{"data":{"skill":{"slug":"metalbear-co-mirrord-temporal","name":"mirrord-temporal","icon":"📦","repo":"https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-temporal","status":"approved","author":"metalbear-co","authorVersion":"1.2","skillstoreRevision":1},"audit":{"id":"fd024a8f-72a7-4c7b-8ccc-c7e28394b612","skill_id":"d084ddb6-df2f-4a6f-8bd6-d520984f00c6","version":1,"content_hash":"v3:bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2:e3b0415e974a1e241bfb971ef08eaf280c13052fef9a4f4d23ead019fad0225e:183a575ea156425185d3bbb74b4d76be23d7ea4c7eb14eadb02d50ebeab950ad:736b696c6c732f6d6574616c626561722d636f2f6d6972726f72642d74656d706f72616c:20458bed85decf4cbc7ddf5133b93626","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"The static matches are mostly false positives caused by Markdown backticks, shell examples, placeholder certificate names, and secret-reference documentation. The skill still presents operational risk because it permits broad cluster discovery and mentions agent-directed operator installation, which require explicit authorization and least-privilege controls.","remediation":[{"issue":"The skill allows an AI agent to offer a trial and install the mirrord operator after user agreement.","severity":"high","suggestion":"Require a separate explicit confirmation before any cluster change, show the exact commands, and verify namespace, RBAC scope, chart source, and rollback steps."},{"issue":"Auto-discovery queries workloads, services, CRDs, and resources across all namespaces.","severity":"medium","suggestion":"Make discovery opt-in, limit it to named namespaces and resources, use least-privilege RBAC, and redact returned configuration before displaying it."},{"issue":"Credential and certificate examples could be copied into generated configuration incorrectly.","severity":"high","suggestion":"Keep all credential examples non-secret, require Kubernetes secret references, and warn users not to paste secret values into prompts or generated output."},{"issue":"Task routing and immediate teardown can affect production work.","severity":"medium","suggestion":"Recommend non-production testing, explicit filter review, bounded buffering, and a nonzero drain timeout when in-flight work must be preserved."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":77,"line_start":62},{"file":"SKILL.md","line_end":79,"line_start":77},{"file":"SKILL.md","line_end":82,"line_start":79},{"file":"SKILL.md","line_end":85,"line_start":82},{"file":"SKILL.md","line_end":91,"line_start":85},{"file":"SKILL.md","line_end":92,"line_start":91},{"file":"SKILL.md","line_end":97,"line_start":92},{"file":"SKILL.md","line_end":101,"line_start":97},{"file":"SKILL.md","line_end":109,"line_start":101},{"file":"SKILL.md","line_end":115,"line_start":109},{"file":"SKILL.md","line_end":122,"line_start":115},{"file":"SKILL.md","line_end":123,"line_start":122},{"file":"SKILL.md","line_end":123,"line_start":123},{"file":"SKILL.md","line_end":124,"line_start":124},{"file":"SKILL.md","line_end":125,"line_start":125},{"file":"SKILL.md","line_end":126,"line_start":126},{"file":"SKILL.md","line_end":142,"line_start":129},{"file":"SKILL.md","line_end":144,"line_start":142},{"file":"SKILL.md","line_end":152,"line_start":144},{"file":"SKILL.md","line_end":152,"line_start":152},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":154,"line_start":154},{"file":"SKILL.md","line_end":155,"line_start":155},{"file":"SKILL.md","line_end":156,"line_start":156},{"file":"SKILL.md","line_end":157,"line_start":157},{"file":"SKILL.md","line_end":183,"line_start":159},{"file":"SKILL.md","line_end":185,"line_start":183},{"file":"SKILL.md","line_end":185,"line_start":185},{"file":"SKILL.md","line_end":191,"line_start":189},{"file":"SKILL.md","line_end":192,"line_start":191},{"file":"SKILL.md","line_end":205,"line_start":192},{"file":"SKILL.md","line_end":206,"line_start":205},{"file":"SKILL.md","line_end":208,"line_start":206},{"file":"SKILL.md","line_end":209,"line_start":208},{"file":"SKILL.md","line_end":210,"line_start":209},{"file":"SKILL.md","line_end":211,"line_start":210},{"file":"SKILL.md","line_end":211,"line_start":211},{"file":"SKILL.md","line_end":214,"line_start":214},{"file":"SKILL.md","line_end":217,"line_start":216},{"file":"SKILL.md","line_end":230,"line_start":217},{"file":"SKILL.md","line_end":231,"line_start":230}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84}]}],"critical_findings":[],"high_findings":[{"title":"Agent-Directed Cluster Installation","locations":[{"file":"SKILL.md","line_end":79,"line_start":79}],"confidence":0.9,"description":"The skill tells an AI agent that it may start a trial and install the mirrord operator after user agreement. Installing an operator changes cluster state and can grant broad control-plane access, so the action requires explicit confirmation and least-privilege review.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The instruction explicitly describes starting a trial and installing an operator. The operational impact is clear, although it requires user agreement and refers to another skill for the procedure."}],"medium_findings":[{"title":"Broad Cluster Discovery","locations":[{"file":"SKILL.md","line_end":84,"line_start":62}],"confidence":0.82,"description":"The discovery workflow queries namespaces, workloads, CRDs, resources across all namespaces, deployment YAML, and services. These read-only queries can expose cluster topology and configuration metadata, so output handling and RBAC scope require controls.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The referenced commands visibly inspect multiple cluster-wide resource types. They are read-only, but the breadth of metadata access creates a confidentiality and least-privilege concern."