluster-admin. The operator Helm","category":"external_commands","line_end":290,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Create an identity and grant it the role** — a `ServiceAccount` (the identity), a `ClusterRoleB","category":"external_commands","line_end":294,"severity":"medium","line_start":294},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":320,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":322,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Build a kubeconfig** from the API server address, cluster CA, and the token (`.data.token` from","category":"external_commands","line_end":322,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Store it as a CI secret** (e.g. base64-encode into `KUBECONFIG_DATA`), then decode it and point","category":"external_commands","line_end":323,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":331,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":333,"severity":"medium","line_start":331},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A token with only this ClusterRole can manage preview environments but can't read or modify other cl","category":"external_commands","line_end":339,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `action` | **yes** | `start` or `stop`. |","category":"external_commands","line_end":339,"severity":"medium","line_start":339},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `target` | **yes** (start) | Kubernetes target path, e.g. `deployment/my-app`. → `target.path` |","category":"external_commands","line_end":340,"severity":"medium","line_start":340},{"id":"external_commands:SKILL.md:341:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `namespace` | no | Target namespace. Defaults to current context. → `target.namespace` |","category":"external_commands","line_end":341,"severity":"medium","line_start":341},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `image` | **yes** (start) | Container image for the preview pod. → `feature.preview.image` |","category":"external_commands","line_end":342,"severity":"medium","line_start":342},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mode` | no | `steal` or `mirror`. Default `steal`. → `feature.network.incoming.mode` |","category":"external_commands","line_end":343,"severity":"medium","line_start":343},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `filter` | no | Header filter regex; use `{{ key }}`. Defaults to a `baggage` / `mirrord-session={","category":"external_commands","line_end":344,"severity":"medium","line_start":344},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ports` | no | JSON array of incoming ports, e.g. `[80, 8080]`. → `feature.network.incoming.ports`","category":"external_commands","line_end":345,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:346:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ttl_mins` | no | Session TTL in minutes. Integer or `\"infinite\"`. → `feature.preview.ttl_mins` |","category":"external_commands","line_end":346,"severity":"medium","line_start":346},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `key` | **yes** (stop) / optional (start) | Environment key; auto-generated on start if omitted, r","category":"external_commands","line_end":347,"severity":"medium","line_start":347},{"id":"external_commands:SKILL.md:348:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cli_path` | no | Path to a pre-existing mirrord binary (skips download). For testing unreleased b","category":"external_commands","line_end":349,"severity":"medium","line_start":348},{"id":"external_commands:SKILL.md:349:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `extra_config` | no | JSON object deep-merged into the generated `mirrord.json`; overrides overlap","category":"external_commands","line_end":349,"severity":"medium","line_start":349},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Output:** `session-key` — the key of the started preview (use it for the matching stop).","category":"external_commands","line_end":357,"severity":"medium","line_start":351},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":388,"severity":"medium","line_start":357},{"id":"external_commands:SKILL.md:388:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":392,"severity":"medium","line_start":388},{"id":"external_commands:SKILL.md:392:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":396,"severity":"medium","line_start":392},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":402,"severity":"medium","line_start":396},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":409,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:409:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":411,"severity":"medium","line_start":409},{"id":"external_commands:SKILL.md:411:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **`--force` is essential in CI.** Without it, `preview start` **refuses** when a session already e","category":"external_commands","line_end":411,"severity":"medium","line_start":411},{"id":"external_commands:SKILL.md:413:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":415,"severity":"medium","line_start":413},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":419,"severity":"medium","line_start":415},{"id":"external_commands:SKILL.md:419:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":422,"severity":"medium","line_start":419},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":424,"severity":"medium","line_start":422},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The typical flow: on PR open/push, CI builds the image(s), pushes to a registry, runs `mirrord previ","category":"external_commands","line_end":424,"severity":"medium","line_start":424},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> `metalbear-co/playground/.github/workflows/preview-shop-pr.yml` — it detects changed","category":"external_commands","line_end":431,"severity":"medium","line_start":427},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Using `extra_config` for anything the Action doesn't expose","category":"external_commands","line_end":433,"severity":"medium","line_start":431},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":446,"severity":"medium","line_start":433},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":449,"severity":"medium","line_start":446},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Set a TTL as a leak guard, not the primary cleanup.