{"data":{"skill":{"slug":"microsoft-azure-upgrade","name":"azure-upgrade","icon":"📦","repo":"https://github.com/microsoft/azure-skills/tree/main/.github/plugins/azure-skills/skills/azure-upgrade/","status":"approved","author":"microsoft","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"dec77cc8-e54e-4778-8e79-3e8622487b01","skill_id":"13237b37-fe34-44f6-8dfc-3bad91660935","version":5,"content_hash":"v2:1200d2f84325e4a40a4c6cc230f3864179fd6940:56b6ce64bca0630e42a3691a08b624227fd5c45e082adc328bfd4ef356a00b20:a221f4331feb70c410eb738fba9a30b4e52047310b78f0b65a23047aa35853e5:790f4244bc3aa847518fbc0c6f5dee92","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static findings are documentation-only false positives, especially PowerShell mentions, Markdown links, and inline code formatting. Confirmed risks remain in executable migration helpers and Azure CLI guidance, including build-tool execution, project file mutation, network fetches, sensitive configuration exposure, and overbroad autonomous workflow language.","remediation":[{"issue":"Overbroad no-pause and no-stop workflow language","severity":"high","suggestion":"State that host rules, user instructions, safety limits, and explicit confirmations always take priority over migration completion goals."},{"issue":"Fixed rewrite.yml path can overwrite or delete user configuration","severity":"high","suggestion":"Use a unique temporary file, detect existing rewrite.yml, and restore or preserve any user-owned file during cleanup."},{"issue":"Function App settings and storage connection strings are printed or handled in shell variables","severity":"high","suggestion":"Redact app setting values, avoid echoing secrets, prefer managed identity, and document secure handling for temporary credentials."},{"issue":"Unquoted shell variables in deployment package handling","severity":"medium","suggestion":"Quote variables, validate package names, reject path separators, and write downloads to a controlled temporary directory."},{"issue":"Maven, Gradle, OpenRewrite, and Azure CLI commands can execute code or change resources","severity":"high","suggestion":"Require explicit user confirmation, show dry-run plans when possible, and warn that project build scripts may execute code."},{"issue":"Remote BOM metadata controls dependency rewrite decisions","severity":"low","suggestion":"Document the trusted source, support offline review, and consider checksum or signed-source verification where available."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/languages/java/bom-migration/bom-gradle.md","line_end":12,"line_start":12},{"file":"references/languages/java/bom-migration/bom-gradle.md","line_end":121,"line_start":121},{"file":"references/languages/java/bom-migration/bom-gradle.md","line_end":122,"line_start":122},{"file":"references/languages/java/bom-migration/bom-maven.md","line_end":12,"line_start":12},{"file":"references/languages/java/bom-migration/bom-maven.md","line_end":111,"line_start":111},{"file":"references/languages/java/bom-migration/bom-migration.md","line_end":9,"line_start":9},{"file":"references/languages/java/bom-migration/bom-migration.md","line_end":15,"line_start":15},{"file":"references/languages/java/bom-migration/bom-migration.md","line_end":17,"line_start":17},{"file":"references/languages/java/bom-migration/bom-migration.md","line_end":31,"line_start":31},{"file":"references/languages/java/INSTRUCTION.md","line_end":17,"line_start":17},{"file":"references/languages/java/INSTRUCTION.md","line_end":19,"line_start":19},{"file":"references/languages/java/INSTRUCTION.md","line_end":25,"line_start":25},{"file":"references/languages/java/INSTRUCTION.md","line_end":82,"line_start":82},{"file":"references/languages/java/INSTRUCTION.md","line_end":84,"line_start":84},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":195,"line_start":195},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":433,"line_start":433},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":371,"line_start":371},{"file":"references/services/functions/automation.md","line_end":143,"line_start":139},{"file":"references/services/functions/automation.md","line_end":110,"line_start":110},{"file":"references/services/functions/automation.md","line_end":153,"line_start":152},{"file":"references/services/functions/automation.md","line_end":165,"line_start":164},{"file":"references/services/functions/automation.md","line_end":169,"line_start":169},{"file":"references/services/functions/automation.md","line_end":171,"line_start":171},{"file":"references/services/functions/automation.md","line_end":214,"line_start":213},{"file":"references/services/functions/automation.md","line_end":218,"line_start":217},{"file":"references/services/functions/automation.md","line_end":355,"line_start":354},{"file":"references/services/functions/automation.md","line_end":357,"line_start":357},{"file":"references/services/functions/automation.md","line_end":4,"line_start":4},{"file":"references/services/functions/automation.md","line_end":57,"line_start":57},{"file":"references/services/functions/automation.md","line_end":68,"line_start":68},{"file":"references/services/functions/consumption-to-flex.md","line_end":47,"line_start":47},{"file":"references/services/redis/redis-to-amr.md","line_end":10,"line_start":10},{"file":"references/services/redis/redis-to-amr.md","line_end":25,"line_start":25},{"file":"references/services/redis/redis-to-amr.md","line_end":33,"line_start":33},{"file":"references/services/redis/redis-to-amr.md","line_end":44,"line_start":44},{"file":"references/services/redis/redis-to-amr.