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":604,"audit_model":"codex","audited_at":"2026-09-29T22:08:36.088+00:00","created_at":"2026-09-30T13:39:28.592852+00:00","static_findings":[{"id":"sensitive:references/temporal-property-list.md:86:certificate-key-files","file":"references/temporal-property-list.md","pattern":"Certificate/key files","snippet":"key: ca.crt","category":"sensitive","line_end":86,"severity":"high","line_start":86},{"id":"sensitive:references/temporal-property-list.md:91:certificate-key-files","file":"references/temporal-property-list.md","pattern":"Certificate/key files","snippet":"key: tls.crt","category":"sensitive","line_end":91,"severity":"high","line_start":91},{"id":"sensitive:references/temporal-property-list.md:96:certificate-key-files","file":"references/temporal-property-list.md","pattern":"Certificate/key files","snippet":"key: tls.key","category":"sensitive","line_end":96,"severity":"high","line_start":96},{"id":"sensitive:references/temporal-property-list.md:103:certificate-key-files","file":"references/temporal-property-list.md","pattern":"Certificate/key files","snippet":"--from-file=ca.crt=./ca.crt \\","category":"sensitive","line_end":103,"severity":"high","line_start":103},{"id":"sensitive:references/temporal-property-list.md:104:certificate-key-files","file":"references/temporal-property-list.md","pattern":"Certificate/key files","snippet":"--from-file=tls.crt=./client.crt \\","category":"sensitive","line_end":104,"severity":"high","line_start":104},{"id":"sensitive:references/temporal-property-list.md:105:certificate-key-files","file":"references/temporal-property-list.md","pattern":"Certificate/key files","snippet":"--from-file=tls.key=./client.key","category":"sensitive","line_end":105,"severity":"high","line_start":105},{"id":"sensitive:references/temporal-property-list.md:23:crypto-seed-private-key-mention","file":"references/temporal-property-list.md","pattern":"Crypto seed/private key mention","snippet":"| `tlsClientKey`  | PEM private key for `tlsClientCert`. Requires `tlsClientCert`. | No | |","category":"sensitive","line_end":23,"severity":"high","line_start":23},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Temporal splitting is configured with **`MirrordSplitConfig`** (which task queues to split + how t","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **No hardcoded credentials:** Never include actual Temporal Cloud API keys, TLS certificates, or p","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Secret creation guidance:** When telling the user to create a Secret, instruct `kubectl create s","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Input sanitization:** Treat all user-provided values (namespaces, workload/container names, env ","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Command execution safeguards:** Auto-discovery `kubectl get` / `kubectl config` calls are read-o","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Helm values** — enable `operator.temporalSplitting` (and optionally set the proxy port)","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **mirrord.json** — the `feature.split_queues` section developers use to filter tasks (`message_fi","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/temporal-property-list.md` — `MirrordPropertyList` field spec for Temporal: connection","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/temporal-split-config.md` — `MirrordSplitConfig` field spec for `kind: temporal` queue","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":77,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":79,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the operator is missing and the cluster has no mirrord for Teams license, an AI agent can offer t","category":"external_commands","line_end":82,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":85,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":91,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For `MirrordPropertyList`:","category":"external_commands","line_end":92,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Temporal frontend address (`host:port` or full URL) and Temporal namespace","category":"external_commands","line_end":97,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For `MirrordSplitConfig`:","category":"external_commands","line_end":101,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The `MirrordPropertyList` name to reference","category":"external_commands","line_end":109,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":115,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":122,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Default to the target workload's namespace** (same namespace as its `MirrordSplitConfig`) — the ","category":"external_commands","line_end":123,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `address` and `namespace` are **required**. A bare `host:port` address gets its scheme from the `t","category":"external_commands","line_end":123,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `valueFrom.secretKeyRef` for any credential (`apiKey`, `tlsClientCert`, `tlsClientKey`, and ty","category":"external_commands","line_end":124,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Setting any `tls*` property implies `tls: \"true\"`. `tlsClientCert` and `tlsClientKey` always go to","category":"external_commands","line_end":125,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Temporal Cloud with an API key needs only `tls: \"true\"` + `apiKey` (publicly trusted cert). A priv","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":142,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":144,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See `references/temporal-property-list.md` for the full property table, Temporal Cloud, and mTLS exa","category":"external_commands","line_end":152,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `spec.targetRef` = `{ apiVersion, kind, name }` (Deployment/StatefulSet/Rollout).","category":"external_commands","line_end":152,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Each `spec.queues[]` needs `id`, `kind: temporal`, a `clientConfig` (the `MirrordPropertyList` nam","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `appConfig.temporalAddress` (optional) names