** The PR-close job is the primary cleanup; `","category":"external_commands","line_end":449,"severity":"medium","line_start":449},{"id":"external_commands:SKILL.md:450:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Stop on PR close** with `action: stop` (or `mirrord preview stop -k <key> || true`) using the sa","category":"external_commands","line_end":450,"severity":"medium","line_start":450},{"id":"external_commands:SKILL.md:451:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Key per PR** (e.g. `pr-${{ github.event.pull_request.number }}`, or include the repo name) so co","category":"external_commands","line_end":452,"severity":"medium","line_start":451},{"id":"external_commands:SKILL.md:452:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Use `concurrency`** (group per PR, `cancel-in-progress: true`).","category":"external_commands","line_end":452,"severity":"medium","line_start":452},{"id":"external_commands:SKILL.md:461:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Preview feature unavailable / operator error | Need Operator 3.142.0+ with `operator.previewEnv: t","category":"external_commands","line_end":461,"severity":"medium","line_start":461},{"id":"external_commands:SKILL.md:462:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Traffic never reaches the preview pod | Check the `header_filter` regex matches the header you sen","category":"external_commands","line_end":463,"severity":"medium","line_start":462},{"id":"external_commands:SKILL.md:463:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ErrImagePull` / `401 Unauthorized` on the preview pod | The preview pulls with the **target's** c","category":"external_commands","line_end":463,"severity":"medium","line_start":463},{"id":"external_commands:SKILL.md:464:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `preview start` refuses — session already exists | A previous run's session for that key+target is","category":"external_commands","line_end":464,"severity":"medium","line_start":464},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Preview times out coming up | Increase `feature.preview.creation_timeout_secs` (CLI `--timeout`). ","category":"external_commands","line_end":466,"severity":"medium","line_start":466},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Preview fails/times out for a reason in the application, not mirrord | `preview start` prints the ","category":"external_commands","line_end":467,"severity":"medium","line_start":467},{"id":"external_commands:SKILL.md:468:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Preview environments linger | Set a TTL; to remove now: `mirrord preview stop --key <key>`. Check ","category":"external_commands","line_end":468,"severity":"medium","line_start":468},{"id":"external_commands:SKILL.md:469:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| No `preview URL` / share link doesn't work | Link sharing needs `mirrord-share-ingress` installed ","category":"external_commands","line_end":469,"severity":"medium","line_start":469},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Want to iterate locally against the same preview | Run `mirrord exec` with the same target + env k","category":"external_commands","line_end":471,"severity":"medium","line_start":470},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Need a config option the Action doesn't expose | Use `extra_config` (deep-merged JSON). |","category":"external_commands","line_end":472,"severity":"medium","line_start":471},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `preview start` fails with `no Pod is ready to be a session target` | The preview uses HTTP filter","category":"external_commands","line_end":472,"severity":"medium","line_start":472},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| CronJob preview rejects `network.incoming`/`idle`/`replicas`/a `value_pattern` branch param | Expe","category":"external_commands","line_end":473,"severity":"medium","line_start":473},{"id":"external_commands:SKILL.md:474:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Second preview session fails with `share host <host> is already held by...` | [Stable share hosts]","category":"external_commands","line_end":479,"severity":"medium","line_start":474},{"id":"external_commands:SKILL.md:479:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Confirm prerequisites** — Operator 3.142.0+ with `previewEnv: true`, CLI 3.189.0+, Enterprise p","category":"external_commands","line_end":480,"severity":"medium","line_start":479},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Get target + image + key** — `target` (deployment/pod), the container `image` (`-i` / `image:`)","category":"external_commands","line_end":480,"severity":"medium","line_start":480},{"id":"external_commands:SKILL.md:481:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Explain traffic isolation** — env `key` + `header_filter`, and that intermediate services must ","category":"external_commands","line_end":481,"severity":"medium","line_start":481},{"id":"external_commands:SKILL.md:482:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Always include teardown** — `mirrord preview stop --key <key>` ad hoc, or `action: stop` + a TT","category":"external_commands","line_end":482,"severity":"medium","line_start":482},{"id":"external_commands:SKILL.md:483:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **For options the Action lacks**, point to `extra_config` rather than hand-editing.","category":"external_commands","line_end":490,"severity":"medium","line_start":483},{"id":"external_commands:SKILL.md:490:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Confirm: Operator 3.142.0+ with `previewEnv: true` and Enterprise license? Which cloud (for clust","category":"external_commands","line_end":491,"severity":"medium","line_start":490},{"id":"external_commands:SKILL.md:491:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Provide a `pull_request` workflow that builds+pushes the image, authenticates to the cluster, the","category":"external_commands","line_end":491,"severity":"medium","line_start":491},{"id":"external_commands:SKILL.md:492:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Add a `closed`-event job with `action: stop` and the same `key`.","category":"external_commands","line_end":492,"severity":"medium","line_start":492},{"id":"network:SKILL.md:34:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Never** instruct or generate remote pipe-to-shell installs (downloading a script and executing i","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:SKILL.md:52:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Reaching a preview** requires sending the filter header (e.g. `baggage: mirrord-session=<key>`).","category":"network","line_end":52,"severity":"low","line_start":52},{"id":"network:SKILL.md:66:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| **License** | Preview environments require the **Enterprise** plan. A [free trial](https://app.met","category":"network","line_end":66,"severity":"low","line_start":66},{"id":"network:SKILL.md:120:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"* preview URL: https://<slug>.