{"data":{"skill":{"slug":"microsoft-azure-deploy","name":"azure-deploy","icon":"📦","repo":"https://github.com/microsoft/github-copilot-for-azure/tree/main/plugin/skills/azure-deploy/","status":"approved","author":"microsoft","authorVersion":"0.0.0-placeholder","skillstoreRevision":2},"audit":{"id":"6c26715b-79a7-4d8e-b444-4be47ecdfcc0","skill_id":"47e443a7-3384-4c95-bb6c-803f187674b6","version":5,"content_hash":"v3:ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006:daa23eea47cd37110b5ceab709592d2cd8758520264dd03121896ebea2fdc80d:b70b80d44814300b9bf8f5ca762033ac622504e687ea32579e33cdcb7fe2f776:736b696c6c732f6d6963726f736f66742f617a7572652d6465706c6f79:0078625b838a723cc1731ebcba16800e","risk_level":"critical","is_blocked":true,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"blocked","manual_install_policy":"allowed_with_warning","summary":"Most findings are false positives from Markdown formatting, relative links, project .azure paths, read-only Azure queries, and documented environment identifiers. Confirmed risks include unsafe shell evaluation, command-line registry password exposure, and a remote installer piped to Bash. Additional concerns include mutable dependencies, broad SQL schema privileges, and unvalidated health-check targets.","remediation":[{"issue":"Remote installer content is executed without verification.","severity":"critical","suggestion":"Use a trusted package manager or download a pinned release, verify its checksum and signature, then execute the reviewed artifact."},{"issue":"AZD environment output is evaluated as shell code.","severity":"high","suggestion":"Replace every eval example with a line parser that validates variable names and exports quoted values."},{"issue":"The ACR administrator password is passed on the command line.","severity":"high","suggestion":"Prefer managed identity or Azure authentication. When a password is unavoidable, use password-stdin and prevent logging."},{"issue":"The application runtime identity receives database schema-administration rights.","severity":"high","suggestion":"Use a separate migration identity with temporary DDL rights. Give the runtime identity only required data permissions."},{"issue":"Health checks trust endpoints read from project state.","severity":"high","suggestion":"Validate HTTPS endpoints against expected deployed resource hosts. Require confirmation before requesting private, local, or non-Azure targets."},{"issue":"Deployment actions, CLI extensions, and global tools are not immutably pinned.","severity":"high","suggestion":"Pin GitHub Actions to commit SHAs and tools to reviewed versions. Verify provenance before installation."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/auth-best-practices.md","line_end":16,"line_start":16},{"file":"references/auth-best-practices.md","line_end":81,"line_start":81},{"file":"references/auth-best-practices.md","line_end":87,"line_start":87},{"file":"references/live-role-verification.md","line_end":102,"line_start":97},{"file":"references/pre-deploy-checklist.md","line_end":122,"line_start":121},{"file":"references/pre-deploy-checklist.md","line_end":182,"line_start":181},{"file":"references/pre-deploy-checklist.md","line_end":323,"line_start":322},{"file":"references/pre-deploy-checklist.md","line_end":326,"line_start":324},{"file":"references/pre-deploy-checklist.md","line_end":328,"line_start":327},{"file":"references/pre-deploy-checklist.md","line_end":349,"line_start":348},{"file":"references/pre-deploy-checklist.md","line_end":366,"line_start":365},{"file":"references/pre-deploy-checklist.md","line_end":400,"line_start":399},{"file":"references/pre-deploy-checklist.md","line_end":417,"line_start":401},{"file":"references/pre-deploy-checklist.md","line_end":342,"line_start":339},{"file":"references/pre-deploy-checklist.md","line_end":359,"line_start":356},{"file":"references/pre-deploy-checklist.md","line_end":378,"line_start":374},{"file":"references/pre-deploy-checklist.md","line_end":439,"line_start":439},{"file":"references/pre-deploy-checklist.md","line_end":118,"line_start":118},{"file":"references/pre-deploy-checklist.md","line_end":119,"line_start":119},{"file":"references/pre-deploy-checklist.md","line_end":178,"line_start":178},{"file":"references/pre-deploy-checklist.md","line_end":179,"line_start":179},{"file":"references/pre-deploy-checklist.md","line_end":318,"line_start":318},{"file":"references/pre-deploy-checklist.md","line_end":319,"line_start":319},{"file":"references/pre-deploy-checklist.md","line_end":345,"line_start":345},{"file":"references/pre-deploy-checklist.md","line_end":346,"line_start":346},{"file":"references/pre-deploy-checklist.md","line_end":362,"line_start":362},{"file":"references/pre-deploy-checklist.md","line_end":363,"line_start":363},{"file":"references/pre-deploy-checklist.md","line_end":395,"line_start":395},{"file":"references/pre-deploy-checklist.md","line_end":396,"line_start":396},{"file":"references/pre-deploy-checklist.md","line_end":443,"line_start":443},{"file":"references/pre-deploy-checklist.md","line_end":444,"line_start":444},{"file":"references/pre-deploy-checklist.md","line_end":457,"line_start":457},{"file":"references/pre-deploy-checklist.md","line_end":458,"line_start":458},{"file":"references/recipes/azcli/verify.md","line_end":40,"line_start":40},{"file":"references/recipes/azcli/verify.md","line_end":44,"line_start":44},{"file":"references/recipes/azcli/verify.md","line_end":48,"line_start":48},{"file":"references/recipes/azcli/verify.md","line_end":52,"line_start":52},{"file":"references/recipes/azcli/verify.md","line_end":53,"line_start":53},{"file":"references/recipes/azd/ef-migrations.md","line_end":56,"line_start":56},{"file":"references/recipes/azd/ef-migrations.md","line_end":14,"line_start":14},{"file":"references/recipes/azd/ef-migrations.md","line_end":15,"line_start":15},{"file":"references/recipes/azd/ef-migrations.md","line_end":33,"line_start":33},{"file":"references/recipes/azd/ef-migrations.md","line_end":59,"line_start":59},{"file":"references/recipes/azd/ef-migrations.md","line_end":60,"line_start":60},{"file":"references/recipes/azd/ef-migrations.md","line_end":90,"line_start":90},{"file":"references/recipes/azd/errors.md","line_end":73,"line_start":72},{"file":"references/recipes/azd/errors.md","line_end":76,"line_start":74},{"file":"references/recipes/azd/errors.md","line_end":47,"line_start":47},{"file":"references/recipes/azd/errors.md","line_end":48,"line_start":48},{"file":"references/recipes/azd/errors.md","line_end":65,"line_start":65}]},{"factor":"env_access","evidence":[{"file":"references/auth-best-practices.md","line_end":43,"line_start":43},{"file":"references/auth-best-practices.md","line_end":101,"line_start":101},{"file":"references/auth-best-practices.md","line_end":104,"line_start":104},{"file":"references/auth-best-practices.md","line_end":105,"line_start":105},{"file":"references/auth-best-practices.md","line_end":43,"line_start":43},{"file":"references/auth-best-practices.md","line_end":101,"line_start":101},{"file":"references/auth-best-practices.md","line_end":104,"line_start":104},{"file":"references/auth-best-practices.md","line_end":105,"line_start":105},{"file":"references/auth-best-practices.md","line_end":57,"line_start":57},{"file":"references/auth-best-practices.md","line_end":57,"line_start":57},{"file":"references/auth-best-practices.md","line_end":69,"line_start":69},{"file":"references/auth-best-practices.md","line_end":104,"line_start":104},{"file":"references/auth-best-practices.md","line_end":105,"line_start":105},{"file":"references/recipes/cicd/examples/github-azd.yml","line_end":26,"line_start":26},{"file":"references/recipes/cicd/examples/github-azd.yml","line_end":27,"line_start":27},{"file":"references/recipes/cicd/examples/github-bicep.yml","line_end":17,"line_start":17},{"file":"references/recipes/cicd/examples/github-bicep.yml","line_end":18,"line_start":18},{"file":"references/recipes/cicd/README.md","line_end":30,"line_start":30},{"file":"references/sdk/azure-identity-py.md","line_end":27,"line_start":27}]},{"factor":"filesystem","evidence":[{"file":"references/pre-deploy-checklist.md","line_end":378,"line_start":378},{"file":"references/recipes/azcli/README.md","line_end":10,"line_start":10},{"file":"references/recipes/azcli/README.md","line_end":16,"line_start":16},{"file":"references/recipes/azd/ef-migrations.md","line_end":43,"line_start":43},{"file":"references/recipes/azd/ef-migrations.md","line_end":43,"line_start":43},{"file":"references/recipes/azd/ef-migrations.md","line_end":10,"line_start":10},{"file":"references/recipes/azd/errors.md","line_end":24,"line_start":24},{"file":"references/recipes/azd/functions-deploy.md","line_end":103,"line_start":103},{"file":"references/recipes/azd/functions-deploy.md","line_end":74,"line_start":74},{"file":"references/recipes/azd/functions-deploy.md","line_end":77,"line_start":77},{"file":"references/recipes/azd/functions-deploy.md","line_end":80,"line_start":80},{"file":"references/recipes/azd/README.md","line_end":14,"line_start":14},{"file":"references/recipes/azd/README.md","line_end":22,"line_start":22},{"file":"references/recipes/azd/README.md","line_end":77,"line_start":77},{"file":"references/recipes/azd/scripts/apply-migrations.sh","line_end":47,"line_start":47},{"file":"references/recipes/azd/scripts/apply-migrations.sh","line_end":44,"line_start":44},{"file":"references/recipes/azd/scripts/grant-and-migrate.sh","line_end":103,"line_start":103},{"file":"references/recipes/azd/scripts/grant-and-migrate.sh","line_end":54,"line_start":54},{"file":"references/recipes/azd/scripts/grant-and-migrate.sh","line_end":100,"line_start":100},{"file":"references/recipes/bicep/README.md","line_end":10,"line_start":10},{"file":"references/recipes/bicep/README.md","line_end":16,"line_start":16},{"file":"references/recipes/terraform/errors.md","line_end":9,"line_start":9},{"file":"references/recipes/terraform/README.md","line_end":11,"line_start":11},{"file":"references/recipes/terraform/README.md","line_end":17,"line_start":17},{"file":"references/recipes/terraform/README.md","line_end":114,"line_start":114},{"file":"references/sdk/azd-deployment.md","line_end":19,"line_start":19},{"file":"references/sdk/azure-identity-dotnet.md","line_end":12,"line_start":12},{"file":"references/sdk/azure-identity-dotnet.md","line_end":20,"line_start":20},{"file":"references/sdk/azure-identity-java.md","line_end":18,"line_start":18},{"file":"references/sdk/azure-identity-java.md","line_end":26,"line_start":26},{"file":"references/sdk/azure-identity-py.md","line_end":14,"line_start":14},{"file":"references/sdk/azure-identity-py.md","line_end":22,"line_start":22},{"file":"references/sdk/azure-identity-ts.md","line_end":12,"line_start":12},{"file":"references/sdk/azure-identity-ts.md","line_end":20,"line_start":20}]},{"factor":"network","evidence":[{"file":"references/recipes/azcli/verify.md","line_end":10,"line_start":10},{"file":"references/recipes/azcli/verify.md","line_end":41,"line_start":41},{"file":"references/recipes/azcli/verify.md","line_end":45,"line_start":45},{"file":"references/recipes/azcli/verify.md","line_end":49,"line_start":49},{"file":"references/recipes/azcli/verify.md","line_end":56,"line_start":56},{"file":"references/recipes/azcli/verify.md","line_end":60,"line_start":60},{"file":"references/recipes/azcli/verify.md","line_end":64,"line_start":64},{"file":"references/recipes/azd/functions-deploy.md","line_end":68,"line_start":68},{"file":"references/recipes/azd/functions-deploy.md","line_end":74,"line_start":74},{"file":"references/recipes/azd/functions-deploy.md","line_end":77,"line_start":77},{"file":"references/recipes/azd/functions-deploy.md","line_end":80,"line_start":80},{"file":"references/recipes/azd/functions-deploy.md","line_end":87,"line_start":87},{"file":"references/recipes/azd/verify.md","line_end":16,"line_start":16},{"file":"references/recipes/azd/verify.md","line_end":68,"line_start":68},{"file":"references/recipes/azd/verify.md","line_end":70,"line_start":70},{"file":"references/recipes/bicep/verify.md","line_end":18,"line_start":18},{"file":"references/recipes/cicd/verify.md","line_end":16,"line_start":16},{"file":"references/recipes/terraform/verify.md","line_end":11,"line_start":11},{"file":"references/troubleshooting.md","line_end":115,"line_start":115},{"file":"references/troubleshooting.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":74,"line_start":74}]}],"critical_findings":[{"title":"Pipe to shell pattern","locations":[{"file":"references/sdk/azd-deployment.md","line_end":8,"line_start":8}],"confidence":0.99,"description":"curl -fsSL https://aka.ms/install-azd.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The command downloads a remote script and pipes it directly to Bash without pinning or verification. A compromised response would execute arbitrary code."}],"high_findings":[{"title":"Shell command substitution","locations":[{"file":"references/recipes/azd/errors.md","line_end":154,"line_start":154}],"confidence":0.98,"description":"ACR_PASS=$(az acr credential show --name <acr-name> --query \"passwords[0].value\" -o tsv)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This captures a live registry password, and the next command passes it through docker login -p. Process inspection and logs can expose it."},{"title":"Shell command substitution","locations":[{"file":"references/recipes/azd/post-deployment.md","line_end":38,"line_start":38}],"confidence":0.98,"description":"eval $(azd env get-values)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges."},{"title":"Shell command substitution","locations":[{"file":"references/recipes/azd/sql-managed-identity.md","line_end":16,"line_start":16}],"confidence":0.98,"description":"eval $(azd env get-values)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges."},{"title":"Shell command substitution","locations":[{"file":"references/recipes/azd/sql-managed-identity.md","line_end":83,"line_start":83}],"confidence":0.98,"description":"eval $(azd env get-values)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges."},{"title":"Shell command substitution","locations":[{"file":"references/recipes/azd/sql-managed-identity.md","line_end":171,"line_start":171}],"confidence":0.98,"description":"eval $(azd env get-values)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges."},{"title":"Shell command substitution","locations":[{"file":"references/recipes/azd/verify.md","line_end":85,"line_start":85}],"confidence":0.98,"description":"eval $(azd env get-values)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges."},{"title":"Registry Password Exposed in Command Arguments","locations":[{"file":"references/recipes/azd/errors.md","line_end":164,"line_start":152}],"confidence":0.98,"description":"The fallback retrieves an ACR administrator password and passes it with docker login -p. Other local processes and logs can expose the credential.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The commands directly retrieve a live password and place it in a process argument in both shell variants."},{"title":"Application Identity Receives Schema Administration","locations":[{"file":"references/recipes/azd/sql-managed-identity.md","line_end":29,"line_start":24},{"file":"references/recipes/azd/scripts/grant-and-migrate.sh","line_end":94,"line_start":67},{"file":"references/recipes/azd/scripts/grant-and-migrate.ps1","line_end":72,"line_start":45}],"confidence":0.97,"description":"Deployment guidance grants the runtime identity db_ddladmin with read and write roles. A compromised application could alter or drop database schema.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The SQL explicitly adds the application identity to db_ddladmin, db_datareader, and db_datawriter in every documented variant."},{"title":"Mutable Deployment Dependencies","locations":[{"file":"references/recipes/cicd/examples/github-azd.yml","line_end":24,"line_start":8},{"file":"references/recipes/azd/scripts/apply-migrations.sh","line_end":46,"line_start":43},{"file":"references/recipes/azd/scripts/grant-and-migrate.sh","line_end":56,"line_start":53}],"confidence":0.95,"description":"CI workflows use mutable action tags with OIDC permission, and migration scripts install unpinned global tools. Upstream changes could execute during deployment.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The workflow uses version tags instead of commit SHAs, while scripts install current package versions without integrity or version constraints."