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":91,"line_start":91}]},{"factor":"env_access","evidence":[{"file":"references/languages/java/package-specific/com.microsoft.azure.management.md","line_end":21,"line_start":21},{"file":"references/languages/java/package-specific/com.microsoft.azure.management.md","line_end":25,"line_start":25},{"file":"references/languages/java/package-specific/com.microsoft.azure.management.md","line_end":21,"line_start":21},{"file":"references/languages/java/package-specific/com.microsoft.azure.management.md","line_end":61,"line_start":61}]},{"factor":"filesystem","evidence":[{"file":"references/languages/java/rules/upgrade-strategy.md","line_end":7,"line_start":7},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":331,"line_start":331},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":394,"line_start":394},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":425,"line_start":425},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":150,"line_start":150},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":257,"line_start":257},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":460,"line_start":460},{"file":"references/languages/java/workflow/phase-1-precheck.md","line_end":3,"line_start":3},{"file":"references/languages/java/workflow/phase-2-plan.md","line_end":3,"line_start":3},{"file":"references/languages/java/workflow/phase-3-execute.md","line_end":3,"line_start":3},{"file":"references/languages/java/workflow/phase-3-execute.md","line_end":24,"line_start":24},{"file":"references/languages/java/workflow/phase-4-summarize.md","line_end":3,"line_start":3},{"file":"references/services/functions/automation.md","line_end":357,"line_start":357},{"file":"references/services/functions/automation.md","line_end":375,"line_start":375}]},{"factor":"network","evidence":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":40,"line_start":40},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":82,"line_start":82},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":45,"line_start":45},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":46,"line_start":46},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":169,"line_start":169},{"file":"references/services/functions/automation.md","line_end":357,"line_start":357},{"file":"references/services/functions/automation.md","line_end":375,"line_start":375},{"file":"SKILL.md","line_end":81,"line_start":81}]}],"critical_findings":[],"high_findings":[{"title":"Python subprocess.run","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":195,"line_start":195}],"confidence":0.84,"description":"return subprocess.run(cmd, cwd=project_dir).returncode","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"The script runs Maven and OpenRewrite in the target project. Even without shell=True, project build tools can execute project-controlled plugins and scripts."},{"title":"Python subprocess.run","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":433,"line_start":433}],"confidence":0.84,"description":"return subprocess.run(cmd, cwd=project_dir).returncode","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"The script runs Gradle rewriteRun in the target project. Gradle builds can execute project-controlled code and alter files during migration."},{"title":"Python file write/append","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":331,"line_start":331}],"confidence":0.93,"description":"with open(yml_path, \"w\", encoding=\"utf-8\") as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The script writes rewrite.yml in the target project without preserving a preexisting file. Cleanup later can remove the same generic project file."},{"title":"Python os file operations","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":460,"line_start":460}],"confidence":0.92,"description":"os.remove(yml_path)","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The script deletes rewrite.yml during cleanup. Because the name is generic, an existing user OpenRewrite configuration could be removed."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":110,"line_start":110}],"confidence":0.91,"description":"app_settings=$(az functionapp config appsettings list --name $appName --resource-group $rgName)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script reads all Function App settings and then prints them. App settings often contain secrets, connection strings, or tokens."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":214,"line_start":213}],"confidence":0.92,"description":"storageConnection=$(az functionapp config appsettings list --name $appName --resource-group $rgName ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script reads AzureWebJobsStorage into a shell variable. This value is a credential-bearing connection string and may be exposed through logs or shell state."