<shareDomain>","category":"network","line_end":120,"severity":"low","line_start":120},{"id":"network:SKILL.md:175:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -H \"baggage: mirrord-session=alice-checkout-fix\" https://staging.example.com/checkout","category":"network","line_end":175,"severity":"low","line_start":175},{"id":"network:SKILL.md:234:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"By default, reaching a preview requires injecting the `baggage: mirrord-session=<key>` header — fine","category":"network","line_end":234,"severity":"low","line_start":234},{"id":"network:SKILL.md:286:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"[`metalbear-co/mirrord-preview`](https://github.com/metalbear-co/mirrord-preview) installs the mirro","category":"network","line_end":286,"severity":"low","line_start":286},{"id":"network:SKILL.md:497:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mirrord Preview Environments docs](https://metalbear.com/mirrord/docs/use-cases/preview-environme","category":"network","line_end":497,"severity":"low","line_start":497},{"id":"network:SKILL.md:498:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Preview Environments in CI docs](https://metalbear.com/mirrord/docs/use-cases/preview-environment","category":"network","line_end":498,"severity":"low","line_start":498},{"id":"network:SKILL.md:499:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mirrord-preview GitHub Action](https://github.com/metalbear-co/mirrord-preview)","category":"network","line_end":499,"severity":"low","line_start":499},{"id":"network:SKILL.md:500:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mirrord Browser Extension (set the header for reviewers)](https://metalbear.com/mirrord/docs/usin","category":"network","line_end":500,"severity":"low","line_start":500},{"id":"network:SKILL.md:501:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Reference workflow (playground)](https://github.com/metalbear-co/playground/blob/main/.github/wor","category":"network","line_end":501,"severity":"low","line_start":501},{"id":"network:SKILL.md:502:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mirrord config options](https://metalbear.com/mirrord/docs/config/options)","category":"network","line_end":502,"severity":"low","line_start":502},{"id":"filesystem:SKILL.md:427:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"> `metalbear-co/playground/.github/workflows/preview-shop-pr.yml` — it detects changed","category":"filesystem","line_end":427,"severity":"medium","line_start":427},{"id":"filesystem:SKILL.md:501:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- [Reference workflow (playground)](https://github.com/metalbear-co/playground/blob/main/.github/wor","category":"filesystem","line_end":501,"severity":"medium","line_start":501},{"id":"env_access:SKILL.md:463:git-platform-tokens","file":"SKILL.md","pattern":"Git platform tokens","snippet":"| `ErrImagePull` / `401 Unauthorized` on the preview pod | The preview pulls with the **target's** c","category":"env_access","line_end":463,"severity":"high","line_start":463},{"id":"sensitive:SKILL.md:265:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"kubectl create secret tls share-ingress-tls --cert=wildcard.crt --key=wildcard.key -n mirrord","category":"sensitive","line_end":265,"severity":"high","line_start":265},{"id":"blocker:SKILL.md:67:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| **Cluster access** | A valid kubeconfig reachable from wherever you run preview (laptop or CI runn","category":"blocker","line_end":67,"severity":"low","line_start":67},{"id":"blocker:SKILL.md:355:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"The runner needs a valid kubeconfig before the action runs (cloud auth + get-credentials).","category":"blocker","line_end":355,"severity":"low","line_start":355},{"id":"blocker:SKILL.md:390:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Recommended concurrency so rapid pushes don't overlap:","category":"blocker","line_end":390,"severity":"low","line_start":390}],"finding_verdicts":[{"id":"external_commands:README.md:28:ruby-shell-backtick-execution","reason":"The backticks format a CLI name inside an example question. They are not shell command substitution.","verdict":"false_positive","confidence":1},{"id":"filesystem:README.md:69:hidden-file-access","reason":"The .github path is part of a public reference-workflow hyperlink. No hidden local file is accessed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"Backticks format CLI subcommands in a mode description. This is Markdown prose, not executable substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"Backticks identify the GitHub Action in descriptive prose. No shell backtick execution occurs.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The command name appears in a sample user question. Markdown formatting does not execute it.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"This paragraph warns against deploying untrusted images and fork contributions. Backticks format a proposed trust check, not executable substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Backticks label traffic modes and filter settings in a safety recommendation. They do not invoke a shell.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backticked TTL fields describe automatic cleanup. No command execution appears here.