the env var holding the frontend address — the operat","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Each `appConfig` field uses the same source structure as other queue services: `env`, `envLike`, `","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Per-queue Temporal options (`max_buffered_tasks`) live in a separate `MirrordPropertyList` referen","category":"external_commands","line_end":156,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `spec.drainTimeout` (seconds) keeps the split's temporary resources alive after the last session e","category":"external_commands","line_end":157,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":183,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":185,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The operator can only read the worker's env vars if they are defined directly in the pod template (`","category":"external_commands","line_end":185,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Show the developer-facing config referencing the queue IDs. Temporal uses `queue_type: \"Temporal\"`. ","category":"external_commands","line_end":191,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Filter on task metadata (`message_filter`):**","category":"external_commands","line_end":192,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":205,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":206,"severity":"medium","line_start":205},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Supported `message_filter` keys — each maps a key to a regex, and **all** specified entries must mat","category":"external_commands","line_end":208,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workflow_id` — the workflow ID","category":"external_commands","line_end":209,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `workflow_type` — the workflow type name","category":"external_commands","line_end":210,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `activity_type` — the activity type name","category":"external_commands","line_end":211,"severity":"medium","line_start":210},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `header.<name>` — a Temporal header value (e.g. `header.x-user`)","category":"external_commands","line_end":211,"severity":"medium","line_start":211},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"An empty `message_filter: {}` with no `jq_filter` is **match-none** (the local worker gets zero task","category":"external_commands","line_end":214,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Filter on task content (`jq_filter`):**","category":"external_commands","line_end":217,"severity":"medium","line_start":216},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":230,"severity":"medium","line_start":217},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":231,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`jq_filter` runs a jq program over a JSON doc the operator builds per task. Every doc has `task_type","category":"external_commands","line_end":231,"severity":"medium","line_start":231},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Activity tasks:** `workflow_namespace`, `workflow_id`, `run_id`, `workflow_type`, `activity_type","category":"external_commands","line_end":233,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Workflow tasks:** `workflow_id`, `run_id`, `workflow_type`, `attempt`, `task_queue`, `cron_sched","category":"external_commands","line_end":234,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A task matches if the program outputs `true`.","category":"external_commands","line_end":239,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`queue_mode: \"mirror\"` is not supported for Temporal** — a Temporal task is always stolen (only ","category":"external_commands","line_end":240,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If both `message_filter` and `jq_filter` are set, **both** must match.","category":"external_commands","line_end":240,"severity":"medium","line_start":240},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For multiple queues (or the same ID on multiple brokers), use the array form with `queue_id` per e","category":"external_commands","line_end":242,"severity":"medium","line_start":241},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- With `operator.injectSessionKeyHeader` enabled, tasks routed to a session are stamped with a `mirr","category":"external_commands","line_end":242,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] `MirrordPropertyList` (in the target's namespace, or the operator's namespace if sharing) has ","category":"external_commands","line_end":249,"severity":"medium","line_start":249},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] `tlsClientCert` and `tlsClientKey` are either both set or both absent.","category":"external_commands","line_end":250,"severity":"medium","line_start":250},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] No inline credential values — `apiKey` and TLS material come from `secretKeyRef`.","category":"external_commands","line_end":251,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] `MirrordSplitConfig` is in the target's namespace with `spec.targetRef` (`apiVersion`, `kind`,","category":"external_commands","line_end":252,"severity":"medium","line_start":252},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] Each queue has `id`, `kind: temporal`, a `clientConfig` (or `spec.clientConfigs.temporal`), an","category":"external_commands","line_end":253,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] `kind` (targetRef) is one of `Deployment`, `StatefulSet`, `Rollout`.","category":"external_commands","line_end":254,"severity":"medium","line_start":254},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] Each queue's `clientConfig` resolves to a `MirrordPropertyList`, looked up in the target's nam","category":"external_commands","line_end":258,"severity":"medium","line_start":258},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] mirrord.json `target` matches the `MirrordSplitConfig` `targetRef`.","category":"external_commands","line_end":259,"severity":"medium","line_start":259},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] mirrord.json entries use `queue_type: \"Temporal\"` and **no** `queue_mode: \"mirror\"`.","category":"external_commands","line_end":260,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [ ] Env vars named in `appConfig` are readable by the operator (pod template `value`/ConfigMap `va","category":"external_commands","line_end":261,"severity":"medium","line_start":261},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Vault-injected env vars → operator can't read them as env vars; move the task queue name into the ","category":"external_commands","line_end":266,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Long local debugging pauses → buffered tasks accumulate; suggest capping with `max_buffered_tasks`","category":"external_commands","line_end":268,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `drainTimeout: 0` / unset → immediate teardown; in-flight work may be lost.","category":"external_commands","line_end":271,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":275,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":279,"severity":"medium","line_start":275},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Full setup:** brief overview of the 2 resources → `MirrordPropertyList` YAML → `MirrordSplitConfig","category":"external_commands","line_end":279,"severity":"medium","line_start":279},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Troubleshooting:** ask for the operator version (`kubectl get deploy mirrord-operator -n mirrord -","category":"external_commands","line_end":281,"severity":"medium","line_start":281},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**\"Set up Temporal splitting for my worker\"** → ask for frontend address + namespace, auth, workload","category":"external_commands","line_end":285,"severity":"medium","line_start":285},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**\"We use Temporal Cloud\"** → `address` = `<ns>.<id>.tmprl.cloud:7233`, `namespace` = `<ns>.<id>`, `","category":"external_commands","line_end":287,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**\"Our frontend uses a private CA / mTLS\"** → `tlsCaCert` for the private CA; add `tlsClientCert` + ","category":"external_commands","line_end":289,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**\"Only route my test workflows to my laptop\"** → `message_filter` on `workflow_id` (e.g. `\"^test-lo","category":"external_commands","line_end":291,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**\"Filter on a workflow's input payload\"** → `jq_filter` over `.input`, e.g. `(.input[0] | fromjson ","category":"external_commands","line_end":293,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**\"Tasks pile up while I'm on a breakpoint\"** → set `max_buffered_tasks` in a `queueConfig` property","category":"external_commands","line_end":297,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Don't offer `queue_mode: \"mirror\"` for Temporal — it's not supported; Temporal tasks are steal-onl","category":"external_commands","line_end":303,"severity":"medium","line_start":302},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Don't use `kind: kafka` field names (`topic`, `groupId`, `appId`) in a Temporal queue — Temporal u","category":"external_commands","line_end":303,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Don't set only one of `tlsClientCert`/`tlsClientKey` — the split fails at start.","category":"external_commands","line_end":304,"severity":"medium","line_start":304},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Don't inline API keys or PEM material in the YAML — always `secretKeyRef`.","category":"external_commands","line_end":306,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Don't default a `MirrordPropertyList` to the operator's namespace — the target's namespace is the ","category":"external_commands","line_end":307,"severity":"medium","line_start":306},{"id":"filesystem:SKILL.md:64:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl cluster-info 2>/dev/null | head -5","category":"filesystem","line_end":64,"severity":"low","line_start":64},{"id":"filesystem:SKILL.md:67:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get ns mirrord --no-headers 2>/dev/null","category":"filesystem","line_end":67,"severity":"low","line_start":67},{"id":"filesystem:SKILL.md:68:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get deploy mirrord-operator -n mirrord --no-headers 2>/dev/null","category":"filesystem","line_end":68,"severity":"low","line_start":68},{"id":"filesystem:SKILL.md:71:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get crd mirrordsplitconfigs.queues.mirrord.metalbear.co --no-headers 2>/dev/null","category":"filesystem","line_end":71,"severity":"low","line_start":71},{"id":"filesystem:SKILL.md:72:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get crd mirrordpropertylists.mirrord.metalbear.co --no-headers 2>/dev/null","category":"filesystem","line_end":72,"severity":"low","line_start":72},{"id":"filesystem:SKILL.md:75:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get mirrordsplitconfigs --all-namespaces --no-headers 2>/dev/null","category":"filesystem","line_end":75,"severity":"low","line_start":75},{"id":"filesystem:SKILL.md:76:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get mirrordpropertylists --all-namespaces --no-headers 2>/dev/null","category":"filesystem","line_end":76,"severity":"low","line_start":76},{"id":"filesystem:SKILL.md:83:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get deployment/<name> -n <ns> -o yaml 2>/dev/null   # or statefulset / rollout","category":"filesystem","line_end":83,"severity":"low","line_start":83},{"id":"filesystem:SKILL.md:84:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"kubectl get svc --all-namespaces --no-headers 2>/dev/null | grep -i temporal","category":"filesystem","line_end":84,"severity":"low","line_start":84},{"id":"sensitive:SKILL.md:26:crypto-seed-private-key-mention","file":"SKILL.md","pattern":"Crypto seed/private key mention","snippet":"- **No hardcoded credentials:** Never include actual Temporal Cloud API keys, TLS certificates, or p","category":"sensitive","line_end":26,"severity":"high","line_start":26}],"finding_verdicts":[{"id":"sensitive:references/temporal-property-list.md:86:certificate-key-files","reason":"The match is a placeholder Kubernetes Secret key named ca.crt in documentation. No certificate value is present, and the surrounding example uses secretKeyRef.