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":218,"line_start":217}],"confidence":0.88,"description":"packageName=$(az storage blob list --connection-string $storageConnection --container-name scm-relea","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script uses the storage connection string to list deployment packages. It combines credential use with unquoted shell variables in runnable guidance."},{"title":"Overbroad Agent Autonomy Instructions","locations":[{"file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","line_end":27,"line_start":15},{"file":"references/languages/java/rules/troubleshooting.md","line_end":20,"line_start":7},{"file":"references/languages/java/workflow/phase-2-plan.md","line_end":44,"line_start":40}],"confidence":0.88,"description":"The Java workflow tells the agent to avoid pausing, treats token and time limits as invalid, and proceeds directly to execution. These instructions can conflict with host limits, user confirmation, and safe scope control.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The cited text directly imposes no-pause and no-stop behavior. It does not claim system authority, but it can override user or host boundaries."},{"title":"Project Configuration Overwrite and Deletion Risk","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":333,"line_start":300},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":463,"line_start":459}],"confidence":0.93,"description":"The BOM helper writes rewrite.yml in the project root and later removes that path. A preexisting OpenRewrite configuration can be overwritten or deleted.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The code constructs a fixed rewrite.yml path, writes it, and removes it during cleanup. There is no check, backup, or restore for an existing user file."},{"title":"Sensitive Azure Configuration Disclosure","locations":[{"file":"references/services/functions/automation.md","line_end":111,"line_start":109},{"file":"references/services/functions/automation.md","line_end":218,"line_start":212}],"confidence":0.91,"description":"The automation guidance collects and prints app settings, then reads the AzureWebJobsStorage connection string for storage access. These values commonly contain secrets.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The cited commands explicitly collect app settings and a storage connection string. Azure app settings commonly include credentials and tokens."}],"medium_findings":[{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":7,"line_start":7}],"confidence":0.76,"description":"- **NO premature termination**: Token limits, time constraints, or complexity are NEVER valid reason","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The mandatory rule says token limits, time constraints, and complexity are never valid reasons to stop. This is not reconnaissance, but it is a real prompt-control risk."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":10,"line_start":10}],"confidence":0.66,"description":"- **NO categorical dismissals**: \"Test-specific issues\", \"doesn't affect production\", \"sample/demo c","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The rule forbids categorical dismissals of failures. It can override normal risk triage in edge cases, so it is kept as a low-confidence control risk."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":12,"line_start":12}],"confidence":0.64,"description":"- **Genuine limitations ONLY**: A limitation is valid ONLY if: (1) multiple distinct fix approaches ","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The rule allows limitations only after exhaustive attempts. That can conflict with practical stopping criteria and user-directed scope limits."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":19,"line_start":19}],"confidence":0.69,"description":"- **Do NOT treat partial migration as acceptable.** Migrating some files but not others is not a val","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The rule forbids partial migration as a stopping point. In a marketplace skill, this can push broad code modification beyond the user-approved scope."},{"title":"Python file write/append","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":394,"line_start":394}],"confidence":0.87,"description":"with open(build_file, \"w\", encoding=\"utf-8\") as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The script rewrites the Gradle build file to inject OpenRewrite configuration. This directly modifies project build configuration and can corrupt it if assumptions fail."},{"title":"Python file write/append","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":425,"line_start":425}],"confidence":0.86,"description":"with open(build_file, \"w\", encoding=\"utf-8\") as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The script rewrites the Gradle build file again during cleanup. Marker-based cleanup can remove or alter build configuration if the file differs from expectations."},{"title":"Python os file operations","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":150,"line_start":150}],"confidence":0.77,"description":"os.chmod(wrapper, mode | stat.S_IXUSR | stat.S_IXGRP | stat.S_IXOTH)","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The script changes executable bits on mvnw in the target project. This is intended wrapper handling but still mutates project file permissions."