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The paragraph explicitly prohibits executing commands or fetching URLs from untrusted configuration. Backticks only format configuration names.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"The paragraph warns reviewers about configuration overrides. Its backticks identify extra_config, not a shell expression.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Inline formatting names the routing header, curl, and share-ingress. This describes preview access without shell substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"This explains local-session precedence using a formatted CLI name. No executable backticks are present.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Inline code identifies multi-cluster settings and version requirements. The text does not execute commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The text explains mesh port exclusions needed for preview routing. STRICT is Markdown-formatted terminology, not shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"A prose comparison names mirrord exec. Backticks are documentation formatting rather than command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The licensing row names another skill and requires user agreement before starting a trial. No shell execution is requested.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The row explains image-pull prerequisites and formats an error name. It contains no shell substitution or credential-reading command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The matched backticks open a YAML code fence for the preview feature flag. They are not executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"A YAML comment formats the Boolean true, followed by the closing Markdown fence. Neither performs command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The match spans adjacent Markdown code fences around configuration and verification examples. No shell backtick expression exists.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The fenced commands check CLI versions, cluster connectivity, and help. These are expected prerequisite checks, without injection or shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The closing code fence and subsequent inline CLI flags are Markdown. They do not execute commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"Inline formatting explains image and environment-key flags. It is not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The fence contains expected start, status, logs, and stop examples with fixed demonstration arguments. No Ruby or shell backtick execution appears.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The match covers a closing Markdown fence and an explanation of generated keys. Neither contains executable backticks.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The paragraph describes automatic key generation and status output. Backticks only label CLI syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"This documents preview logs, target selection, and required versions. No command substitution or external log destination is specified.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The text introduces example start output and a Markdown fence. It does not execute a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The fenced block is illustrative CLI output with placeholder values. Its backticks are not shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"A closing output fence precedes a note about link-sharing prerequisites. No executable substitution occurs.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"Inline code labels preview output and a configuration filename. These are documentation references.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The heading formats mirrord.json as a filename. It is not a shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The paragraph names the preview configuration section before a JSON fence. No shell execution occurs.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"These backticks delimit a JSON configuration example, not command substitution. The filter-isolation defect is assessed separately as a semantic finding.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"A closing JSON fence leads into a field-reference table. This is Markdown structure, not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The table row formats target.path and an example deployment identifier. Neither is executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The table describes namespace and TTL fields using inline code. No executable expression appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The row documents automatic teardown fields and recommends setting them. Its backticks are formatting.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The table explains preview creation timeout and incoming traffic modes. No shell substitution is present.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The backticked values steal and mirror identify configuration modes. They are not executable commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The field table describes routing filters and image configuration. Markdown identifiers do not execute shell commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The note compares a configuration field with a CLI flag. Its inline code is documentation formatting.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The fenced command validates the expected local mirrord configuration. It contains no backtick substitution or untrusted argument interpolation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The match spans a closing fence and explanatory routing prose. No shell backtick execution exists.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"This explains header-based routing before a command example. Backticks format the filter field and code fence.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The fenced curl example sends a demonstration routing header to staging.example.com. It contains no secrets or shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"A closing command fence precedes header-propagation guidance. The matched backticks are Markdown.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"Inline code identifies tracing headers and transports in propagation guidance. It does not invoke a shell.