},{"title":"Project-Controlled Health Check Targets","locations":[{"file":"references/recipes/azd/post-deployment.md","line_end":82,"line_start":74},{"file":"references/recipes/azd/verify.md","line_end":36,"line_start":21}],"confidence":0.9,"description":"Health checks request endpoints loaded from project-controlled AZD values without validating the host. A crafted project can direct the agent toward internal services.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The endpoint comes from local AZD environment state and is passed directly to curl or Invoke-WebRequest without a scheme or hostname allowlist."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[{"title":"Pipe to shell pattern","locations":[{"file":"references/sdk/azd-deployment.md","line_end":8,"line_start":8}],"confidence":0.99,"description":"curl -fsSL https://aka.ms/install-azd.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The command downloads a remote script and pipes it directly to Bash without pinning or verification. A compromised response would execute arbitrary code."}],"files_scanned":42,"total_lines":3650,"audit_model":"codex","audited_at":"2026-07-23T18:27:00.816+00:00","created_at":"2026-07-25T23:05:51.926879+00:00","static_findings":[{"id":"external_commands:references/auth-best-practices.md:16:powershell-invocation","file":"references/auth-best-practices.md","pattern":"PowerShell invocation","snippet":"| **Local development** | `DefaultAzureCredential` | Chains CLI, PowerShell, and VS Code credentials","category":"external_commands","line_end":16,"severity":"high","line_start":16},{"id":"external_commands:references/auth-best-practices.md:81:powershell-invocation","file":"references/auth-best-practices.md","pattern":"PowerShell invocation","snippet":"3. **Azure PowerShell** — `Connect-AzAccount`","category":"external_commands","line_end":81,"severity":"high","line_start":81},{"id":"external_commands:references/auth-best-practices.md:87:powershell-invocation","file":"references/auth-best-practices.md","pattern":"PowerShell invocation","snippet":"// Local development only — uses CLI/PowerShell/VS Code credentials","category":"external_commands","line_end":87,"severity":"high","line_start":87},{"id":"env_access:references/auth-best-practices.md:43:environment-variable-access-dot-notation","file":"references/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"const credential = process.env.NODE_ENV === \"development\"","category":"env_access","line_end":43,"severity":"low","line_start":43},{"id":"env_access:references/auth-best-practices.md:101:environment-variable-access-dot-notation","file":"references/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"if (process.env.NODE_ENV === \"development\") {","category":"env_access","line_end":101,"severity":"low","line_start":101},{"id":"env_access:references/auth-best-practices.md:104:environment-variable-access-dot-notation","file":"references/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"return process.env.AZURE_CLIENT_ID","category":"env_access","line_end":104,"severity":"low","line_start":104},{"id":"env_access:references/auth-best-practices.md:105:environment-variable-access-dot-notation","file":"references/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"env_access","line_end":105,"severity":"low","line_start":105},{"id":"env_access:references/auth-best-practices.md:43:environment-variable-object","file":"references/auth-best-practices.md","pattern":"Environment variable object","snippet":"const credential = process.env.NODE_ENV === \"development\"","category":"env_access","line_end":43,"severity":"low","line_start":43},{"id":"env_access:references/auth-best-practices.md:101:environment-variable-object","file":"references/auth-best-practices.md","pattern":"Environment variable object","snippet":"if (process.env.NODE_ENV === \"development\") {","category":"env_access","line_end":101,"severity":"low","line_start":101},{"id":"env_access:references/auth-best-practices.md:104:environment-variable-object","file":"references/auth-best-practices.md","pattern":"Environment variable object","snippet":"return process.env.AZURE_CLIENT_ID","category":"env_access","line_end":104,"severity":"low","line_start":104},{"id":"env_access:references/auth-best-practices.md:105:environment-variable-object","file":"references/auth-best-practices.md","pattern":"Environment variable object","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"env_access","line_end":105,"severity":"low","line_start":105},{"id":"env_access:references/auth-best-practices.md:57:python-getenv-function","file":"references/auth-best-practices.md","pattern":"Python getenv function","snippet":"if os.getenv(\"AZURE_FUNCTIONS_ENVIRONMENT\") == \"Development\"","category":"env_access","line_end":57,"severity":"low","line_start":57},{"id":"env_access:references/auth-best-practices.md:57:getenv-function-call","file":"references/auth-best-practices.md","pattern":"getenv function call","snippet":"if os.getenv(\"AZURE_FUNCTIONS_ENVIRONMENT\") == \"Development\"","category":"env_access","line_end":57,"severity":"low","line_start":57},{"id":"env_access:references/auth-best-practices.md:69:getenv-function-call","file":"references/auth-best-practices.md","pattern":"getenv function call","snippet":"var credential = \"Development\".equals(System.getenv(\"AZURE_FUNCTIONS_ENVIRONMENT\"))","category":"env_access","line_end":69,"severity":"low","line_start":69},{"id":"env_access:references/auth-best-practices.md:104:azure-credential-environment-variables","file":"references/auth-best-practices.md","pattern":"Azure credential environment variables","snippet":"return process.env.AZURE_CLIENT_ID","category":"env_access","line_end":104,"severity":"high","line_start":104},{"id":"env_access:references/auth-best-practices.md:105:azure-credential-environment-variables","file":"references/auth-best-practices.md","pattern":"Azure credential environment variables","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"env_access","line_end":105,"severity":"high","line_start":105},{"id":"sensitive:references/auth-best-practices.md:43:environment-file-access","file":"references/auth-best-practices.md","pattern":"Environment file access","snippet":"const credential = process.env.NODE_ENV === \"development\"","category":"sensitive","line_end":43,"severity":"high","line_start":43},{"id":"sensitive:references/auth-best-practices.md:101:environment-file-access","file":"references/auth-best-practices.md","pattern":"Environment file access","snippet":"if (process.env.NODE_ENV === \"development\") {","category":"sensitive","line_end":101,"severity":"high","line_start":101},{"id":"sensitive:references/auth-best-practices.md:104:environment-file-access","file":"references/auth-best-practices.md","pattern":"Environment file access","snippet":"return process.env.AZURE_CLIENT_ID","category":"sensitive","line_end":104,"severity":"high","line_start":104},{"id":"sensitive:references/auth-best-practices.md:105:environment-file-access","file":"references/auth-best-practices.md","pattern":"Environment file access","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"sensitive","line_end":105,"severity":"high","line_start":105},{"id":"external_commands:references/live-role-verification.md:97:ruby-shell-backtick-execution","file":"references/live-role-verification.md","pattern":"Ruby/shell backtick execution","snippet":"- Command: `az role assignment list --scope <resourceId> --assignee-object-id <principalId>`","category":"external_commands","line_end":102,"severity":"medium","line_start":97},{"id":"sensitive:references/live-role-verification.md:25:azure-credentials-directory","file":"references/live-role-verification.md","pattern":"Azure credentials directory","snippet":"Read `.azure/deployment-plan.md` to find all services with managed identities. Then query Azure for ","category":"sensitive","line_end":25,"severity":"critical","line_start":25},{"id":"sensitive:references/live-role-verification.md:93:azure-credentials-directory","file":"references/live-role-verification.md","pattern":"Azure credentials directory","snippet":"Add live role verification results to the deployment log in `.azure/deployment-plan.md`:","category":"sensitive","line_end":93,"severity":"critical","line_start":93},{"id":"blocker:references/live-role-verification.md:53:system-reconnaissance","file":"references/live-role-verification.md","pattern":"System reconnaissance","snippet":"az role assignment list --scope <resourceId> --assignee-object-id <principalId> --output table","category":"blocker","line_end":53,"severity":"low","line_start":53},{"id":"blocker:references/live-role-verification.md:97:system-reconnaissance","file":"references/live-role-verification.md","pattern":"System reconnaissance","snippet":"- Command: `az role assignment list --scope <resourceId> --assignee-object-id <principalId>`","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"external_commands:references/pre-deploy-checklist.md:121:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--resource-group rg-<env-name> `","category":"external_commands","line_end":122,"severity":"medium","line_start":121},{"id":"external_commands:references/pre-deploy-checklist.md:181:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--name <environment-name> `","category":"external_commands","line_end":182,"severity":"medium","line_start":181},{"id":"external_commands:references/pre-deploy-checklist.md:322:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--name <app-name> `","category":"external_commands","line_end":323,"severity":"medium","line_start":322},{"id":"external_commands:references/pre-deploy-checklist.md:324:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--server <acr-login-server> `","category":"external_commands","line_end":326,"severity":"medium","line_start":324},{"id":"external_commands:references/pre-deploy-checklist.md:327:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--name <app-name> `","category":"external_commands","line_end":328,"severity":"medium","line_start":327},{"id":"external_commands:references/pre-deploy-checklist.md:348:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--name <app-name> `","category":"external_commands","line_end":349,"severity":"medium","line_start":348},{"id":"external_commands:references/pre-deploy-checklist.md:365:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--name <acr-name> `","category":"external_commands","line_end":366,"severity":"medium","line_start":365},{"id":"external_commands:references/pre-deploy-checklist.md:399:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--scope $AcrId `","category":"external_commands","line_end":400,"severity":"medium","line_start":399},{"id":"external_commands:references/pre-deploy-checklist.md:401:ruby-shell-backtick-execution","file":"references/pre-deploy-checklist.md","pattern":"Ruby/shell backtick execution","snippet":"--query \"[?roleDefinitionName=='AcrPull'].roleDefinitionName\" `","category":"external_commands","line_end":417,"severity":"medium","line_start":401},{"id":"external_commands:references/pre-deploy-checklist.md:339:shell-command-substitution","file":"references/pre-deploy-checklist.md","pattern":"Shell command substitution","snippet":"PRINCIPAL_ID=$(az containerapp identity show \\","category":"external_commands","line_end":342,"severity":"medium","line_start":339},{"id":"external_commands:references/pre-deploy-checklist.md:356:shell-command-substitution","file":"references/pre-deploy-checklist.md","pattern":"Shell command substitution","snippet":"ACR_ID=$(az acr show \\","category":"external_commands","line_end":359,"severity":"medium","line_start":356},{"id":"external_commands:references/pre-deploy-checklist.md:374:shell-command-substitution","file":"references/pre-deploy-checklist.md","pattern":"Shell command substitution","snippet":"ROLE=$(az role assignment list \\","category":"external_commands","line_end":378,"severity":"medium","line_start":374},{"id":"external_commands:references/pre-deploy-checklist.md:439:shell-command-substitution","file":"references/pre-deploy-checklist.md","pattern":"Shell command substitution","snippet":"AUTH_TYPE=$(az account show --query user.type -o tsv)","category":"external_commands","line_end":439,"severity":"medium","line_start":439},{"id":"external_commands:references/pre-deploy-checklist.md:118:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":118,"severity":"high","line_start":118},{"id":"external_commands:references/pre-deploy-checklist.md:119:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":119,"severity":"high","line_start":119},{"id":"external_commands:references/pre-deploy-checklist.md:178:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":178,"severity":"high","line_start":178},{"id":"external_commands:references/pre-deploy-checklist.md:179:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":179,"severity":"high","line_start":179},{"id":"external_commands:references/pre-deploy-checklist.md:318:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":318,"severity":"high","line_start":318},{"id":"external_commands:references/pre-deploy-checklist.md:319:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":319,"severity":"high","line_start":319},{"id":"external_commands:references/pre-deploy-checklist.md:345:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":345,"severity":"high","line_start":345},{"id":"external_commands:references/pre-deploy-checklist.md:346:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":346,"severity":"high","line_start":346},{"id":"external_commands:references/pre-deploy-checklist.md:362:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":362,"severity":"high","line_start":362},{"id":"external_commands:references/pre-deploy-checklist.md:363:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":363,"severity":"high","line_start":363},{"id":"external_commands:references/pre-deploy-checklist.md:395:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":395,"severity":"high","line_start":395},{"id":"external_commands:references/pre-deploy-checklist.md:396:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":396,"severity":"high","line_start":396},{"id":"external_commands:references/pre-deploy-checklist.md:443:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":443,"severity":"high","line_start":443},{"id":"external_commands:references/pre-deploy-checklist.md:444:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":444,"severity":"high","line_start":444},{"id":"external_commands:references/pre-deploy-checklist.md:457:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":457,"severity":"high","line_start":457},{"id":"external_commands:references/pre-deploy-checklist.md:458:powershell-invocation","file":"references/pre-deploy-checklist.