},{"title":"Python os file operations","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":257,"line_start":257}],"confidence":0.77,"description":"os.chmod(wrapper, mode | stat.S_IXUSR | stat.S_IXGRP | stat.S_IXOTH)","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The script changes executable bits on gradlew in the target project. This is intended wrapper handling but still mutates project file permissions."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","line_end":16,"line_start":16}],"confidence":0.78,"description":"- **NO premature termination**: Token limits, time constraints, or complexity are NEVER valid reason","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The template says token limits, time constraints, and complexity are never valid reasons to skip fixing. This can pressure an agent to ignore operational limits."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","line_end":27,"line_start":27}],"confidence":0.66,"description":"- **NO categorical dismissals**: \"Test-specific issues\", \"doesn't affect production\", \"sample/demo c","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The template forbids dismissing failing tests as non-production or sample issues. This can be useful quality guidance, but it also reduces safe stopping discretion."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":153,"line_start":152}],"confidence":0.74,"description":"systemUserId=$(az functionapp identity show --name $appName --resource-group $rgName \\","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script enumerates system-assigned managed identity principal IDs. This is read-only but exposes cloud identity metadata."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":165,"line_start":164}],"confidence":0.74,"description":"userIdentities=$(az functionapp identity show --name $appName --resource-group $rgName \\","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script enumerates user-assigned managed identities. This is legitimate assessment work but reveals cloud identity metadata."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":169,"line_start":169}],"confidence":0.73,"description":"echo \"User-assigned identity: $(echo \"$identity\" | jq -r '.key' | sed 's|.*/userAssignedIdentities/|","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The loop prints user-assigned identity names derived from resource IDs. This can disclose identity inventory during migration."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":171,"line_start":171}],"confidence":0.82,"description":"az role assignment list --assignee $(echo \"$identity\" | jq -r '.value.principalId') --all --output j","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script lists all role assignments for each identity principal. RBAC enumeration can reveal privilege paths and should be handled carefully."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":355,"line_start":354}],"confidence":0.67,"description":"DEFAULT_HOST=$(az functionapp show --name <NEW_APP_NAME> --resource-group <RESOURCE_GROUP> \\","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script discovers the migrated app default hostname for validation. This is low-impact cloud resource discovery but still executes Azure CLI."},{"title":"Shell command substitution","locations":[{"file":"references/services/functions/automation.md","line_end":357,"line_start":357}],"confidence":0.71,"description":"HTTP_STATUS=$(curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST\")","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The script performs an HTTP smoke test against the migrated app. This is legitimate validation but calls a live endpoint."},{"title":"Hardcoded URL","locations":[{"file":"references/services/functions/automation.md","line_end":375,"line_start":375}],"confidence":0.74,"description":"curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST/api/<FUNCTION_NAME>\"","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The curl command can invoke a live HTTP trigger endpoint. If the function is not idempotent, validation may have side effects."},{"title":"Unquoted Deployment Package Filename","locations":[{"file":"references/services/functions/automation.md","line_end":222,"line_start":217}],"confidence":0.78,"description":"The package name returned from blob storage is used unquoted as the local output file path. Blob names with spaces, option-like prefixes, or path separators can cause unintended behavior.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The package name comes from remote blob metadata and is expanded unquoted in a shell command. This creates plausible parsing and file path risks."}],"low_findings":[{"title":"Python HTTP libraries","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":40,"line_start":40}],"confidence":0.72,"description":"import urllib.request","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The imported urllib module is used by the same script to fetch BOM metadata from GitHub. This is an external network dependency that influences migration output."},{"title":"Python HTTP libraries","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":82,"line_start":82}],"confidence":0.86,"description":"with urllib.request.urlopen(BOM_POM_URL, timeout=HTTP_TIMEOUT_SECONDS) as response:","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The script downloads the Azure SDK BOM POM from GitHub to select a version. The fetch is legitimate but remote content affects dependency rewrites."