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/temporal-property-list.md:91:certificate-key-files","reason":"The match is a placeholder Kubernetes Secret key named tls.crt in documentation. It describes secret-backed configuration and does not disclose certificate material.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/temporal-property-list.md:96:certificate-key-files","reason":"The match is a placeholder Kubernetes Secret key named tls.key in documentation. The example references a Secret and contains no private-key value.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/temporal-property-list.md:103:certificate-key-files","reason":"The match is a documented kubectl from-file argument using a local placeholder path. It instructs users to load key material from files without embedding the material.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/temporal-property-list.md:104:certificate-key-files","reason":"The match is a documented kubectl from-file argument using a local placeholder path. It does not contain a certificate and explicitly avoids inline credential values.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/temporal-property-list.md:105:certificate-key-files","reason":"The match is a documented kubectl from-file argument using a local placeholder path. It does not expose a private key or instruct the agent to collect one.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/temporal-property-list.md:23:crypto-seed-private-key-mention","reason":"The line documents the tlsClientKey property and requires it to be supplied through a Kubernetes Secret. It contains no key material and warns against inline credentials.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The detector matched Markdown backticks around configuration names in prose. This line does not execute Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around credential terms. This is security guidance, not executable Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a documented kubectl command. The line presents user-reviewed guidance and is not Ruby backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around input names and a regular expression. This line contains validation guidance, not executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around kubectl commands. The line explicitly restricts discovery to read-only calls and forbids unattended cluster changes.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a Helm value key. This is configuration documentation and does not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around configuration fields. This line describes generated configuration and contains no executable Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The detector matched Markdown code spans containing a reference filename and resource name. This is a file reference, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The detector matched Markdown code spans containing a reference filename and resource name. The line is descriptive documentation, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The match is the start of a Markdown shell code block. A code block documents commands for review and does not itself provide Ruby backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block boundary after read-only kubectl examples. It is formatting, not an executable command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a skill name. This prose discusses a possible workflow and contains no shell execution syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The match is the start of a Markdown shell code block containing an illustrative kubectl command. The formatting does not execute the command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block boundary after read-only discovery examples. It is documentation formatting, not external command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The detector matched Markdown code spans around a configuration resource name. This heading contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The detector matched Markdown code spans around configuration fields. This line asks for connection context and does not execute external code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The detector matched Markdown code spans around a configuration resource name. This heading is descriptive documentation, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a resource name. The line requests a reference name and contains no executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The match is the start of a YAML code block showing configuration. It is an example for user review, not Ruby or shell execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block boundary after a YAML example. It does not execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around resource names and versions in configuration guidance. This prose is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around address and namespace fields. This line defines validation requirements and does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around configuration fields. The guidance recommends secret references and contains no command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around TLS field names. This is configuration validation guidance, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around TLS and API key field names. The line contains safe configuration guidance, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The match is the start of a YAML configuration example. Markdown code formatting does not execute the shown resource definition.