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":458,"severity":"high","line_start":458},{"id":"filesystem:references/pre-deploy-checklist.md:378:standard-device-file-access","file":"references/pre-deploy-checklist.md","pattern":"Standard device file access","snippet":"-o tsv 2>/dev/null)","category":"filesystem","line_end":378,"severity":"low","line_start":378},{"id":"sensitive:references/pre-deploy-checklist.md:46:azure-credentials-directory","file":"references/pre-deploy-checklist.md","pattern":"Azure credentials directory","snippet":"> ⛔ **DO NOT** manually create `.azure/` folder with `mkdir` or `New-Item`. Let `azd` create it.","category":"sensitive","line_end":46,"severity":"critical","line_start":46},{"id":"sensitive:references/pre-deploy-checklist.md:59:azure-credentials-directory","file":"references/pre-deploy-checklist.md","pattern":"Azure credentials directory","snippet":"- `.azure/<env-name>/` folder with config files","category":"sensitive","line_end":59,"severity":"critical","line_start":59},{"id":"blocker:references/pre-deploy-checklist.md:66:system-reconnaissance","file":"references/pre-deploy-checklist.md","pattern":"System reconnaissance","snippet":"> ⛔ **CRITICAL** — Skip this and you'll hit \"Invalid resource group location\" errors.","category":"blocker","line_end":66,"severity":"low","line_start":66},{"id":"blocker:references/pre-deploy-checklist.md:259:system-reconnaissance","file":"references/pre-deploy-checklist.md","pattern":"System reconnaissance","snippet":"## Common Mistakes to Avoid","category":"blocker","line_end":261,"severity":"low","line_start":259},{"id":"blocker:references/pre-deploy-checklist.md:359:system-reconnaissance","file":"references/pre-deploy-checklist.md","pattern":"System reconnaissance","snippet":"--query id -o tsv)","category":"blocker","line_end":359,"severity":"low","line_start":359},{"id":"blocker:references/pre-deploy-checklist.md:367:system-reconnaissance","file":"references/pre-deploy-checklist.md","pattern":"System reconnaissance","snippet":"--query id -o tsv","category":"blocker","line_end":367,"severity":"low","line_start":367},{"id":"blocker:references/pre-deploy-checklist.md:376:system-reconnaissance","file":"references/pre-deploy-checklist.md","pattern":"System reconnaissance","snippet":"--assignee-object-id \"$PRINCIPAL_ID\" \\","category":"blocker","line_end":376,"severity":"low","line_start":376},{"id":"blocker:references/pre-deploy-checklist.md:400:system-reconnaissance","file":"references/pre-deploy-checklist.md","pattern":"System reconnaissance","snippet":"--assignee-object-id $PrincipalId `","category":"blocker","line_end":400,"severity":"low","line_start":400},{"id":"filesystem:references/recipes/azcli/README.md:10:path-traversal-sequence","file":"references/recipes/azcli/README.md","pattern":"Path traversal sequence","snippet":"- **Subscription and location confirmed** → See [Pre-Deploy Checklist](../../pre-deploy-checklist.md","category":"filesystem","line_end":10,"severity":"high","line_start":10},{"id":"filesystem:references/recipes/azcli/README.md:16:path-traversal-sequence","file":"references/recipes/azcli/README.md","pattern":"Path traversal sequence","snippet":"| 1 | **[Pre-deploy checklist](../../pre-deploy-checklist.md)** | Confirm subscription/location with","category":"filesystem","line_end":16,"severity":"high","line_start":16},{"id":"sensitive:references/recipes/azcli/README.md:8:azure-credentials-directory","file":"references/recipes/azcli/README.md","pattern":"Azure credentials directory","snippet":"- `.azure/deployment-plan.md` exists with status `Validated`","category":"sensitive","line_end":8,"severity":"critical","line_start":8},{"id":"external_commands:references/recipes/azcli/verify.md:40:shell-command-substitution","file":"references/recipes/azcli/verify.md","pattern":"Shell command substitution","snippet":"FQDN=$(az containerapp show --name <app-name> --resource-group <rg-name> --query \"properties.configu","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:references/recipes/azcli/verify.md:44:shell-command-substitution","file":"references/recipes/azcli/verify.md","pattern":"Shell command substitution","snippet":"HOSTNAME=$(az webapp show --name <app-name> --resource-group <rg-name> --query \"defaultHostName\" -o ","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:references/recipes/azcli/verify.md:48:shell-command-substitution","file":"references/recipes/azcli/verify.md","pattern":"Shell command substitution","snippet":"HOSTNAME=$(az staticwebapp show --name <app-name> --resource-group <rg-name> --query \"defaultHostnam","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:references/recipes/azcli/verify.md:52:powershell-invocation","file":"references/recipes/azcli/verify.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":52,"severity":"high","line_start":52},{"id":"external_commands:references/recipes/azcli/verify.md:53:powershell-invocation","file":"references/recipes/azcli/verify.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":53,"severity":"high","line_start":53},{"id":"network:references/recipes/azcli/verify.md:10:hardcoded-url","file":"references/recipes/azcli/verify.md","pattern":"Hardcoded URL","snippet":"curl -s https://<endpoint>/health | jq .","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:references/recipes/azcli/verify.md:41:hardcoded-url","file":"references/recipes/azcli/verify.md","pattern":"Hardcoded URL","snippet":"echo \"https://$FQDN\"","category":"network","line_end":41,"severity":"low","line_start":41},{"id":"network:references/recipes/azcli/verify.md:45:hardcoded-url","file":"references/recipes/azcli/verify.md","pattern":"Hardcoded URL","snippet":"echo \"https://$HOSTNAME\"","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:references/recipes/azcli/verify.md:49:hardcoded-url","file":"references/recipes/azcli/verify.md","pattern":"Hardcoded URL","snippet":"echo \"https://$HOSTNAME\"","category":"network","line_end":49,"severity":"low","line_start":49},{"id":"network:references/recipes/azcli/verify.md:56:hardcoded-url","file":"references/recipes/azcli/verify.md","pattern":"Hardcoded URL","snippet":"Write-Output \"https://$Fqdn\"","category":"network","line_end":56,"severity":"low","line_start":56},{"id":"network:references/recipes/azcli/verify.md:60:hardcoded-url","file":"references/recipes/azcli/verify.md","pattern":"Hardcoded URL","snippet":"Write-Output \"https://$Hostname\"","category":"network","line_end":60,"severity":"low","line_start":60},{"id":"network:references/recipes/azcli/verify.md:64:hardcoded-url","file":"references/recipes/azcli/verify.md","pattern":"Hardcoded URL","snippet":"Write-Output \"https://$Hostname\"","category":"network","line_end":64,"severity":"low","line_start":64},{"id":"blocker:references/recipes/azcli/verify.md:67:system-reconnaissance","file":"references/recipes/azcli/verify.md","pattern":"System reconnaissance","snippet":"> ⚠️ **These commands return bare hostnames without a scheme.** Always prepend `https://` when prese","category":"blocker","line_end":67,"severity":"low","line_start":67},{"id":"external_commands:references/recipes/azd/ef-migrations.md:56:shell-command-substitution","file":"references/recipes/azd/ef-migrations.md","pattern":"Shell command substitution","snippet":"--auth-mode ActiveDirectoryDefault --queries \"$(cat migrations.sql)\"","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:references/recipes/azd/ef-migrations.md:14:powershell-invocation","file":"references/recipes/azd/ef-migrations.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":14,"severity":"high","line_start":14},{"id":"external_commands:references/recipes/azd/ef-migrations.md:15:powershell-invocation","file":"references/recipes/azd/ef-migrations.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":15,"severity":"high","line_start":15},{"id":"external_commands:references/recipes/azd/ef-migrations.md:33:powershell-invocation","file":"references/recipes/azd/ef-migrations.md","pattern":"PowerShell invocation","snippet":"shell: pwsh","category":"external_commands","line_end":33,"severity":"high","line_start":33},{"id":"external_commands:references/recipes/azd/ef-migrations.md:59:powershell-invocation","file":"references/recipes/azd/ef-migrations.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":59,"severity":"high","line_start":59},{"id":"external_commands:references/recipes/azd/ef-migrations.md:60:powershell-invocation","file":"references/recipes/azd/ef-migrations.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":60,"severity":"high","line_start":60},{"id":"external_commands:references/recipes/azd/ef-migrations.md:90:powershell-invocation","file":"references/recipes/azd/ef-migrations.md","pattern":"PowerShell invocation","snippet":"shell: pwsh","category":"external_commands","line_end":90,"severity":"high","line_start":90},{"id":"filesystem:references/recipes/azd/ef-migrations.md:43:hidden-file-in-home-directory","file":"references/recipes/azd/ef-migrations.md","pattern":"Hidden file in home directory","snippet":"- Adds `~/.dotnet/tools` to `PATH` so the tool is immediately available","category":"filesystem","line_end":43,"severity":"high","line_start":43},{"id":"filesystem:references/recipes/azd/ef-migrations.md:43:hidden-file-access","file":"references/recipes/azd/ef-migrations.md","pattern":"Hidden file access","snippet":"- Adds `~/.dotnet/tools` to `PATH` so the tool is immediately available","category":"filesystem","line_end":43,"severity":"medium","line_start":43},{"id":"filesystem:references/recipes/azd/ef-migrations.md:10:standard-device-file-access","file":"references/recipes/azd/ef-migrations.md","pattern":"Standard device file access","snippet":"find . -type d -name \"Migrations\" 2>/dev/null","category":"filesystem","line_end":10,"severity":"low","line_start":10},{"id":"external_commands:references/recipes/azd/errors.md:72:ruby-shell-backtick-execution","file":"references/recipes/azd/errors.md","pattern":"Ruby/shell backtick execution","snippet":"--assignee-object-id $PrincipalId `","category":"external_commands","line_end":73,"severity":"medium","line_start":72},{"id":"external_commands:references/recipes/azd/errors.md:74:ruby-shell-backtick-execution","file":"references/recipes/azd/errors.md","pattern":"Ruby/shell backtick execution","snippet":"--role AcrPull `","category":"external_commands","line_end":76,"severity":"medium","line_start":74},{"id":"external_commands:references/recipes/azd/errors.md:47:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"PRINCIPAL_ID=$(az containerapp identity show --name <app-name> --resource-group <resource-group> --q","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:references/recipes/azd/errors.md:48:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"az role assignment list --scope $(az acr show --name <acr-name> --resource-group <resource-group> --","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:references/recipes/azd/errors.md:65:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"--scope $(az acr show --name <acr-name> --resource-group <resource-group> --query id -o tsv)","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:references/recipes/azd/errors.md:80:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"azd env set AZURE_CONTAINER_REGISTRY_ENDPOINT $(az acr show --name <acr-name> --resource-group <reso","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:references/recipes/azd/errors.md:153:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"ACR_USER=$(az acr credential show --name <acr-name> --query username -o tsv)","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:references/recipes/azd/errors.md:154:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"ACR_PASS=$(az acr credential show --name <acr-name> --query \"passwords[0].value\" -o tsv)","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:references/recipes/azd/errors.md:202:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"azd env set AZURE_CONTAINER_REGISTRY_ENDPOINT $(az acr list --resource-group <resource-group-name> -","category":"external_commands","line_end":202,"severity":"medium","line_start":202},{"id":"external_commands:references/recipes/azd/errors.md:205:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"azd env set AZURE_CONTAINER_REGISTRY_MANAGED_IDENTITY_ID $(az identity list --resource-group <resour","category":"external_commands","line_end":205,"severity":"medium","line_start":205},{"id":"external_commands:references/recipes/azd/errors.md:208:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"azd env set MANAGED_IDENTITY_CLIENT_ID $(az identity list --resource-group <resource-group-name> --q","category":"external_commands","line_end":208,"severity":"medium","line_start":208},{"id":"external_commands:references/recipes/azd/errors.md:256:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"azd env set TF_VAR_environment_name \"$(azd env get-value AZURE_ENV_NAME)\"","category":"external_commands","line_end":256,"severity":"medium","line_start":256},{"id":"external_commands:references/recipes/azd/errors.md:257:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"azd env set TF_VAR_location \"$(azd env get-value AZURE_LOCATION)\"","category":"external_commands","line_end":257,"severity":"medium","line_start":257},{"id":"external_commands:references/recipes/azd/errors.md:258:shell-command-substitution","file":"references/recipes/azd/errors.md","pattern":"Shell command substitution","snippet":"azd env set TF_VAR_subscription_id \"$(azd env get-value AZURE_SUBSCRIPTION_ID)\"","category":"external_commands","line_end":258,"severity":"medium","line_start":258},{"id":"external_commands:references/recipes/azd/errors.md:52:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":52,"severity":"high","line_start":52},{"id":"external_commands:references/recipes/azd/errors.md:53:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":53,"severity":"high","line_start":53},{"id":"external_commands:references/recipes/azd/errors.md:68:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":68,"severity":"high","line_start":68},{"id":"external_commands:references/recipes/azd/errors.md:69:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":69,"severity":"high","line_start":69},{"id":"external_commands:references/recipes/azd/errors.md:98:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":98,"severity":"high","line_start":98},{"id":"external_commands:references/recipes/azd/errors.md:99:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":99,"severity":"high","line_start":99},{"id":"external_commands:references/recipes/azd/errors.md:159:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"**PowerShell (Method 2):**","category":"external_commands","line_end":159,"severity":"high","line_start":159},{"id":"external_commands:references/recipes/azd/errors.md:160:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":160,"severity":"high","line_start":160},{"id":"external_commands:references/recipes/azd/errors.md:211:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":211,"severity":"high","line_start":211},{"id":"external_commands:references/recipes/azd/errors.md:212:powershell-invocation","file":"references/recipes/azd/errors.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":212,"severity":"high","line_start":212},{"id":"filesystem:references/recipes/azd/errors.md:24:path-traversal-sequence","file":"references/recipes/azd/errors.md","pattern":"Path traversal sequence","snippet":"> i️ **Pre-flight validation**: Run `azure-validate` before deployment to catch configuration errors","category":"filesystem","line_end":24,"severity":"high","line_start":24},{"id":"blocker:references/recipes/azd/errors.md:28:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"**Symptom:** `azd up` provisions infrastructure successfully but the Container App revision creation","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"blocker:references/recipes/azd/errors.md:48:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"az role assignment list --scope $(az acr show --name <acr-name> --resource-group <resource-group> --","category":"blocker","line_end":48,"severity":"low","line_start":48},{"id":"blocker:references/recipes/azd/errors.md:49:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"--assignee-object-id \"$PRINCIPAL_ID\" --query \"[].roleDefinitionName\" -o tsv","category":"blocker","line_end":49,"severity":"low","line_start":49},{"id":"blocker:references/recipes/azd/errors.md:55:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"$AcrScope = az acr show --name <acr-name> --resource-group <resource-group> --query id -o tsv","category":"blocker","line_end":55,"severity":"low","line_start":55},{"id":"blocker:references/recipes/azd/errors.md:56:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"az role assignment list --scope $AcrScope --assignee-object-id $PrincipalId --query \"[].roleDefiniti","category":"blocker","line_end":56,"severity":"low","line_start":56},{"id":"blocker:references/recipes/azd/errors.md:62:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"--assignee-object-id \"$PRINCIPAL_ID\" \\","category":"blocker","line_end":62,"severity":"low","line_start":62},{"id":"blocker:references/recipes/azd/errors.md:65:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"--scope $(az acr show --name <acr-name> --resource-group <resource-group> --query id -o tsv)","category":"blocker","line_end":65,"severity":"low","line_start":65},{"id":"blocker:references/recipes/azd/errors.md:70:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"$AcrScope = az acr show --name <acr-name> --resource-group <resource-group> --query id -o tsv","category":"blocker","line_end":70,"severity":"low","line_start":70},{"id":"blocker:references/recipes/azd/errors.md:72:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"--assignee-object-id $PrincipalId `","category":"blocker","line_end":72,"severity":"low","line_start":72},{"id":"blocker:references/recipes/azd/errors.md:119:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"> 💡 **Prevention:** To avoid this in future deployments, ensure the Bicep template includes the `Ac","category":"blocker","line_end":119,"severity":"low","line_start":119},{"id":"blocker:references/recipes/azd/errors.md:235:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"Error: Invalid value for variable \"environment_name\"","category":"blocker","line_end":235,"severity":"low","line_start":235},{"id":"blocker:references/recipes/azd/errors.md:258:system-reconnaissance","file":"references/recipes/azd/errors.md","pattern":"System reconnaissance","snippet":"azd env set TF_VAR_subscription_id \"$(azd env get-value