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The fenced Go example copies baggage into outgoing request metadata. There is no Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"A closing Go fence and a formatted header name trigger the match. Neither is executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The prose explains baggage propagation and introduces queue-only previews. Inline identifiers do not execute commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"The paragraph explicitly warns of queue-message loss and gives a KEDA mitigation. Its settings and annotation names are Markdown-formatted data.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"The prose explains target readiness requirements and quotes an error. It contains no shell substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The fenced command demonstrates the requested CronJob preview operation with fixed example arguments. No backtick-based execution or injection is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"The closing fence precedes documentation of CronJob behavior. These backticks are Markdown delimiters.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"The paragraph explains the immediate CronJob run and how to disable it. Backticks format examples and settings, not executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"The text names a schedule configuration field before a JSON block. No shell command is executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","reason":"The backticks delimit JSON showing CronJob preview settings. JSON data does not perform shell substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","reason":"The closing JSON fence leads into configuration limitations. No Ruby or shell execution appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","reason":"The paragraph lists unsupported CronJob settings using inline code. This is explanatory documentation.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"The line lists documented operator permissions and version prerequisites. Backticks label API verbs and resources, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The paragraph describes header injection for preview links. Its inline code contains names and header examples, not shell substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The line describes preview hostname structure and expiry behavior. Backticks format placeholders and CLI output labels.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"This documents how share-link headers supplement configured filters. No executable backticks or external shell command appear.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"The paragraph explains in-cluster forwarding by share-ingress. Backticks format a component name and routing header.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","reason":"The setup step names a domain setting and introduces YAML. Markdown syntax is not command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"The fence contains operator configuration with an example domain. No shell backticks are executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The match joins a closing YAML fence with the following chart setup description. It is Markdown formatting.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"This describes an explicit platform-admin chart installation task. Inline component and setting names are not shell substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","reason":"The Helm example installs the documented share-ingress component using example domains. Its code fence is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","reason":"A closing shell fence precedes DNS and ingress instructions. The matched backticks are Markdown delimiters.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","reason":"Inline code formats a wildcard example hostname and the Host header. No command substitution occurs.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The fence wraps a standard Kubernetes TLS-secret creation example for the configured ingress. The backticks themselves are Markdown, not executable syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"The closing fence precedes a stable-host configuration explanation. No shell backtick execution appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","reason":"This explains an optional operator setting for stable hosts. Backticks format configuration and CLI names.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:272:ruby-shell-backtick-execution","reason":"The YAML fence shows stable-host configuration, with authentication explicitly required below. It contains no executable shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"A closing configuration fence leads into hostname sanitization documentation. The backticks are Markdown syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","reason":"Inline code illustrates hostname normalization and a sample key. It does not execute shell commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","reason":"The paragraph requires authentication for guessable stable hosts and documents collision errors. Backticks format names and error text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"The Action overview formats CLI names and template variables. There is no Ruby or shell command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"The paragraph recommends a scoped CI role instead of cluster-admin credentials. Backticks only identify commands and the role name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","reason":"Backticks identify Kubernetes resource types, not executable substitution. The persistent-token provisioning risk is recorded separately as a semantic finding.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The fence contains Kubernetes YAML, not Ruby or shell execution. Its persistent-token design is assessed separately.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The match covers a closing YAML fence and formatted token-field names. The credential-lifetime concern is separate from this syntax false positive.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"The line describes kubeconfig assembly using a named token field. Markdown backticks do not execute commands; persistent credentials are assessed separately.