},{"title":"Hardcoded URL","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":45,"line_start":45}],"confidence":0.84,"description":"BOM_POM_URL = \"https://raw.githubusercontent.com/Azure/azure-sdk-for-java/main/sdk/boms/azure-sdk-bo","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The hardcoded raw.githubusercontent.com URL is fetched for BOM data. A remote source controls version selection, so integrity and availability matter."},{"title":"Hardcoded URL","locations":[{"file":"references/services/functions/automation.md","line_end":357,"line_start":357}],"confidence":0.7,"description":"HTTP_STATUS=$(curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST\")","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The curl command sends a request to the app hostname. The URL is dynamic, but the line still performs a network call to a live Azure endpoint."}],"dangerous_patterns":[{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":7,"line_start":7}],"confidence":0.76,"description":"- **NO premature termination**: Token limits, time constraints, or complexity are NEVER valid reason","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The mandatory rule says token limits, time constraints, and complexity are never valid reasons to stop. This is not reconnaissance, but it is a real prompt-control risk."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":10,"line_start":10}],"confidence":0.66,"description":"- **NO categorical dismissals**: \"Test-specific issues\", \"doesn't affect production\", \"sample/demo c","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The rule forbids categorical dismissals of failures. It can override normal risk triage in edge cases, so it is kept as a low-confidence control risk."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":12,"line_start":12}],"confidence":0.64,"description":"- **Genuine limitations ONLY**: A limitation is valid ONLY if: (1) multiple distinct fix approaches ","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The rule allows limitations only after exhaustive attempts. That can conflict with practical stopping criteria and user-directed scope limits."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/rules/troubleshooting.md","line_end":19,"line_start":19}],"confidence":0.69,"description":"- **Do NOT treat partial migration as acceptable.** Migrating some files but not others is not a val","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The rule forbids partial migration as a stopping point. In a marketplace skill, this can push broad code modification beyond the user-approved scope."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","line_end":16,"line_start":16}],"confidence":0.78,"description":"- **NO premature termination**: Token limits, time constraints, or complexity are NEVER valid reason","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The template says token limits, time constraints, and complexity are never valid reasons to skip fixing. This can pressure an agent to ignore operational limits."},{"title":"System reconnaissance","locations":[{"file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","line_end":27,"line_start":27}],"confidence":0.66,"description":"- **NO categorical dismissals**: \"Test-specific issues\", \"doesn't affect production\", \"sample/demo c","review_kind":"security","source_category":"blocker","source_severity":"low","confidence_reasoning":"The template forbids dismissing failing tests as non-production or sample issues. This can be useful quality guidance, but it also reduces safe stopping discretion."}],"files_scanned":31,"total_lines":3461,"audit_model":"codex","audited_at":"2026-07-08T05:05:16.233+00:00","created_at":"2026-07-08T06:37:52.043867+00:00","static_findings":[{"id":"external_commands:references/languages/java/bom-migration/bom-gradle.md:12:powershell-invocation","file":"references/languages/java/bom-migration/bom-gradle.md","pattern":"PowerShell invocation","snippet":"The following invocation works identically in **bash** and **PowerShell**:","category":"external_commands","line_end":12,"severity":"high","line_start":12},{"id":"external_commands:references/languages/java/bom-migration/bom-gradle.md:121:powershell-invocation","file":"references/languages/java/bom-migration/bom-gradle.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":121,"severity":"high","line_start":121},{"id":"external_commands:references/languages/java/bom-migration/bom-gradle.md:122:powershell-invocation","file":"references/languages/java/bom-migration/bom-gradle.md","pattern":"PowerShell invocation","snippet":"# PowerShell on Windows","category":"external_commands","line_end":122,"severity":"high","line_start":122},{"id":"external_commands:references/languages/java/bom-migration/bom-maven.md:12:powershell-invocation","file":"references/languages/java/bom-migration/bom-maven.md","pattern":"PowerShell invocation","snippet":"The following invocation works identically in **bash** and **PowerShell**:","category":"external_commands","line_end":12,"severity":"high","line_start":12},{"id":"external_commands:references/languages/java/bom-migration/bom-maven.md:111:powershell-invocation","file":"references/languages/java/bom-migration/bom-maven.md","pattern":"PowerShell