AZURE_SUBSCRIPTION_ID)\"","category":"blocker","line_end":258,"severity":"low","line_start":258},{"id":"network:references/recipes/azd/functions-deploy.md:68:python-http-libraries","file":"references/recipes/azd/functions-deploy.md","pattern":"Python HTTP libraries","snippet":"> Azure Functions `[HttpTrigger]` with `\"get\"` does **not** automatically handle HEAD requests. HEAD","category":"network","line_end":68,"severity":"low","line_start":68},{"id":"network:references/recipes/azd/functions-deploy.md:74:hardcoded-url","file":"references/recipes/azd/functions-deploy.md","pattern":"Hardcoded URL","snippet":"curl -s -o /dev/null -w \"%{http_code}\" \"https://<func-name>.azurewebsites.net/api/<route>\"","category":"network","line_end":74,"severity":"low","line_start":74},{"id":"network:references/recipes/azd/functions-deploy.md:77:hardcoded-url","file":"references/recipes/azd/functions-deploy.md","pattern":"Hardcoded URL","snippet":"curl -s -o /dev/null -w \"Status: %{http_code}\\nRedirect: %{redirect_url}\" \"https://<func-name>.azure","category":"network","line_end":77,"severity":"low","line_start":77},{"id":"network:references/recipes/azd/functions-deploy.md:80:hardcoded-url","file":"references/recipes/azd/functions-deploy.md","pattern":"Hardcoded URL","snippet":"curl -sS -D - -o /dev/null \"https://<func-name>.azurewebsites.net/api/<route>\"","category":"network","line_end":80,"severity":"low","line_start":80},{"id":"network:references/recipes/azd/functions-deploy.md:87:hardcoded-url","file":"references/recipes/azd/functions-deploy.md","pattern":"Hardcoded URL","snippet":"curl -I \"https://<func-name>.azurewebsites.net/api/<route>\"","category":"network","line_end":87,"severity":"low","line_start":87},{"id":"filesystem:references/recipes/azd/functions-deploy.md:103:path-traversal-sequence","file":"references/recipes/azd/functions-deploy.md","pattern":"Path traversal sequence","snippet":"For automated deployments with azd, see [cicd/README.md](../cicd/README.md) for GitHub Actions and A","category":"filesystem","line_end":103,"severity":"high","line_start":103},{"id":"filesystem:references/recipes/azd/functions-deploy.md:74:standard-device-file-access","file":"references/recipes/azd/functions-deploy.md","pattern":"Standard device file access","snippet":"curl -s -o /dev/null -w \"%{http_code}\" \"https://<func-name>.azurewebsites.net/api/<route>\"","category":"filesystem","line_end":74,"severity":"low","line_start":74},{"id":"filesystem:references/recipes/azd/functions-deploy.md:77:standard-device-file-access","file":"references/recipes/azd/functions-deploy.md","pattern":"Standard device file access","snippet":"curl -s -o /dev/null -w \"Status: %{http_code}\\nRedirect: %{redirect_url}\" \"https://<func-name>.azure","category":"filesystem","line_end":77,"severity":"low","line_start":77},{"id":"filesystem:references/recipes/azd/functions-deploy.md:80:standard-device-file-access","file":"references/recipes/azd/functions-deploy.md","pattern":"Standard device file access","snippet":"curl -sS -D - -o /dev/null \"https://<func-name>.azurewebsites.net/api/<route>\"","category":"filesystem","line_end":80,"severity":"low","line_start":80},{"id":"sensitive:references/recipes/azd/functions-deploy.md:9:azure-credentials-directory","file":"references/recipes/azd/functions-deploy.md","pattern":"Azure credentials directory","snippet":"- `.azure/deployment-plan.md` status = `Validated`","category":"sensitive","line_end":9,"severity":"critical","line_start":9},{"id":"external_commands:references/recipes/azd/post-deployment.md:38:shell-command-substitution","file":"references/recipes/azd/post-deployment.md","pattern":"Shell command substitution","snippet":"eval $(azd env get-values)","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:references/recipes/azd/post-deployment.md:76:shell-command-substitution","file":"references/recipes/azd/post-deployment.md","pattern":"Shell command substitution","snippet":"ENDPOINT=$(azd env get-values | grep SERVICE_.*_URI | cut -d'=' -f2)","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:references/recipes/azd/post-deployment.md:45:powershell-invocation","file":"references/recipes/azd/post-deployment.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":45,"severity":"high","line_start":45},{"id":"external_commands:references/recipes/azd/post-deployment.md:46:powershell-invocation","file":"references/recipes/azd/post-deployment.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":46,"severity":"high","line_start":46},{"id":"external_commands:references/recipes/azd/post-deployment.md:85:powershell-invocation","file":"references/recipes/azd/post-deployment.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":85,"severity":"high","line_start":85},{"id":"external_commands:references/recipes/azd/post-deployment.md:86:powershell-invocation","file":"references/recipes/azd/post-deployment.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":86,"severity":"high","line_start":86},{"id":"blocker:references/recipes/azd/post-deployment.md:109:system-reconnaissance","file":"references/recipes/azd/post-deployment.md","pattern":"System reconnaissance","snippet":"| `Invalid object name` | Migrations not applied | Run EF migrations per [ef-migrations.md](ef-migra","category":"blocker","line_end":109,"severity":"low","line_start":109},{"id":"filesystem:references/recipes/azd/README.md:14:path-traversal-sequence","file":"references/recipes/azd/README.md","pattern":"Path traversal sequence","snippet":"- **Subscription and location confirmed** → See [Pre-deploy Checklist](../../pre-deploy-checklist.md","category":"filesystem","line_end":14,"severity":"high","line_start":14},{"id":"filesystem:references/recipes/azd/README.md:22:path-traversal-sequence","file":"references/recipes/azd/README.md","pattern":"Path traversal sequence","snippet":"| 3 | **RBAC health check** *(Container Apps + ACR only)* | After provisioning, verify `AcrPull` rol","category":"filesystem","line_end":22,"severity":"high","line_start":22},{"id":"filesystem:references/recipes/azd/README.md:77:path-traversal-sequence","file":"references/recipes/azd/README.md","pattern":"Path traversal sequence","snippet":"- [Pre-deploy Checklist](../../pre-deploy-checklist.md) — **REQUIRED**","category":"filesystem","line_end":77,"severity":"high","line_start":77},{"id":"sensitive:references/recipes/azd/README.md:10:azure-credentials-directory","file":"references/recipes/azd/README.md","pattern":"Azure credentials directory","snippet":"- `.azure/deployment-plan.md` exists with status `Validated`","category":"sensitive","line_end":10,"severity":"critical","line_start":10},{"id":"blocker:references/recipes/azd/README.md:36:system-reconnaissance","file":"references/recipes/azd/README.md","pattern":"System reconnaissance","snippet":"| `azd up --location eastus2` | `--location` is not a valid flag for `azd up` |","category":"blocker","line_end":36,"severity":"low","line_start":36},{"id":"blocker:references/recipes/azd/README.md:39:system-reconnaissance","file":"references/recipes/azd/README.md","pattern":"System reconnaissance","snippet":"| Setting AZURE_LOCATION without checking RG | \"Invalid resource group location\" if RG exists elsewh","category":"blocker","line_end":39,"severity":"low","line_start":39},{"id":"blocker:references/recipes/azd/README.md:41:system-reconnaissance","file":"references/recipes/azd/README.md","pattern":"System reconnaissance","snippet":"| `language: html` or `language: static` | Not valid - use `language: js` with `dist: .` for static ","category":"blocker","line_end":41,"severity":"low","line_start":41},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.ps1:49:shell-command-substitution","file":"references/recipes/azd/scripts/apply-migrations.ps1","pattern":"Shell command substitution","snippet":"$ConnectionString = \"Server=tcp:$($env:SQL_SERVER).database.windows.net,1433;Database=$($env:SQL_DAT","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.ps1:12:powershell-invocation","file":"references/recipes/azd/scripts/apply-migrations.ps1","pattern":"PowerShell invocation","snippet":"#         shell: pwsh","category":"external_commands","line_end":12,"severity":"high","line_start":12},{"id":"blocker:references/recipes/azd/scripts/apply-migrations.ps1:21:system-reconnaissance","file":"references/recipes/azd/scripts/apply-migrations.ps1","pattern":"System reconnaissance","snippet":"#   - A valid managed identity or Entra-authenticated session","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.sh:13:powershell-invocation","file":"references/recipes/azd/scripts/apply-migrations.sh","pattern":"PowerShell invocation","snippet":"#         shell: pwsh","category":"external_commands","line_end":13,"severity":"high","line_start":13},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.sh:1:unix-shell-invocation","file":"references/recipes/azd/scripts/apply-migrations.sh","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":1,"severity":"medium","line_start":1},{"id":"filesystem:references/recipes/azd/scripts/apply-migrations.sh:47:hidden-file-access","file":"references/recipes/azd/scripts/apply-migrations.sh","pattern":"Hidden file access","snippet":"export PATH=\"$PATH:$HOME/.dotnet/tools\"","category":"filesystem","line_end":47,"severity":"medium","line_start":47},{"id":"filesystem:references/recipes/azd/scripts/apply-migrations.sh:44:standard-device-file-access","file":"references/recipes/azd/scripts/apply-migrations.sh","pattern":"Standard device file access","snippet":"if ! dotnet tool list --global 2>/dev/null | grep -q '^\\s*dotnet-ef\\s'; then","category":"filesystem","line_end":44,"severity":"low","line_start":44},{"id":"blocker:references/recipes/azd/scripts/apply-migrations.sh:22:system-reconnaissance","file":"references/recipes/azd/scripts/apply-migrations.sh","pattern":"System reconnaissance","snippet":"#   - A valid managed identity or Entra-authenticated session","category":"blocker","line_end":22,"severity":"low","line_start":22},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:83:ruby-shell-backtick-execution","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"Ruby/shell backtick execution","snippet":"az sql db query `","category":"external_commands","line_end":84,"severity":"medium","line_start":83},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:85:ruby-shell-backtick-execution","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"Ruby/shell backtick execution","snippet":"--database $env:SQL_DATABASE `","category":"external_commands","line_end":86,"severity":"medium","line_start":85},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:106:shell-command-substitution","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"Shell command substitution","snippet":"$ConnectionString = \"Server=tcp:$($env:SQL_SERVER).database.windows.net,1433;Database=$($env:SQL_DAT","category":"external_commands","line_end":106,"severity":"medium","line_start":106},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:12:powershell-invocation","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"PowerShell invocation","snippet":"#         shell: pwsh","category":"external_commands","line_end":12,"severity":"high","line_start":12},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:51:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":51,"severity":"low","line_start":51},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:52:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":52,"severity":"low","line_start":52},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:59:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":59,"severity":"low","line_start":59},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:60:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":60,"severity":"low","line_start":60},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:67:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":67,"severity":"low","line_start":67},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:68:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.ps1","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":68,"severity":"low","line_start":68},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.sh:13:powershell-invocation","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"PowerShell invocation","snippet":"#         shell: pwsh","category":"external_commands","line_end":13,"severity":"high","line_start":13},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.sh:1:unix-shell-invocation","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":1,"severity":"medium","line_start":1},{"id":"filesystem:references/recipes/azd/scripts/grant-and-migrate.sh:103:hidden-file-access","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"Hidden file access","snippet":"export PATH=\"$PATH:$HOME/.dotnet/tools\"","category":"filesystem","line_end":103,"severity":"medium","line_start":103},{"id":"filesystem:references/recipes/azd/scripts/grant-and-migrate.sh:54:standard-device-file-access","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"Standard device file access","snippet":"if ! az extension show --name rdbms-connect >/dev/null 2>&1; then","category":"filesystem","line_end":54,"severity":"low","line_start":54},{"id":"filesystem:references/recipes/azd/scripts/grant-and-migrate.sh:100:standard-device-file-access","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"Standard device file access","snippet":"if ! dotnet tool list --global 2>/dev/null | grep -q '^\\s*dotnet-ef\\s'; then","category":"filesystem","line_end":100,"severity":"low","line_start":100},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:73:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":73,"severity":"low","line_start":73},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:74:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":74,"severity":"low","line_start":74},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:81:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":81,"severity":"low","line_start":81},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:82:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":82,"severity":"low","line_start":82},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:89:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":89,"severity":"low","line_start":89},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:90:system-reconnaissance","file":"references/recipes/azd/scripts/grant-and-migrate.sh","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:48:ruby-shell-backtick-execution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Ruby/shell backtick execution","snippet":"--server $env:SQL_SERVER `","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:50:ruby-shell-backtick-execution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Ruby/shell backtick execution","snippet":"--resource-group $env:AZURE_RESOURCE_GROUP `","category":"external_commands","line_end":51,"severity":"medium","line_start":50},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:159:ruby-shell-backtick-execution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Ruby/shell backtick execution","snippet":"--server $env:SQL_SERVER `","category":"external_commands","line_end":160,"severity":"medium","line_start":159},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:161:ruby-shell-backtick-execution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Ruby/shell backtick execution","snippet":"--resource-group $env:AZURE_RESOURCE_GROUP `","category":"external_commands","line_end":162,"severity":"medium","line_start":161},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:16:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"eval $(azd env get-values)","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:17:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"APP_NAME=$(echo \"$SERVICE_API_NAME\")  # or SERVICE_WEB_NAME","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:83:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"eval $(azd env get-values)","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:130:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"IF NOT EXISTS (SELECT * FROM sys.database_principals WHERE name = '$($env:SERVICE_API_NAME)')","category":"external_commands","line_end":130,"severity":"medium","line_start":130},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:131:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"CREATE USER [$($env:SERVICE_API_NAME)] FROM EXTERNAL PROVIDER;","category":"external_commands","line_end":131,"severity":"medium","line_start":131},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:137:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"WHERE r.name = 'db_datareader' AND m.name = '$($env:SERVICE_API_NAME)'","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:139:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"ALTER ROLE db_datareader ADD MEMBER [$($env:SERVICE_API_NAME)];","category":"external_commands","line_end":139,"severity":"medium","line_start":139},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:145:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"WHERE r.name = 'db_datawriter' AND m.name = '$($env:SERVICE_API_NAME)'","category":"external_commands","line_end":145,"severity":"medium","line_start":145},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:147:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"ALTER ROLE db_datawriter ADD MEMBER [$($env:SERVICE_API_NAME)];","category":"external_commands","line_end":147,"severity":"medium","line_start":147},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:153:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"WHERE r.name = 'db_ddladmin' AND m.name = '$($env:SERVICE_API_NAME)'","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:155:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"ALTER ROLE db_ddladmin ADD MEMBER [$($env:SERVICE_API_NAME)];","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:171:shell-command-substitution","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Shell command substitution","snippet":"eval $(azd env get-values)","category":"external_commands","line_end":171,"severity":"medium","line_start":171},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:32:powershell-invocation","file":"references/recipes/azd/sql-managed-identity.