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"The line names CI secret and environment-variable fields in prose. No executable backtick expression appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"The YAML uses quoted environment variables to decode an intended CI secret into kubeconfig. It does not use backtick execution or exfiltrate credentials.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","reason":"The match spans a closing YAML fence and role-scope documentation. No shell substitution occurs.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The text names the CI role and discusses OIDC as an alternative. Backticks are formatting, not executable syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","reason":"The table lists the action input and its permitted lifecycle values. These are documentation labels.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","reason":"The table documents the target input and its configuration mapping. No shell command is executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:341:ruby-shell-backtick-execution","reason":"The namespace input is described using inline code. It is not executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","reason":"The image input and preview configuration field are Markdown identifiers. No command substitution exists.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","reason":"The table documents steal and mirror as traffic-mode values. Backticks only format data.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","reason":"This lists filter input syntax and key substitution within configuration. It does not execute a shell expression.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"The ports row shows a JSON array and configuration mapping. Neither performs shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:346:ruby-shell-backtick-execution","reason":"The row lists supported TTL input values. Markdown formatting is not command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","reason":"The row explains environment-key requirements for start and stop. Its backticks are documentation formatting.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:348:ruby-shell-backtick-execution","reason":"The table describes a pre-existing CLI path and extra configuration. It neither executes those values nor introduces backtick substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:349:ruby-shell-backtick-execution","reason":"The row documents JSON merge behavior; earlier guidance requires reviewing overrides. Inline code does not invoke a shell.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","reason":"The match spans an output-field label and a workflow code fence. These are Markdown constructs, not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","reason":"The backticks delimit a YAML workflow, not command substitution. Mutable Action references and the missing trust gate are separate semantic findings.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:388:ruby-shell-backtick-execution","reason":"The match spans Markdown fences around workflow and concurrency examples. No executable backtick syntax exists.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:392:ruby-shell-backtick-execution","reason":"The YAML code block configures per-PR concurrency and cancellation. These settings are not shell commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","reason":"Closing and opening Markdown fences surround explanatory CI prose. They are not command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"The command demonstrates preview replacement with a fixed example image, key, and timeout. No shell backtick execution or injected argument appears.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:409:ruby-shell-backtick-execution","reason":"A closing fence precedes an explanation of the force flag. The matched backticks are formatting.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:411:ruby-shell-backtick-execution","reason":"The note explains replacing an existing preview during CI updates. Inline CLI names and flags do not execute shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:413:ruby-shell-backtick-execution","reason":"The cleanup example uses a numeric GitHub PR identifier in a quoted key. It contains no backtick substitution or free-text shell interpolation.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","reason":"The match spans Markdown fences and a sentence introducing key reuse. No shell execution occurs in the matched syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:419:ruby-shell-backtick-execution","reason":"The YAML fence defines a preview key using the numeric PR identifier. It does not execute a shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","reason":"A closing YAML fence precedes a lifecycle overview. Inline command names are documentation, not executable backticks.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","reason":"The prose summarizes expected preview creation and cleanup operations. It does not contain shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","reason":"The match formats a reference-workflow path and a section heading. No file or shell command is executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","reason":"The heading names extra_config before a YAML code fence. This is Markdown formatting, not shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","reason":"The fence contains a YAML Action example with timeout configuration. Its mutable Action reference is assessed separately, not as backtick execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","reason":"The closing YAML fence leads into TTL guidance. The backticks are documentation delimiters.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","reason":"The guidance explains TTL cleanup and explicitly warns that infinite TTL removes the fallback. Inline configuration values are not command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:450:ruby-shell-backtick-execution","reason":"This recommends expected preview cleanup on PR closure. Backticks format commands and Action values, not executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:451:ruby-shell-backtick-execution","reason":"The prose recommends per-PR keys and concurrency. Inline examples are Markdown, not shell commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:452:ruby-shell-backtick-execution","reason":"The line recommends concurrency cancellation settings. Backticks format configuration identifiers.