invocation","snippet":"Run `mvn -q -DskipTests dependency:tree` (the same command works in both **bash** and **PowerShell**","category":"external_commands","line_end":111,"severity":"high","line_start":111},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:9:powershell-invocation","file":"references/languages/java/bom-migration/bom-migration.md","pattern":"PowerShell invocation","snippet":"The following check works in both **bash** and **PowerShell 7+** (the `||` operator is supported in ","category":"external_commands","line_end":9,"severity":"high","line_start":9},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:15:powershell-invocation","file":"references/languages/java/bom-migration/bom-migration.md","pattern":"PowerShell invocation","snippet":"For Windows PowerShell 5.1, use:","category":"external_commands","line_end":15,"severity":"high","line_start":15},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:17:powershell-invocation","file":"references/languages/java/bom-migration/bom-migration.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":17,"severity":"high","line_start":17},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:31:powershell-invocation","file":"references/languages/java/bom-migration/bom-migration.md","pattern":"PowerShell invocation","snippet":"The following invocation works identically in **bash** and **PowerShell** (no shell-specific syntax)","category":"external_commands","line_end":31,"severity":"high","line_start":31},{"id":"external_commands:references/languages/java/INSTRUCTION.md:17:powershell-invocation","file":"references/languages/java/INSTRUCTION.md","pattern":"PowerShell invocation","snippet":"PowerShell equivalent (run from repo root):","category":"external_commands","line_end":17,"severity":"high","line_start":17},{"id":"external_commands:references/languages/java/INSTRUCTION.md:19:powershell-invocation","file":"references/languages/java/INSTRUCTION.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":19,"severity":"high","line_start":19},{"id":"external_commands:references/languages/java/INSTRUCTION.md:25:powershell-invocation","file":"references/languages/java/INSTRUCTION.md","pattern":"PowerShell invocation","snippet":"Commonly overlooked locations:`.ci/**/pom.xml`, `ci/**`, parent/BOM poms, `buildSrc/`, `gradle/libs.","category":"external_commands","line_end":25,"severity":"high","line_start":25},{"id":"external_commands:references/languages/java/INSTRUCTION.md:82:powershell-invocation","file":"references/languages/java/INSTRUCTION.md","pattern":"PowerShell invocation","snippet":"PowerShell equivalent (run from repo root):","category":"external_commands","line_end":82,"severity":"high","line_start":82},{"id":"external_commands:references/languages/java/INSTRUCTION.md:84:powershell-invocation","file":"references/languages/java/INSTRUCTION.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":84,"severity":"high","line_start":84},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:21:getenv-function-call","file":"references/languages/java/package-specific/com.microsoft.azure.management.md","pattern":"getenv function call","snippet":"> **Important:** Reading `clientId`, `clientSecret`, or `tenantId` from **environment variables** (e","category":"env_access","line_end":21,"severity":"low","line_start":21},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:25:getenv-function-call","file":"references/languages/java/package-specific/com.microsoft.azure.management.md","pattern":"getenv function call","snippet":"Azure azure = Azure.authenticate(new File(System.getenv(\"AZURE_AUTH_LOCATION\")))","category":"env_access","line_end":25,"severity":"low","line_start":25},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:21:azure-credential-environment-variables","file":"references/languages/java/package-specific/com.microsoft.azure.management.md","pattern":"Azure credential environment variables","snippet":"> **Important:** Reading `clientId`, `clientSecret`, or `tenantId` from **environment variables** (e","category":"env_access","line_end":21,"severity":"high","line_start":21},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:61:azure-credential-environment-variables","file":"references/languages/java/package-specific/com.microsoft.azure.management.md","pattern":"Azure credential environment variables","snippet":"If legacy code mentions `AZURE_AUTH_LOCATION` only in a validation guard or exception message, do no","category":"env_access","line_end":61,"severity":"high","line_start":61},{"id":"blocker:references/languages/java/package-specific/com.microsoft.azure.management.md:8:system-reconnaissance","file":"references/languages/java/package-specific/com.microsoft.azure.management.md","pattern":"System reconnaissance","snippet":"- Keep the text emitted by logging and stdout/stderr unchanged to avoid breaking downstream consumer","category":"blocker","line_end":8,"severity":"low","line_start":8},{"id":"blocker:references/languages/java/rules/troubleshooting.md:7:system-reconnaissance","file":"references/languages/java/rules/troubleshooting.md","pattern":"System reconnaissance","snippet":"- **NO premature termination**: Token limits, time constraints, or complexity are NEVER valid