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":32,"severity":"high","line_start":32},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:33:powershell-invocation","file":"references/recipes/azd/sql-managed-identity.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":33,"severity":"high","line_start":33},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:122:powershell-invocation","file":"references/recipes/azd/sql-managed-identity.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":122,"severity":"high","line_start":122},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:184:powershell-invocation","file":"references/recipes/azd/sql-managed-identity.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":184,"severity":"high","line_start":184},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:185:powershell-invocation","file":"references/recipes/azd/sql-managed-identity.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":185,"severity":"high","line_start":185},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:81:unix-shell-invocation","file":"references/recipes/azd/sql-managed-identity.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:96:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":96,"severity":"low","line_start":96},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:97:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:104:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":104,"severity":"low","line_start":104},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:105:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":105,"severity":"low","line_start":105},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:112:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":112,"severity":"low","line_start":112},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:113:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:135:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":135,"severity":"low","line_start":135},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:136:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":136,"severity":"low","line_start":136},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:143:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":143,"severity":"low","line_start":143},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:144:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":144,"severity":"low","line_start":144},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:151:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":151,"severity":"low","line_start":151},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:152:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":152,"severity":"low","line_start":152},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:178:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_role_members drm ON dp.principal_id = drm.member_principal_id","category":"blocker","line_end":178,"severity":"low","line_start":178},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:179:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals dr ON drm.role_principal_id = dr.principal_id","category":"blocker","line_end":179,"severity":"low","line_start":179},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:195:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_role_members drm ON dp.principal_id = drm.member_principal_id","category":"blocker","line_end":195,"severity":"low","line_start":195},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:196:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals dr ON drm.role_principal_id = dr.principal_id","category":"blocker","line_end":196,"severity":"low","line_start":196},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:224:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals r ON drm.role_principal_id = r.principal_id","category":"blocker","line_end":224,"severity":"low","line_start":224},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:225:system-reconnaissance","file":"references/recipes/azd/sql-managed-identity.md","pattern":"System reconnaissance","snippet":"JOIN sys.database_principals m ON drm.member_principal_id = m.principal_id","category":"blocker","line_end":225,"severity":"low","line_start":225},{"id":"external_commands:references/recipes/azd/verify.md:106:ruby-shell-backtick-execution","file":"references/recipes/azd/verify.md","pattern":"Ruby/shell backtick execution","snippet":"--server $env:SQL_SERVER `","category":"external_commands","line_end":107,"severity":"medium","line_start":106},{"id":"external_commands:references/recipes/azd/verify.md:108:ruby-shell-backtick-execution","file":"references/recipes/azd/verify.md","pattern":"Ruby/shell backtick execution","snippet":"--resource-group $env:AZURE_RESOURCE_GROUP `","category":"external_commands","line_end":109,"severity":"medium","line_start":108},{"id":"external_commands:references/recipes/azd/verify.md:132:ruby-shell-backtick-execution","file":"references/recipes/azd/verify.md","pattern":"Ruby/shell backtick execution","snippet":"--server $env:SQL_SERVER `","category":"external_commands","line_end":133,"severity":"medium","line_start":132},{"id":"external_commands:references/recipes/azd/verify.md:134:ruby-shell-backtick-execution","file":"references/recipes/azd/verify.md","pattern":"Ruby/shell backtick execution","snippet":"--resource-group $env:AZURE_RESOURCE_GROUP `","category":"external_commands","line_end":135,"severity":"medium","line_start":134},{"id":"external_commands:references/recipes/azd/verify.md:23:shell-command-substitution","file":"references/recipes/azd/verify.md","pattern":"Shell command substitution","snippet":"ENDPOINT=$(azd env get-values | grep -E \"SERVICE_.*_URI|.*_ENDPOINT\" | head -1 | cut -d'=' -f2)","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:references/recipes/azd/verify.md:85:shell-command-substitution","file":"references/recipes/azd/verify.md","pattern":"Shell command substitution","snippet":"eval $(azd env get-values)","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:references/recipes/azd/verify.md:29:powershell-invocation","file":"references/recipes/azd/verify.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":29,"severity":"high","line_start":29},{"id":"external_commands:references/recipes/azd/verify.md:30:powershell-invocation","file":"references/recipes/azd/verify.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":30,"severity":"high","line_start":30},{"id":"external_commands:references/recipes/azd/verify.md:96:powershell-invocation","file":"references/recipes/azd/verify.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":96,"severity":"high","line_start":96},{"id":"external_commands:references/recipes/azd/verify.md:97:powershell-invocation","file":"references/recipes/azd/verify.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":97,"severity":"high","line_start":97},{"id":"external_commands:references/recipes/azd/verify.md:129:powershell-invocation","file":"references/recipes/azd/verify.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":129,"severity":"high","line_start":129},{"id":"external_commands:references/recipes/azd/verify.md:130:powershell-invocation","file":"references/recipes/azd/verify.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":130,"severity":"high","line_start":130},{"id":"network:references/recipes/azd/verify.md:16:hardcoded-url","file":"references/recipes/azd/verify.md","pattern":"Hardcoded URL","snippet":"api - Endpoint: https://api-xxxx.azurecontainerapps.io","category":"network","line_end":16,"severity":"low","line_start":16},{"id":"network:references/recipes/azd/verify.md:68:hardcoded-url","file":"references/recipes/azd/verify.md","pattern":"Hardcoded URL","snippet":"| apiservice | https://apiservice.xxx.azurecontainerapps.io |","category":"network","line_end":68,"severity":"low","line_start":68},{"id":"network:references/recipes/azd/verify.md:70:hardcoded-url","file":"references/recipes/azd/verify.md","pattern":"Hardcoded URL","snippet":"Aspire Dashboard: https://aspire-dashboard.xxx.azurecontainerapps.io","category":"network","line_end":70,"severity":"low","line_start":70},{"id":"blocker:references/recipes/azd/verify.md:73:system-reconnaissance","file":"references/recipes/azd/verify.md","pattern":"System reconnaissance","snippet":"> ⚠️ **Always use fully-qualified URLs with the `https://` scheme.** If a command returns a bare hos","category":"blocker","line_end":73,"severity":"low","line_start":73},{"id":"blocker:references/recipes/azd/verify.md:161:system-reconnaissance","file":"references/recipes/azd/verify.md","pattern":"System reconnaissance","snippet":"| \"Invalid object name\" errors | Migrations not applied | See [ef-migrations.md](ef-migrations.md) |","category":"blocker","line_end":161,"severity":"low","line_start":161},{"id":"blocker:references/recipes/bicep/errors.md:7:system-reconnaissance","file":"references/recipes/bicep/errors.md","pattern":"System reconnaissance","snippet":"| Invalid property | Check `mcp_bicep_get_az_resource_type_schema` |","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"filesystem:references/recipes/bicep/README.md:10:path-traversal-sequence","file":"references/recipes/bicep/README.md","pattern":"Path traversal sequence","snippet":"- **Subscription and location confirmed** → See [Pre-Deploy Checklist](../../pre-deploy-checklist.md","category":"filesystem","line_end":10,"severity":"high","line_start":10},{"id":"filesystem:references/recipes/bicep/README.md:16:path-traversal-sequence","file":"references/recipes/bicep/README.md","pattern":"Path traversal sequence","snippet":"| 1 | **[Pre-deploy checklist](../../pre-deploy-checklist.md)** | Confirm subscription/location with","category":"filesystem","line_end":16,"severity":"high","line_start":16},{"id":"sensitive:references/recipes/bicep/README.md:8:azure-credentials-directory","file":"references/recipes/bicep/README.md","pattern":"Azure credentials directory","snippet":"- `.azure/deployment-plan.md` exists with status `Validated`","category":"sensitive","line_end":8,"severity":"critical","line_start":8},{"id":"network:references/recipes/bicep/verify.md:18:hardcoded-url","file":"references/recipes/bicep/verify.md","pattern":"Hardcoded URL","snippet":"curl -s https://<endpoint>/health | jq .","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"blocker:references/recipes/bicep/verify.md:31:system-reconnaissance","file":"references/recipes/bicep/verify.md","pattern":"System reconnaissance","snippet":"Present a summary including all service URLs as fully-qualified `https://` links. If a deployment ou","category":"blocker","line_end":31,"severity":"low","line_start":31},{"id":"external_commands:references/recipes/cicd/examples/azdo-azd.yml:21:shell-command-substitution","file":"references/recipes/cicd/examples/azdo-azd.yml","pattern":"Shell command substitution","snippet":"AZURE_ENV_NAME: $(AZURE_ENV_NAME)","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:references/recipes/cicd/examples/azdo-azd.yml:22:shell-command-substitution","file":"references/recipes/cicd/examples/azdo-azd.yml","pattern":"Shell command substitution","snippet":"AZURE_LOCATION: $(AZURE_LOCATION)","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"env_access:references/recipes/cicd/examples/github-azd.yml:26:azure-credential-environment-variables","file":"references/recipes/cicd/examples/github-azd.yml","pattern":"Azure credential environment variables","snippet":"client-id: ${{ secrets.AZURE_CLIENT_ID }}","category":"env_access","line_end":26,"severity":"high","line_start":26},{"id":"env_access:references/recipes/cicd/examples/github-azd.yml:27:azure-credential-environment-variables","file":"references/recipes/cicd/examples/github-azd.yml","pattern":"Azure credential environment variables","snippet":"tenant-id: ${{ secrets.AZURE_TENANT_ID }}","category":"env_access","line_end":27,"severity":"high","line_start":27},{"id":"env_access:references/recipes/cicd/examples/github-bicep.yml:17:azure-credential-environment-variables","file":"references/recipes/cicd/examples/github-bicep.yml","pattern":"Azure credential environment variables","snippet":"client-id: ${{ secrets.AZURE_CLIENT_ID }}","category":"env_access","line_end":17,"severity":"high","line_start":17},{"id":"env_access:references/recipes/cicd/examples/github-bicep.yml:18:azure-credential-environment-variables","file":"references/recipes/cicd/examples/github-bicep.yml","pattern":"Azure credential environment variables","snippet":"tenant-id: ${{ secrets.AZURE_TENANT_ID }}","category":"env_access","line_end":18,"severity":"high","line_start":18},{"id":"env_access:references/recipes/cicd/README.md:30:azure-credential-environment-variables","file":"references/recipes/cicd/README.md","pattern":"Azure credential environment variables","snippet":"2. Add secrets: `AZURE_CLIENT_ID`, `AZURE_TENANT_ID`, `AZURE_SUBSCRIPTION_ID`","category":"env_access","line_end":30,"severity":"high","line_start":30},{"id":"sensitive:references/recipes/cicd/README.md:7:azure-credentials-directory","file":"references/recipes/cicd/README.md","pattern":"Azure credentials directory","snippet":"- `.azure/deployment-plan.md` exists with status `Validated`","category":"sensitive","line_end":7,"severity":"critical","line_start":7},{"id":"network:references/recipes/cicd/verify.md:16:hardcoded-url","file":"references/recipes/cicd/verify.md","pattern":"Hardcoded URL","snippet":"curl -s https://<endpoint>/health | jq .","category":"network","line_end":16,"severity":"low","line_start":16},{"id":"blocker:references/recipes/cicd/verify.md:23:system-reconnaissance","file":"references/recipes/cicd/verify.md","pattern":"System reconnaissance","snippet":"Extract endpoints from the pipeline output or query them directly via `az` CLI. Present a summary in","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"filesystem:references/recipes/terraform/errors.md:9:path-traversal-sequence","file":"references/recipes/terraform/errors.md","pattern":"Path traversal sequence","snippet":"| Literal `{{ .Env.