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:461:ruby-shell-backtick-execution","reason":"The troubleshooting row lists feature and licensing prerequisites. Its formatted setting and skill name do not execute commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:462:ruby-shell-backtick-execution","reason":"The row discusses traffic filters and header propagation. The adjacent image-pull error is also documentation, not executable substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:463:ruby-shell-backtick-execution","reason":"The troubleshooting row names image-pull errors, a registry, and GITHUB_TOKEN. These are explanatory references without shell execution or token extraction.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:464:ruby-shell-backtick-execution","reason":"The row explains replacing a conflicting preview using force. Markdown CLI references are not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","reason":"The row suggests increasing the documented creation timeout. Configuration names and CLI flags are inline code, not shell expressions.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","reason":"The row explains accessing retained preview logs for troubleshooting. No external upload or shell substitution is instructed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:468:ruby-shell-backtick-execution","reason":"The row recommends TTLs and ordinary status or stop commands for cleanup. Its backticks are Markdown formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:469:ruby-shell-backtick-execution","reason":"The troubleshooting row describes share-ingress prerequisites and routing behavior. No executable shell expression appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","reason":"This describes local iteration with the same preview key and configuration overrides. Inline names are not command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","reason":"The table recommends a documented configuration mechanism and quotes a readiness error. Its backticks do not execute a shell.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","reason":"The row explains a target-readiness failure and supported queue-only cases. The formatted error is not executable syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","reason":"The row documents unsupported CronJob preview options. Inline configuration names do not execute commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:474:ruby-shell-backtick-execution","reason":"The row quotes a host-collision error and suggests changing keys. The following prerequisite guidance also uses ordinary Markdown formatting.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:479:ruby-shell-backtick-execution","reason":"The response guidance asks for prerequisite checks and target details. Backticks identify configuration fields, not executable substitutions.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","reason":"The line lists the target, image, and environment key needed for setup. Its inline CLI flags are documentation.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:481:ruby-shell-backtick-execution","reason":"The line asks for an explanation of traffic isolation and propagation. Backticks label the key and filter fields.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:482:ruby-shell-backtick-execution","reason":"The guideline requires teardown commands and a CI TTL. These are expected lifecycle instructions, without shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:483:ruby-shell-backtick-execution","reason":"The match spans configuration guidance and an example interaction. All backticks format identifiers rather than executable shell expressions.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:490:ruby-shell-backtick-execution","reason":"The example response asks for prerequisites before proposing a workflow. Backticks format settings and Action inputs, not shell commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:491:ruby-shell-backtick-execution","reason":"The example describes workflow generation using named Action inputs and a TTL. It contains no executable backtick substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:492:ruby-shell-backtick-execution","reason":"The example response requests a close-event cleanup job. Inline configuration values are Markdown, not shell execution.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:34:hardcoded-url","reason":"The URL points to vendor installation documentation while explicitly prohibiting remote pipe-to-shell installs. It is not an exfiltration destination.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:52:hardcoded-url","reason":"The hyperlink references vendor browser-extension documentation. The text does not send credentials or private data to it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:66:hardcoded-url","reason":"The URL is a vendor trial signup page, with user agreement explicitly required before starting a trial. No automatic data transmission is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:120:hardcoded-url","reason":"The URL contains placeholder slug and shareDomain values inside example CLI output. It is not a real network destination.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:175:hardcoded-url","reason":"The curl example targets the reserved example.com domain with a demonstration routing header. It sends no credentials or private payload.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:234:hardcoded-url","reason":"The URL links to vendor documentation about browser-based header injection. There is no exfiltration request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:286:hardcoded-url","reason":"The hyperlink identifies the documented GitHub Action repository. No sensitive data is sent by this reference.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:497:hardcoded-url","reason":"This is a vendor documentation link for preview environments. No network command or data upload accompanies it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:498:hardcoded-url","reason":"This links to vendor CI preview documentation. The URL is a reference, not an external collection endpoint.