{"data":{"skill":{"slug":"metalbear-co-mirrord-quickstart","name":"mirrord-quickstart","icon":"📦","repo":"https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-quickstart","status":"approved","author":"metalbear-co","authorVersion":"1.2","skillstoreRevision":1},"audit":{"id":"1c2d10db-a8cf-4a85-ba2b-ffbdf285fe60","skill_id":"709bfb44-52f1-4b05-827d-52577d724ca7","version":1,"content_hash":"v3:bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2:02f12e6af83d44ec8669a407677e014b0ae63ec4178079debad8b67eaa5c634e:5283bb33de0cc8341d3e5e3b475909340aad8715feb2baa9e667c9d5b73f192d:736b696c6c732f6d6574616c626561722d636f2f6d6972726f72642d717569636b7374617274:ba2ab04088314ebe728c87deb13846ba","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 19 static flags reflect Markdown formatting, legitimate prerequisite checks, or documentation links rather than the reported threats. A separate verification step risks exposing database credentials by printing remote environment values. No evidence found of prompt injection or intentional data exfiltration.","remediation":[{"issue":"The verification command prints remote environment values containing database-related text, which can expose credentials in terminal output or assistant logs.","severity":"medium","suggestion":"Replace value printing with a presence-only check for a user-approved variable, and prohibit copying secrets into logs or chat."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":32,"line_start":28},{"file":"SKILL.md","line_end":51,"line_start":32},{"file":"SKILL.md","line_end":53,"line_start":51},{"file":"SKILL.md","line_end":73,"line_start":53},{"file":"SKILL.md","line_end":85,"line_start":73},{"file":"SKILL.md","line_end":102,"line_start":85},{"file":"SKILL.md","line_end":105,"line_start":102},{"file":"SKILL.md","line_end":110,"line_start":105},{"file":"SKILL.md","line_end":111,"line_start":110},{"file":"SKILL.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":120,"line_start":112},{"file":"SKILL.md","line_end":137,"line_start":120},{"file":"SKILL.md","line_end":139,"line_start":137},{"file":"SKILL.md","line_end":140,"line_start":139}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":110,"line_start":110},{"file":"SKILL.md","line_end":112,"line_start":112}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Verification Can Expose Remote Database Credentials","locations":[{"file":"SKILL.md","line_end":105,"line_start":98}],"confidence":0.93,"description":"The verification example runs env and filters database-related lines, printing complete matching values. Database connection strings or passwords can enter terminal output and assistant logs.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The command explicitly prints remote environment values without redaction. Actual credential disclosure depends on the selected pod's environment."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":190,"audit_model":"codex","audited_at":"2026-09-29T22:05:23.452+00:00","created_at":"2026-09-30T13:39:15.988694+00:00","static_findings":[{"id":"blocker:README.md:26:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"Use the [official installation guide](https://mirrord.dev/docs/overview/quick-start/) — avoid downlo","category":"blocker","line_end":26,"severity":"low","line_start":26},{"id":"blocker:README.md:8:network-reconnaissance","file":"README.md","pattern":"Network reconnaissance","snippet":"- **Requirements** — verify kubectl and cluster access","category":"blocker","line_end":9,"severity":"low","line_start":8},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":32,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":51,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":53,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":73,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":85,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":102,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":105,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":110,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`mirrord ui`** — launches a local dashboard showing every active session on the machine, with a ","category":"external_commands","line_end":111,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`mirrord up`** — for debugging several microservices together from one `mirrord-up.yaml` (compos","category":"external_commands","line_end":111,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Browser extension** — routes requests made from Chrome to the local process, for testing an HTTP","category":"external_commands","line_end":120,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"No pods found\" | Check namespace: `kubectl get pods -n <namespace>` |","category":"external_commands","line_end":137,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Check: `kubectl cluster-info` working?","category":"external_commands","line_end":139,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Run: `mirrord ls` to see targets","category":"external_commands","line_end":140,"severity":"medium","line_start":139},{"id":"network:SKILL.md:42:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Official guide:** Follow [mirrord installation documentation](https://mirrord.dev/docs/overview/qu","category":"network","line_end":42,"severity":"low","line_start":42},{"id":"network:SKILL.md:110:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **`mirrord ui`** — launches a local dashboard showing every active session on the machine, with a ","category":"network","line_end":110,"severity":"low","line_start":110},{"id":"network:SKILL.md:112:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Browser extension** — routes requests made from Chrome to the local process, for testing an HTTP","category":"network","line_end":112,"severity":"low","line_start":112}],"finding_verdicts":[{"id":"blocker:README.md:26:system-reconnaissance","reason":"The line recommends official installation methods and checksum verification while discouraging remote shell scripts. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:README.md:8:network-reconnaissance","reason":"The text describes checking kubectl and existing cluster access as onboarding prerequisites. It does not instruct network scanning or unauthorized discovery.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"These backticks delimit a Markdown code block containing read-only kubectl prerequisite checks. They are not executable shell substitutions or Ruby expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown block, followed by installation guidance that explicitly forbids downloaded script execution. No backtick execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The Markdown block contains only mirrord --version, a normal installation check. The fence is not shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The match is a closing Markdown fence followed by ordinary IDE installation instructions. No Ruby or shell backtick execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The fenced examples list mirrord targets and launch the user's local application, matching the stated purpose. Markdown fences do not execute commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The matched delimiter closes a Markdown example before IDE and verification instructions. It is not a shell execution operator.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The backticks open a Markdown code fence, not command substitution. The enclosed environment-printing command has a separate credential-exposure finding below.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The matched line closes the verification code fence and is not executable syntax. Credential exposure from its contents is assessed separately.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"Inline backticks format mirrord ui and mirrord up as command names in explanatory text. They do not implement shell or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"Inline code spans identify a command and configuration filename for an optional workflow. No executable backtick expression is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"Backticks format curl and a namespace troubleshooting command within Markdown prose. Optional browser routing and consent-based trial guidance do not establish backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The table formats a read-only kubectl pod query as inline code for troubleshooting. Subsequent response guidance contains no shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The example formats cluster-info and target listing commands as Markdown code spans. These are expected connectivity checks, not executable backtick expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"Inline code describes listing targets and running the user's application against a selected pod. Markdown backticks are not shell command substitution.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:42:hardcoded-url","reason":"The URL points to mirrord installation documentation within guidance requiring approved installation methods. No credential submission or external upload is instructed.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:110:hardcoded-url","reason":"The MetalBear URL is a documentation reference for the local dashboard. The text does not send session events to that URL.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:112:hardcoded-url","reason":"The MetalBear URL links to browser debugging documentation. It is not presented as a destination for credentials or application data.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Verification Can Expose Remote Database Credentials","severity":"medium","locations":[{"file":"SKILL.md","line_end":105,"line_start":98}],"confidence":0.93,"description":"The verification example runs env and filters database-related lines, printing complete matching values. Database connection strings or passwords can enter terminal output and assistant logs.","confidence_reasoning":"The command explicitly prints remote environment values without redaction. Actual credential disclosure depends on the selected pod's environment."}],"subject_marketplace_commit_sha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","subject_content_hash":"02f12e6af83d44ec8669a407677e014b0ae63ec4178079debad8b67eaa5c634e","subject_tree_hash":"5283bb33de0cc8341d3e5e3b475909340aad8715feb2baa9e667c9d5b73f192d","subject_plugin_path":"skills/metalbear-co/mirrord-quickstart","audit_payload_hash":"ba2ab04088314ebe728c87deb13846ba","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","contentHash":"02f12e6af83d44ec8669a407677e014b0ae63ec4178079debad8b67eaa5c634e","treeHash":"5283bb33de0cc8341d3e5e3b475909340aad8715feb2baa9e667c9d5b73f192d","pluginPath":"skills/metalbear-co/mirrord-quickstart","auditPayloadHash":"ba2ab04088314ebe728c87deb13846ba"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/metalbear-co-mirrord-quickstart/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}