* }}` in variable values | Fix syntax in `main.tfvars.json`: use `${VAR}` (e.g., ","category":"filesystem","line_end":9,"severity":"high","line_start":9},{"id":"sensitive:references/recipes/terraform/errors.md:10:azure-credentials-directory","file":"references/recipes/terraform/errors.md","pattern":"Azure credentials directory","snippet":"| State cleared on each `azd provision` | azd copies Terraform config to `.azure/<env>/infra/` on ea","category":"sensitive","line_end":10,"severity":"critical","line_start":10},{"id":"external_commands:references/recipes/terraform/README.md:103:ruby-shell-backtick-execution","file":"references/recipes/terraform/README.md","pattern":"Ruby/shell backtick execution","snippet":"--name $AppName `","category":"external_commands","line_end":104,"severity":"medium","line_start":103},{"id":"external_commands:references/recipes/terraform/README.md:105:ruby-shell-backtick-execution","file":"references/recipes/terraform/README.md","pattern":"Ruby/shell backtick execution","snippet":"--server $AcrServer `","category":"external_commands","line_end":108,"severity":"medium","line_start":105},{"id":"external_commands:references/recipes/terraform/README.md:109:ruby-shell-backtick-execution","file":"references/recipes/terraform/README.md","pattern":"Ruby/shell backtick execution","snippet":"--name $AppName `","category":"external_commands","line_end":110,"severity":"medium","line_start":109},{"id":"external_commands:references/recipes/terraform/README.md:71:shell-command-substitution","file":"references/recipes/terraform/README.md","pattern":"Shell command substitution","snippet":"ACR_NAME=$(terraform output -raw acr_name)","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:references/recipes/terraform/README.md:72:shell-command-substitution","file":"references/recipes/terraform/README.md","pattern":"Shell command substitution","snippet":"ACR_SERVER=$(terraform output -raw acr_login_server)","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:references/recipes/terraform/README.md:73:shell-command-substitution","file":"references/recipes/terraform/README.md","pattern":"Shell command substitution","snippet":"APP_NAME=$(terraform output -raw container_app_name)","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:references/recipes/terraform/README.md:74:shell-command-substitution","file":"references/recipes/terraform/README.md","pattern":"Shell command substitution","snippet":"RG_NAME=$(terraform output -raw resource_group_name)","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:references/recipes/terraform/README.md:93:powershell-invocation","file":"references/recipes/terraform/README.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":93,"severity":"high","line_start":93},{"id":"external_commands:references/recipes/terraform/README.md:94:powershell-invocation","file":"references/recipes/terraform/README.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":94,"severity":"high","line_start":94},{"id":"filesystem:references/recipes/terraform/README.md:11:path-traversal-sequence","file":"references/recipes/terraform/README.md","pattern":"Path traversal sequence","snippet":"- **Subscription and location confirmed** → See [Pre-Deploy Checklist](../../pre-deploy-checklist.md","category":"filesystem","line_end":11,"severity":"high","line_start":11},{"id":"filesystem:references/recipes/terraform/README.md:17:path-traversal-sequence","file":"references/recipes/terraform/README.md","pattern":"Path traversal sequence","snippet":"| 1 | **[Pre-deploy checklist](../../pre-deploy-checklist.md)** | Confirm subscription/location with","category":"filesystem","line_end":17,"severity":"high","line_start":17},{"id":"filesystem:references/recipes/terraform/README.md:114:path-traversal-sequence","file":"references/recipes/terraform/README.md","pattern":"Path traversal sequence","snippet":"> ⚠️ **Warning:** Step 2 requires the `AcrPull` role assignment to have propagated (1–5 minutes). If","category":"filesystem","line_end":114,"severity":"high","line_start":114},{"id":"sensitive:references/recipes/terraform/README.md:8:azure-credentials-directory","file":"references/recipes/terraform/README.md","pattern":"Azure credentials directory","snippet":"- `.azure/deployment-plan.md` exists with status `Validated`","category":"sensitive","line_end":8,"severity":"critical","line_start":8},{"id":"external_commands:references/recipes/terraform/verify.md:11:shell-command-substitution","file":"references/recipes/terraform/verify.md","pattern":"Shell command substitution","snippet":"curl -s https://$(terraform output -raw api_url)/health | jq .","category":"external_commands","line_end":11,"severity":"medium","line_start":11},{"id":"external_commands:references/recipes/terraform/verify.md:17:shell-command-substitution","file":"references/recipes/terraform/verify.md","pattern":"Shell command substitution","snippet":"az resource list --resource-group $(terraform output -raw resource_group_name) --output table","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"network:references/recipes/terraform/verify.md:11:hardcoded-url","file":"references/recipes/terraform/verify.md","pattern":"Hardcoded URL","snippet":"curl -s https://$(terraform output -raw api_url)/health | jq .","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"blocker:references/recipes/terraform/verify.md:30:system-reconnaissance","file":"references/recipes/terraform/verify.md","pattern":"System reconnaissance","snippet":"Present a summary including all service URLs as fully-qualified `https://` links. If a Terraform out","category":"blocker","line_end":30,"severity":"low","line_start":30},{"id":"filesystem:references/sdk/azd-deployment.md:19:hidden-file-access","file":"references/sdk/azd-deployment.md","pattern":"Hidden file access","snippet":"- Bicep outputs auto-populate .azure/<env>/.env — don't manually edit","category":"filesystem","line_end":19,"severity":"medium","line_start":19},{"id":"sensitive:references/sdk/azd-deployment.md:19:azure-credentials-directory","file":"references/sdk/azd-deployment.md","pattern":"Azure credentials directory","snippet":"- Bicep outputs auto-populate .azure/<env>/.env — don't manually edit","category":"sensitive","line_end":19,"severity":"critical","line_start":19},{"id":"sensitive:references/sdk/azd-deployment.md:19:environment-file-access","file":"references/sdk/azd-deployment.md","pattern":"Environment file access","snippet":"- Bicep outputs auto-populate .azure/<env>/.env — don't manually edit","category":"sensitive","line_end":19,"severity":"high","line_start":19},{"id":"blocker:references/sdk/azd-deployment.md:8:pipe-to-shell-pattern","file":"references/sdk/azd-deployment.md","pattern":"Pipe to shell pattern","snippet":"curl -fsSL https://aka.ms/install-azd.sh | bash","category":"blocker","line_end":8,"severity":"critical","line_start":8},{"id":"filesystem:references/sdk/azure-identity-dotnet.md:12:path-traversal-sequence","file":"references/sdk/azure-identity-dotnet.md","pattern":"Path traversal sequence","snippet":"> **Auth:** `DefaultAzureCredential` is for local development. See [auth-best-practices.md](../auth-","category":"filesystem","line_end":12,"severity":"high","line_start":12},{"id":"filesystem:references/sdk/azure-identity-dotnet.md:20:path-traversal-sequence","file":"references/sdk/azure-identity-dotnet.md","pattern":"Path traversal sequence","snippet":"- Use DefaultAzureCredential for **local development only**. In production, use deterministic creden","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"external_commands:references/sdk/azure-identity-java.md:26:powershell-invocation","file":"references/sdk/azure-identity-java.md","pattern":"PowerShell invocation","snippet":"- Use DefaultAzureCredential for **local development only** (CLI, PowerShell, VS Code). In productio","category":"external_commands","line_end":26,"severity":"high","line_start":26},{"id":"filesystem:references/sdk/azure-identity-java.md:18:path-traversal-sequence","file":"references/sdk/azure-identity-java.md","pattern":"Path traversal sequence","snippet":"> **Auth:** `DefaultAzureCredential` is for local development. See [auth-best-practices.md](../auth-","category":"filesystem","line_end":18,"severity":"high","line_start":18},{"id":"filesystem:references/sdk/azure-identity-java.md:26:path-traversal-sequence","file":"references/sdk/azure-identity-java.md","pattern":"Path traversal sequence","snippet":"- Use DefaultAzureCredential for **local development only** (CLI, PowerShell, VS Code). In productio","category":"filesystem","line_end":26,"severity":"high","line_start":26},{"id":"external_commands:references/sdk/azure-identity-py.md:22:powershell-invocation","file":"references/sdk/azure-identity-py.md","pattern":"PowerShell invocation","snippet":"- Use DefaultAzureCredential for **local development only** (CLI, PowerShell, VS Code). In productio","category":"external_commands","line_end":22,"severity":"high","line_start":22},{"id":"filesystem:references/sdk/azure-identity-py.md:14:path-traversal-sequence","file":"references/sdk/azure-identity-py.md","pattern":"Path traversal sequence","snippet":"> **Auth:** `DefaultAzureCredential` is for local development. See [auth-best-practices.md](../auth-","category":"filesystem","line_end":14,"severity":"high","line_start":14},{"id":"filesystem:references/sdk/azure-identity-py.md:22:path-traversal-sequence","file":"references/sdk/azure-identity-py.md","pattern":"Path traversal sequence","snippet":"- Use DefaultAzureCredential for **local development only** (CLI, PowerShell, VS Code). In productio","category":"filesystem","line_end":22,"severity":"high","line_start":22},{"id":"env_access:references/sdk/azure-identity-py.md:27:azure-credential-environment-variables","file":"references/sdk/azure-identity-py.md","pattern":"Azure credential environment variables","snippet":"- Set AZURE_CLIENT_ID env var for user-assigned managed identities","category":"env_access","line_end":27,"severity":"high","line_start":27},{"id":"external_commands:references/sdk/azure-identity-ts.md:20:powershell-invocation","file":"references/sdk/azure-identity-ts.md","pattern":"PowerShell invocation","snippet":"- Use DefaultAzureCredential for **local development only** (CLI, PowerShell, VS Code). In productio","category":"external_commands","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:references/sdk/azure-identity-ts.md:12:path-traversal-sequence","file":"references/sdk/azure-identity-ts.md","pattern":"Path traversal sequence","snippet":"> **Auth:** `DefaultAzureCredential` is for local development. See [auth-best-practices.md](../auth-","category":"filesystem","line_end":12,"severity":"high","line_start":12},{"id":"filesystem:references/sdk/azure-identity-ts.md:20:path-traversal-sequence","file":"references/sdk/azure-identity-ts.md","pattern":"Path traversal sequence","snippet":"- Use DefaultAzureCredential for **local development only** (CLI, PowerShell, VS Code). In productio","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"external_commands:references/troubleshooting.md:156:shell-command-substitution","file":"references/troubleshooting.md","pattern":"Shell command substitution","snippet":"azd env set AZURE_CONTAINER_REGISTRY_ENDPOINT $(az acr list --resource-group <resource-group-name> -","category":"external_commands","line_end":156,"severity":"medium","line_start":156},{"id":"external_commands:references/troubleshooting.md:159:shell-command-substitution","file":"references/troubleshooting.md","pattern":"Shell command substitution","snippet":"azd env set AZURE_CONTAINER_REGISTRY_MANAGED_IDENTITY_ID $(az identity list --resource-group <resour","category":"external_commands","line_end":159,"severity":"medium","line_start":159},{"id":"external_commands:references/troubleshooting.md:162:shell-command-substitution","file":"references/troubleshooting.md","pattern":"Shell command substitution","snippet":"azd env set MANAGED_IDENTITY_CLIENT_ID $(az identity list --resource-group <resource-group-name> --q","category":"external_commands","line_end":162,"severity":"medium","line_start":162},{"id":"external_commands:references/troubleshooting.md:165:powershell-invocation","file":"references/troubleshooting.md","pattern":"PowerShell invocation","snippet":"**PowerShell:**","category":"external_commands","line_end":165,"severity":"high","line_start":165},{"id":"external_commands:references/troubleshooting.md:166:powershell-invocation","file":"references/troubleshooting.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":166,"severity":"high","line_start":166},{"id":"network:references/troubleshooting.md:115:hardcoded-url","file":"references/troubleshooting.md","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#\",","category":"network","line_end":115,"severity":"low","line_start":115},{"id":"network:references/troubleshooting.md:116:hardcoded-ip-address","file":"references/troubleshooting.md","pattern":"Hardcoded IP address","snippet":"\"contentVersion\": \"1.0.0.0\",","category":"network","line_end":116,"severity":"medium","line_start":116},{"id":"blocker:references/troubleshooting.md:9:system-reconnaissance","file":"references/troubleshooting.md","pattern":"System reconnaissance","snippet":"**Cause:** Using unsupported language value in `azure.yaml`. Neither `html` nor `static` are valid l","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"blocker:references/troubleshooting.md:23:system-reconnaissance","file":"references/troubleshooting.md","pattern":"System reconnaissance","snippet":"Valid language values: `python`, `js`, `ts`, `java`, `dotnet`, `go` (or omit for staticwebapp withou","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **PREREQUISITE**: The **azure-validate** skill **MUST** be invoked and completed with status `Vali","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> 1. **azure-prepare** was invoked and completed → `.azure/deployment-plan.md` exists","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> 2. **azure-validate** was invoked and passed → plan status = `Validated`","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - Status not `Validated`? → Invoke **azure-validate** skill first","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> You are **FORBIDDEN** from changing the plan status to `Validated` yourself. Only the **azure-vali","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> `azure-prepare` → `azure-validate` → `azure-deploy`","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Run `azd up`, `azd deploy`, or `az deployment` on a prepared project","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `.azure/deployment-plan.md` must exist with status `Validated`","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. ⛔ **Destructive actions require `ask_user`** — [global-rules](references/global-rules.md)","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Scope: deployment execution only** — This skill owns execution of `azd up`, `azd deploy`, `terr","category":"external_commands","line_end":53,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 1 | **Check Plan** — Read `.azure/deployment-plan.md`, verify status = `Validated` AND **Validatio","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 3 | **Load Recipe** — Based on `recipe.type` in `.azure/deployment-plan.md` | [recipes/README.md](","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 4 | **RBAC Health Check** — For Container Apps + ACR with managed identity: run `azd provision --n","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 7 | **Handle Errors** — See recipe's `errors.md` | — |","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 10 | **Report Results** — Present deployed endpoint URLs to the user as fully-qualified `https://`","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> When presenting endpoint URLs to the user, you **MUST** always use fully-qualified URLs with the `","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mcp_azure_mcp_subscription_list` | List available subscriptions |","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mcp_azure_mcp_group_list` | List resource groups in subscription |","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mcp_azure_mcp_azd` | Execute AZD commands |","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `azure__role` | List role assignments for live RBAC verification (step 9) |","category":"external_commands","line_end":92,"severity":"medium","line_start":92},{"id":"network:SKILL.md:45:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> **APIM / AI Gateway**: Use this skill to deploy applications whose APIM/AI gateway infrastructure ","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:SKILL.md:70:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| 10 | **Report Results** — Present deployed endpoint URLs to the user as fully-qualified `https://`","category":"network","line_end":70,"severity":"low","line_start":70},{"id":"network:SKILL.md:74:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> When presenting endpoint URLs to the user, you **MUST** always use fully-qualified URLs with the `","category":"network","line_end":74,"severity":"low","line_start":74},{"id":"sensitive:SKILL.md:3:azure-credentials-directory","file":"SKILL.md","pattern":"Azure credentials directory","snippet":"description: \"Execute Azure deployments for ALREADY-PREPARED applications that have existing .azure/","category":"sensitive","line_end":3,"severity":"critical","line_start":3},{"id":"sensitive:SKILL.md:19:azure-credentials-directory","file":"SKILL.md","pattern":"Azure credentials directory","snippet":"> 1. **azure-prepare** was invoked and completed → `.azure/deployment-plan.md` exists","category":"sensitive","line_end":19,"severity":"critical","line_start":19},{"id":"sensitive:SKILL.md:50:azure-credentials-directory","file":"SKILL.md","pattern":"Azure credentials directory","snippet":"2. `.azure/deployment-plan.md` must exist with status `Validated`","category":"sensitive","line_end":50,"severity":"critical","line_start":50},{"id":"sensitive:SKILL.md:61:azure-credentials-directory","file":"SKILL.md","pattern":"Azure credentials directory","snippet":"| 1 | **Check Plan** — Read `.azure/deployment-plan.md`, verify status = `Validated` AND **Validatio","category":"sensitive","line_end":61,"severity":"critical","line_start":61},{"id":"sensitive:SKILL.md:63:azure-credentials-directory","file":"SKILL.md","pattern":"Azure credentials directory","snippet":"| 3 | **Load Recipe** — Based on `recipe.type` in `.azure/deployment-plan.md` | [recipes/README.md](","category":"sensitive","line_end":63,"severity":"critical","line_start":63},{"id":"blocker:SKILL.md:74:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"> When presenting endpoint URLs to the user, you **MUST** always use fully-qualified URLs with the `","category":"blocker","line_end":74,"severity":"low","line_start":74}],"finding_verdicts":[{"id":"external_commands:references/auth-best-practices.md:16:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/auth-best-practices.md:81:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/auth-best-practices.md:87:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/auth-best-practices.md:43:environment-variable-access-dot-notation","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:101:environment-variable-access-dot-notation","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:104:environment-variable-access-dot-notation","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:105:environment-variable-access-dot-notation","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:43:environment-variable-object","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:101:environment-variable-object","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:104:environment-variable-object","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:105:environment-variable-object","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:57:python-getenv-function","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:57:getenv-function-call","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:69:getenv-function-call","reason":"This documentation example reads an environment selector or managed-identity client identifier. It does not enumerate, print, or transmit environment secrets.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/auth-best-practices.md:104:azure-credential-environment-variables","reason":"The text reads or names AZURE_CLIENT_ID for user-assigned managed identity selection. A client identifier is not a secret and is not exfiltrated.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/auth-best-practices.md:105:azure-credential-environment-variables","reason":"The text reads or names AZURE_CLIENT_ID for user-assigned managed identity selection. A client identifier is not a secret and is not exfiltrated.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/auth-best-practices.md:43:environment-file-access","reason":"The text warns that AZD manages a project .env file. It neither opens nor discloses the file contents.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/auth-best-practices.md:101:environment-file-access","reason":"The text warns that AZD manages a project .env file. It neither opens nor discloses the file contents.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/auth-best-practices.md:104:environment-file-access","reason":"The text warns that AZD manages a project .env file. It neither opens nor discloses the file contents.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/auth-best-practices.md:105:environment-file-access","reason":"The text warns that AZD manages a project .env file. It neither opens nor discloses the file contents.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/live-role-verification.md:97:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/live-role-verification.md:25:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/live-role-verification.md:93:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/live-role-verification.md:53:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/live-role-verification.md:97:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/pre-deploy-checklist.md:121:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:181:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:322:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:324:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:327:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:348:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:365:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:399:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:401:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:339:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/pre-deploy-checklist.md:356:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/pre-deploy-checklist.md:374:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/pre-deploy-checklist.md:439:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/pre-deploy-checklist.md:118:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:119:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:178:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:179:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:318:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:319:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:345:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:346:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:362:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:363:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:395:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:396:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:443:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:444:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:457:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/pre-deploy-checklist.md:458:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/pre-deploy-checklist.md:378:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/pre-deploy-checklist.md:46:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/pre-deploy-checklist.md:59:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pre-deploy-checklist.md:66:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/pre-deploy-checklist.md:259:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/pre-deploy-checklist.md:359:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/pre-deploy-checklist.md:367:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/pre-deploy-checklist.md:376:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/pre-deploy-checklist.md:400:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/recipes/azcli/README.md:10:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azcli/README.md:16:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/recipes/azcli/README.md:8:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azcli/verify.md:40:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azcli/verify.md:44:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azcli/verify.md:48:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azcli/verify.md:52:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azcli/verify.md:53:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"network:references/recipes/azcli/verify.md:10:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azcli/verify.md:41:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azcli/verify.md:45:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azcli/verify.md:49:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azcli/verify.md:56:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azcli/verify.md:60:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azcli/verify.md:64:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azcli/verify.md:67:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/ef-migrations.md:56:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/ef-migrations.md:14:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/ef-migrations.md:15:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/ef-migrations.md:33:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/ef-migrations.md:59:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/ef-migrations.md:60:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/ef-migrations.md:90:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/recipes/azd/ef-migrations.md:43:hidden-file-in-home-directory","reason":"The path is the standard .NET global-tools directory added to PATH. The command does not inspect credentials or unrelated hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/ef-migrations.md:43:hidden-file-access","reason":"The path is the standard .NET global-tools directory added to PATH. The command does not inspect credentials or unrelated hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/ef-migrations.md:10:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:72:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:74:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:47:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:48:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:65:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:80:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:153:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:154:shell-command-substitution","reason":"This captures a live registry password, and the next command passes it through docker login -p. Process inspection and logs can expose it.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/recipes/azd/errors.md:202:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:205:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:208:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:256:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:257:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:258:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/errors.md:52:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:53:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:68:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:69:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:98:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:99:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:159:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:160:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:211:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/errors.md:212:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/recipes/azd/errors.md:24:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/errors.md:28:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/errors.md:48:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:49:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:55:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:56:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:62:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:65:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:70:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:72:system-reconnaissance","reason":"This is a read-only Azure RBAC or resource query scoped to the deployment. It does not inspect the local host or send results externally.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/errors.md:119:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/errors.md:235:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/errors.md:258:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"network:references/recipes/azd/functions-deploy.md:68:python-http-libraries","reason":"The text names an Azure Functions HttpTrigger attribute. It does not import a Python HTTP library or issue a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:references/recipes/azd/functions-deploy.md:74:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azd/functions-deploy.md:77:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azd/functions-deploy.md:80:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azd/functions-deploy.md:87:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/recipes/azd/functions-deploy.md:103:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/functions-deploy.md:74:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/recipes/azd/functions-deploy.md:77:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/recipes/azd/functions-deploy.md:80:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/recipes/azd/functions-deploy.md:9:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/post-deployment.md:38:shell-command-substitution","reason":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/recipes/azd/post-deployment.md:76:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/post-deployment.md:45:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/post-deployment.md:46:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/post-deployment.md:85:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/post-deployment.md:86:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/post-deployment.md:109:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/README.md:14:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/README.md:22:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/README.md:77:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/recipes/azd/README.md:10:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/README.md:36:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/README.md:39:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/README.md:41:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.ps1:49:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.ps1:12:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/apply-migrations.ps1:21:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.sh:13:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/scripts/apply-migrations.sh:1:unix-shell-invocation","reason":"The shebang only declares the interpreter for an explicit deployment helper script. It is not a dynamic or hidden shell invocation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/scripts/apply-migrations.sh:47:hidden-file-access","reason":"The path is the standard .NET global-tools directory added to PATH. The command does not inspect credentials or unrelated hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/scripts/apply-migrations.sh:44:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/apply-migrations.sh:22:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:83:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:85:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:106:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.ps1:12:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:51:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:52:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:59:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:60:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:67:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.ps1:68:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.sh:13:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/scripts/grant-and-migrate.sh:1:unix-shell-invocation","reason":"The shebang only declares the interpreter for an explicit deployment helper script. It is not a dynamic or hidden shell invocation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/scripts/grant-and-migrate.sh:103:hidden-file-access","reason":"The path is the standard .NET global-tools directory added to PATH. The command does not inspect credentials or unrelated hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/azd/scripts/grant-and-migrate.sh:54:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/recipes/azd/scripts/grant-and-migrate.sh:100:standard-device-file-access","reason":"The command redirects routine output to /dev/null. It does not read device data or access a sensitive filesystem target.