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:499:hardcoded-url","reason":"The link identifies the preview Action source repository. It does not transmit credentials or private files.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:500:hardcoded-url","reason":"The vendor documentation link explains the browser extension. No automatic request carrying sensitive data is specified.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:501:hardcoded-url","reason":"This is a reference link to a public example workflow. No upload or credential transfer is present.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:502:hardcoded-url","reason":"The URL points to vendor configuration documentation. It is not used as a data-exfiltration endpoint.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:427:hidden-file-access","reason":"The .github path names a reference workflow in another repository. It does not access local hidden files.","verdict":"false_positive","confidence":1},{"id":"filesystem:SKILL.md:501:hidden-file-access","reason":"The .github path occurs inside a public GitHub hyperlink. No filesystem read or write is performed.","verdict":"false_positive","confidence":1},{"id":"env_access:SKILL.md:463:git-platform-tokens","reason":"GITHUB_TOKEN is mentioned to explain private registry-package defaults. The text neither reads its value nor transmits it.","verdict":"false_positive","confidence":1},{"id":"sensitive:SKILL.md:265:certificate-key-files","reason":"The command provisions an explicitly named ingress TLS secret from placeholder certificate files. This is expected administrator setup, not secret discovery or exfiltration.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:67:system-reconnaissance","reason":"The table states that a valid kubeconfig is a prerequisite. It does not search for credentials or enumerate the system.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:355:system-reconnaissance","reason":"The sentence states that CI requires configured cluster authentication. It contains no reconnaissance command.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:390:system-reconnaissance","reason":"The sentence introduces workflow concurrency settings to prevent overlapping runs. It has no system-discovery behavior.","verdict":"false_positive","confidence":1}],"semantic_findings":[{"title":"Persistent Cluster Credentials in the Primary CI Example","severity":"medium","locations":[{"file":"SKILL.md","line_end":323,"line_start":294},{"file":"SKILL.md","line_end":333,"line_start":325}],"confidence":0.96,"description":"The setup creates a service-account-token Secret, extracts its token, and stores a reusable kubeconfig in CI. Unlike short-lived authentication, a stolen token remains usable until revoked, extending access to preview-management privileges.","confidence_reasoning":"The YAML explicitly creates a persistent service-account-token Secret and instructs storing its derived kubeconfig. OIDC is mentioned, but expiration and rotation are absent from this example."},{"title":"Mutable Action References in Credentialed CI Workflows","severity":"medium","locations":[{"file":"README.md","line_end":59,"line_start":45},{"file":"SKILL.md","line_end":387,"line_start":364},{"file":"SKILL.md","line_end":446,"line_start":433},{"file":"SKILL.md","line_end":64,"line_start":64}],"confidence":0.97,"description":"Examples execute metalbear-co/mirrord-preview@main after configuring cluster access. A changed or compromised branch can execute different code with those credentials; the default CLI download adds another unpinned dependency.","confidence_reasoning":"The examples use @main rather than immutable revisions and describe automatic installation of the latest CLI. This establishes a supply-chain exposure, not evidence that upstream code is malicious."},{"title":"Preview Workflow Omits the Required Trusted-PR Gate","severity":"high","locations":[{"file":"SKILL.md","line_end":377,"line_start":357},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":455,"line_start":455}],"confidence":0.85,"description":"The pull_request example starts previews whenever the event is not closed, without checking repository ownership or author approval. Where cluster credentials are available to fork jobs, copying this workflow can deploy untrusted PR images into the shared cluster.","confidence_reasoning":"The start condition lacks the trust check explicitly required elsewhere in the skill. Default GitHub fork-secret restrictions mitigate exposure, so exploitation depends on runner credentials and authentication configuration."},{"title":"Traffic Filters Do Not Enforce Complete Environment Keys","severity":"medium","locations":[{"file":"SKILL.md","line_end":145,"line_start":140},{"file":"SKILL.md","line_end":377,"line_start":375},{"file":"README.md","line_end":53,"line_start":51}],"confidence":0.96,"description":"The example regex accepts any suffix after alice-checkout-fix, while CI filters substitute a key without an ending boundary. A longer key sharing that prefix can match another preview filter and misroute requests, weakening the documented session isolation.","confidence_reasoning":"The ad-hoc regex explicitly ends its key match with .*, and the CI regex has no complete-member boundary. Prefix collisions follow directly from these documented regex patterns."}],"subject_marketplace_commit_sha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","subject_content_hash":"d312dce595adb9b42632433fafff435ef1a278d0bb0ac1e80c22a0b4b2773a69","subject_tree_hash":"08a04f1c0895961601a269c06d8793c922342be0534628fa2a8c05dfcd649dcf","subject_plugin_path":"skills/metalbear-co/mirrord-prev-env","audit_payload_hash":"7a4bde5effda237c73ed27bb0b0149b0","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","contentHash":"d312dce595adb9b42632433fafff435ef1a278d0bb0ac1e80c22a0b4b2773a69","treeHash":"08a04f1c0895961601a269c06d8793c922342be0534628fa2a8c05dfcd649dcf","pluginPath":"skills/metalbear-co/mirrord-prev-env","auditPayloadHash":"7a4bde5effda237c73ed27bb0b0149b0"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/metalbear-co-mirrord-prev-env/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":4,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}