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a reference filename. This line points to documentation and contains no external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around connection and frontend terms. This is explanatory prose, not executable shell or Ruby code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around target reference fields. This line documents a resource schema and does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around resource fields. This is configuration guidance and contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around application configuration fields. The line describes patching behavior and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around source field names and versions. This line defines accepted configuration sources, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around queue configuration names. This is a resource schema note and does not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a field name and numeric value. This line explains lifecycle behavior and is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The match is the start of a YAML resource example. It is documentation formatting and does not execute a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The match is the end of a YAML example and adjacent prose formatting. It is not Ruby backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around pod and operator terms. This line explains visibility limits and contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around configuration names. This line describes filter configuration and does not execute external code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The detector matched Markdown around a filter name. This is a section heading and contains no executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a filter field. This line explains metadata matching and is not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","reason":"The match is the end of a JSON example. It is Markdown formatting for user configuration and does not execute code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around filter fields. This line documents supported keys and contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a metadata key. This is a list item describing filter semantics, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a metadata key. The line contains descriptive configuration guidance only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a metadata key. This is documentation for filtering and does not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a header key. The line describes a filter input and contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around an empty filter value. This line explains matching behavior and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","reason":"The detector matched Markdown around a filter name. This is a section heading and contains no executable shell or Ruby code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","reason":"The match is the start of a JSON configuration example. It is documentation formatting and does not execute the example.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"The match is the end of a JSON example. It is Markdown formatting, not external command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a jq field name. This line explains data passed to a filter and does not execute shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around activity task fields. This is a data schema list, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around workflow task fields. This is a data schema list and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a Boolean result. This line describes filter semantics and contains no external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a queue mode value. This is a warning about unsupported configuration, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around filter names. This line explains matching logic and does not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around queue fields. This is configuration advice and contains no executable shell or Ruby code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a header setting and field name. This line documents routing behavior and does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This checklist item describes a resource location and contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item checks paired certificate settings and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item requires secret references and contains no executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item describes a Kubernetes resource relationship, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item checks required fields and contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item lists permitted workload kinds and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item explains resource resolution and contains no executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item checks configuration references and does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item checks queue settings and contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown in a validation checklist. This item explains environment visibility and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a source type and version. This warning is descriptive guidance, not external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a field name. This warning describes buffering behavior and contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a field value. This warning explains teardown behavior and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block boundary for an output format example. It is documentation