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:73:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:74:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:81:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:82:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:89:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/scripts/grant-and-migrate.sh:90:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:48:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:50:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:159:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:161:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:16:shell-command-substitution","reason":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:17:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:83:shell-command-substitution","reason":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:130:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:131:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:137:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:139:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:145:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:147:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:153:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:155:shell-command-substitution","reason":"This is PowerShell variable interpolation inside a connection string or SQL template. The interpolated text is not executed as a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:171:shell-command-substitution","reason":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:32:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:33:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:122:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:184:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:185:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/sql-managed-identity.md:81:unix-shell-invocation","reason":"The shebang only declares the interpreter for an explicit deployment helper script. It is not a dynamic or hidden shell invocation.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:96:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:97:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:104:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:105:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:112:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:113:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:135:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:136:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:143:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:144:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:151:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:152:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:178:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:179:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:195:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:196:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:224:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/recipes/azd/sql-managed-identity.md:225:system-reconnaissance","reason":"This SQL joins database catalog views to verify role membership. It is not host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:106:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:108:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:132:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:134:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:23:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/azd/verify.md:85:shell-command-substitution","reason":"eval executes AZD environment values as shell code. A crafted project environment value can run arbitrary commands with the agent privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:references/recipes/azd/verify.md:29:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:30:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:96:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:97:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:129:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/azd/verify.md:130:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"network:references/recipes/azd/verify.md:16:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azd/verify.md:68:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/recipes/azd/verify.md:70:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/azd/verify.md:73:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/azd/verify.md:161:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/recipes/bicep/errors.md:7:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/bicep/README.md:10:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/bicep/README.md:16:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/recipes/bicep/README.md:8:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"network:references/recipes/bicep/verify.md:18:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/bicep/verify.md:31:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/recipes/cicd/examples/azdo-azd.yml:21:shell-command-substitution","reason":"This is Azure DevOps pipeline variable syntax, not shell command substitution. The value is supplied through the pipeline environment.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/cicd/examples/azdo-azd.yml:22:shell-command-substitution","reason":"This is Azure DevOps pipeline variable syntax, not shell command substitution. The value is supplied through the pipeline environment.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/recipes/cicd/examples/github-azd.yml:26:azure-credential-environment-variables","reason":"The workflow references configured Azure OIDC identifiers through pipeline secret syntax. It does not print or transmit them outside Azure authentication.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/recipes/cicd/examples/github-azd.yml:27:azure-credential-environment-variables","reason":"The workflow references configured Azure OIDC identifiers through pipeline secret syntax. It does not print or transmit them outside Azure authentication.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/recipes/cicd/examples/github-bicep.yml:17:azure-credential-environment-variables","reason":"The workflow references configured Azure OIDC identifiers through pipeline secret syntax. It does not print or transmit them outside Azure authentication.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/recipes/cicd/examples/github-bicep.yml:18:azure-credential-environment-variables","reason":"The workflow references configured Azure OIDC identifiers through pipeline secret syntax. It does not print or transmit them outside Azure authentication.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/recipes/cicd/README.md:30:azure-credential-environment-variables","reason":"The workflow references configured Azure OIDC identifiers through pipeline secret syntax. It does not print or transmit them outside Azure authentication.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:references/recipes/cicd/README.md:7:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"network:references/recipes/cicd/verify.md:16:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/cicd/verify.md:23:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/terraform/errors.md:9:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/recipes/terraform/errors.md:10:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/terraform/README.md:103:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/terraform/README.md:105:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/terraform/README.md:109:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/terraform/README.md:71:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/terraform/README.md:72:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/terraform/README.md:73:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/terraform/README.md:74:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/terraform/README.md:93:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/terraform/README.md:94:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/recipes/terraform/README.md:11:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/terraform/README.md:17:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recipes/terraform/README.md:114:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/recipes/terraform/README.md:8:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/recipes/terraform/verify.md:11:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/recipes/terraform/verify.md:17:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"network:references/recipes/terraform/verify.md:11:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/recipes/terraform/verify.md:30:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/sdk/azd-deployment.md:19:hidden-file-access","reason":"The path is the standard .NET global-tools directory added to PATH. The command does not inspect credentials or unrelated hidden files.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/sdk/azd-deployment.md:19:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:references/sdk/azd-deployment.md:19:environment-file-access","reason":"The text warns that AZD manages a project .env file. It neither opens nor discloses the file contents.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/sdk/azd-deployment.md:8:pipe-to-shell-pattern","reason":"The command downloads a remote script and pipes it directly to Bash without pinning or verification. A compromised response would execute arbitrary code.","verdict":"confirmed","severity":"critical","confidence":0.99},{"id":"filesystem:references/sdk/azure-identity-dotnet.md:12:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/sdk/azure-identity-dotnet.md:20:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/sdk/azure-identity-java.md:26:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/sdk/azure-identity-java.md:18:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/sdk/azure-identity-java.md:26:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/sdk/azure-identity-py.md:22:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/sdk/azure-identity-py.md:14:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/sdk/azure-identity-py.md:22:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/sdk/azure-identity-py.md:27:azure-credential-environment-variables","reason":"The text reads or names AZURE_CLIENT_ID for user-assigned managed identity selection. A client identifier is not a secret and is not exfiltrated.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/sdk/azure-identity-ts.md:20:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/sdk/azure-identity-ts.md:12:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/sdk/azure-identity-ts.md:20:path-traversal-sequence","reason":"The matched text is a Markdown relative link or deployment guidance. It does not construct a runtime filesystem path from untrusted input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/troubleshooting.md:156:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/troubleshooting.md:159:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/troubleshooting.md:162:shell-command-substitution","reason":"The substitution captures output from Azure, AZD, Terraform, or a local file for a documented deployment command. It does not re-evaluate that output as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/troubleshooting.md:165:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/troubleshooting.md:166:powershell-invocation","reason":"This line is a Markdown heading, code fence, comment, or credential-chain description. It does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"network:references/troubleshooting.md:115:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:references/troubleshooting.md:116:hardcoded-ip-address","reason":"The matched value 1.0.0.0 is an ARM template contentVersion string. It is not an IP address or network destination.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/troubleshooting.md:9:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/troubleshooting.md:23:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The backtick is Markdown inline-code punctuation or PowerShell line continuation. It is not Ruby or POSIX command execution.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:45:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:70:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:74:hardcoded-url","reason":"The URL is an Azure documentation or schema address, a placeholder, or a deployed endpoint used for expected health checks. No credential is sent.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:SKILL.md:3:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:19:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:50:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:61:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:63:azure-credentials-directory","reason":"The match is a project .azure path, not the Azure CLI credential directory ~/.azure. It does not read authentication tokens.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:74:system-reconnaissance","reason":"The matched text is deployment guidance, validation output, or a scoped Azure query. It does not perform host-system reconnaissance.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Registry Password Exposed in Command Arguments","severity":"high","locations":[{"file":"references/recipes/azd/errors.md","line_end":164,"line_start":152}],"confidence":0.98,"description":"The fallback retrieves an ACR administrator password and passes it with docker login -p. Other local processes and logs can expose the credential.","confidence_reasoning":"The commands directly retrieve a live password and place it in a process argument in both shell variants."},{"title":"Application Identity Receives Schema Administration","severity":"high","locations":[{"file":"references/recipes/azd/sql-managed-identity.md","line_end":29,"line_start":24},{"file":"references/recipes/azd/scripts/grant-and-migrate.sh","line_end":94,"line_start":67},{"file":"references/recipes/azd/scripts/grant-and-migrate.ps1","line_end":72,"line_start":45}],"confidence":0.97,"description":"Deployment guidance grants the runtime identity db_ddladmin with read and write roles. A compromised application could alter or drop database schema.","confidence_reasoning":"The SQL explicitly adds the application identity to db_ddladmin, db_datareader, and db_datawriter in every documented variant."},{"title":"Mutable Deployment Dependencies","severity":"high","locations":[{"file":"references/recipes/cicd/examples/github-azd.yml","line_end":24,"line_start":8},{"file":"references/recipes/azd/scripts/apply-migrations.sh","line_end":46,"line_start":43},{"file":"references/recipes/azd/scripts/grant-and-migrate.sh","line_end":56,"line_start":53}],"confidence":0.95,"description":"CI workflows use mutable action tags with OIDC permission, and migration scripts install unpinned global tools. Upstream changes could execute during deployment.","confidence_reasoning":"The workflow uses version tags instead of commit SHAs, while scripts install current package versions without integrity or version constraints."},{"title":"Project-Controlled Health Check Targets","severity":"high","locations":[{"file":"references/recipes/azd/post-deployment.md","line_end":82,"line_start":74},{"file":"references/recipes/azd/verify.md","line_end":36,"line_start":21}],"confidence":0.9,"description":"Health checks request endpoints loaded from project-controlled AZD values without validating the host. A crafted project can direct the agent toward internal services.","confidence_reasoning":"The endpoint comes from local AZD environment state and is passed directly to curl or Invoke-WebRequest without a scheme or hostname allowlist."}],"subject_marketplace_commit_sha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","subject_content_hash":"daa23eea47cd37110b5ceab709592d2cd8758520264dd03121896ebea2fdc80d","subject_tree_hash":"b70b80d44814300b9bf8f5ca762033ac622504e687ea32579e33cdcb7fe2f776","subject_plugin_path":"skills/microsoft/azure-deploy","audit_payload_hash":"0078625b838a723cc1731ebcba16800e","confirmed_risk_level":"critical","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","contentHash":"daa23eea47cd37110b5ceab709592d2cd8758520264dd03121896ebea2fdc80d","treeHash":"b70b80d44814300b9bf8f5ca762033ac622504e687ea32579e33cdcb7fe2f776","pluginPath":"skills/microsoft/azure-deploy","auditPayloadHash":"0078625b838a723cc1731ebcba16800e"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/microsoft-azure-deploy/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"critical","confirmedFindingCount":5,"capabilityReviewCount":6,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"blocked","manualInstallPolicy":"allowed_with_warning","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}