formatting, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block boundary after an output format example. It does not execute external code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around resource names. This response-format guidance is prose, not executable shell or Ruby code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around kubectl and mirrord commands in troubleshooting guidance. The line documents commands for review and does not itself execute them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a user scenario. This line describes information gathering and contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around Temporal Cloud values and field names. This scenario guidance is not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around TLS field names. This scenario describes secret-backed configuration and does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a filter field. This scenario gives a routing example and contains no external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a filter field and payload path. This is a jq configuration example, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a buffering field. This scenario provides configuration advice and does not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around a queue mode value. This safety rule is prose and contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around configuration field names. This rule prevents invalid configuration and does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around TLS field names. This rule explains required pairing and contains no executable shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around credential fields. This rule explicitly forbids inline secrets and does not execute external code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","reason":"The detector matched inline Markdown around namespaces and versions. This rule describes resource placement and contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:64:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only kubectl example. It is not an independent filesystem operation performed by the skill.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:67:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only kubectl example. The skill provides guidance rather than executing the command.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:68:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only kubectl example. It does not indicate arbitrary filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:71:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only CRD query. It is command-example formatting, not filesystem abuse.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:72:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only CRD query. It does not represent arbitrary file access by the skill.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:75:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only resource query. It is not a malicious filesystem operation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:76:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only resource query. It does not indicate arbitrary filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:83:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only workload inspection command. This is not arbitrary filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:84:standard-device-file-access","reason":"The match is shell redirection to /dev/null in a documented read-only service query. It does not represent filesystem abuse by the skill.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:26:crypto-seed-private-key-mention","reason":"The line explicitly forbids hardcoded API keys, certificates, and private keys. It directs generated resources to use Kubernetes Secret references and contains no secret value.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Agent-Directed Cluster Installation","severity":"high","locations":[{"file":"SKILL.md","line_end":79,"line_start":79}],"confidence":0.9,"description":"The skill tells an AI agent that it may start a trial and install the mirrord operator after user agreement. Installing an operator changes cluster state and can grant broad control-plane access, so the action requires explicit confirmation and least-privilege review.","confidence_reasoning":"The instruction explicitly describes starting a trial and installing an operator. The operational impact is clear, although it requires user agreement and refers to another skill for the procedure."},{"title":"Broad Cluster Discovery","severity":"medium","locations":[{"file":"SKILL.md","line_end":84,"line_start":62}],"confidence":0.82,"description":"The discovery workflow queries namespaces, workloads, CRDs, resources across all namespaces, deployment YAML, and services. These read-only queries can expose cluster topology and configuration metadata, so output handling and RBAC scope require controls.","confidence_reasoning":"The referenced commands visibly inspect multiple cluster-wide resource types. They are read-only, but the breadth of metadata access creates a confidentiality and least-privilege concern."}],"subject_marketplace_commit_sha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","subject_content_hash":"e3b0415e974a1e241bfb971ef08eaf280c13052fef9a4f4d23ead019fad0225e","subject_tree_hash":"183a575ea156425185d3bbb74b4d76be23d7ea4c7eb14eadb02d50ebeab950ad","subject_plugin_path":"skills/metalbear-co/mirrord-temporal","audit_payload_hash":"20458bed85decf4cbc7ddf5133b93626","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2","contentHash":"e3b0415e974a1e241bfb971ef08eaf280c13052fef9a4f4d23ead019fad0225e","treeHash":"183a575ea156425185d3bbb74b4d76be23d7ea4c7eb14eadb02d50ebeab950ad","pluginPath":"skills/metalbear-co/mirrord-temporal","auditPayloadHash":"20458bed85decf4cbc7ddf5133b93626"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/metalbear-co-mirrord-temporal/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}