reason","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"blocker:references/languages/java/rules/troubleshooting.md:10:system-reconnaissance","file":"references/languages/java/rules/troubleshooting.md","pattern":"System reconnaissance","snippet":"- **NO categorical dismissals**: \"Test-specific issues\", \"doesn't affect production\", \"sample/demo c","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:references/languages/java/rules/troubleshooting.md:12:system-reconnaissance","file":"references/languages/java/rules/troubleshooting.md","pattern":"System reconnaissance","snippet":"- **Genuine limitations ONLY**: A limitation is valid ONLY if: (1) multiple distinct fix approaches ","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"blocker:references/languages/java/rules/troubleshooting.md:19:system-reconnaissance","file":"references/languages/java/rules/troubleshooting.md","pattern":"System reconnaissance","snippet":"- **Do NOT treat partial migration as acceptable.** Migrating some files but not others is not a val","category":"blocker","line_end":19,"severity":"low","line_start":19},{"id":"filesystem:references/languages/java/rules/upgrade-strategy.md:7:path-traversal-sequence","file":"references/languages/java/rules/upgrade-strategy.md","pattern":"Path traversal sequence","snippet":"- **Automation tools**: Use automation tools like OpenRewrite for efficiency; always verify output. ","category":"filesystem","line_end":7,"severity":"high","line_start":7},{"id":"blocker:references/languages/java/rules/upgrade-strategy.md:3:system-reconnaissance","file":"references/languages/java/rules/upgrade-strategy.md","pattern":"System reconnaissance","snippet":"- **Incremental upgrades**: Stepwise dependency upgrades to avoid large jumps breaking builds.","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"external_commands:references/languages/java/scripts/upgrade_bom.py:195:python-subprocess-run","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python subprocess.run","snippet":"return subprocess.run(cmd, cwd=project_dir).returncode","category":"external_commands","line_end":195,"severity":"high","line_start":195},{"id":"external_commands:references/languages/java/scripts/upgrade_bom.py:433:python-subprocess-run","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python subprocess.run","snippet":"return subprocess.run(cmd, cwd=project_dir).returncode","category":"external_commands","line_end":433,"severity":"high","line_start":433},{"id":"external_commands:references/languages/java/scripts/upgrade_bom.py:371:ruby-shell-backtick-execution","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Ruby/shell backtick execution","snippet":"# `plugins {`, so don't add another one before the marker.","category":"external_commands","line_end":371,"severity":"medium","line_start":371},{"id":"network:references/languages/java/scripts/upgrade_bom.py:40:python-http-libraries","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python HTTP libraries","snippet":"import urllib.request","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"network:references/languages/java/scripts/upgrade_bom.py:82:python-http-libraries","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python HTTP libraries","snippet":"with urllib.request.urlopen(BOM_POM_URL, timeout=HTTP_TIMEOUT_SECONDS) as response:","category":"network","line_end":82,"severity":"low","line_start":82},{"id":"network:references/languages/java/scripts/upgrade_bom.py:45:hardcoded-url","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Hardcoded URL","snippet":"BOM_POM_URL = \"https://raw.githubusercontent.com/Azure/azure-sdk-for-java/main/sdk/boms/azure-sdk-bo","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:references/languages/java/scripts/upgrade_bom.py:46:hardcoded-url","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Hardcoded URL","snippet":"POM_NAMESPACE = {\"m\": \"http://maven.apache.org/POM/4.0.0\"}","category":"network","line_end":46,"severity":"low","line_start":46},{"id":"network:references/languages/java/scripts/upgrade_bom.py:169:hardcoded-url","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Hardcoded URL","snippet":"ns = {\"m\": \"http://maven.apache.org/POM/4.0.0\"}","category":"network","line_end":169,"severity":"low","line_start":169},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:331:python-file-write-append","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python file write/append","snippet":"with open(yml_path, \"w\", encoding=\"utf-8\") as f:","category":"filesystem","line_end":331,"severity":"medium","line_start":331},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:394:python-file-write-append","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python file write/append","snippet":"with open(build_file, \"w\", encoding=\"utf-8\") as f:","category":"filesystem","line_end":394,"severity":"medium","line_start":394},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:425:python-file-write-append","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python file write/append","snippet":"with open(build_file, \"w\", encoding=\"utf-8\") as f:","category":"filesystem","line_end":425,"severity":"medium","line_start":425},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:150:python-os-file-operations","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python os file operations","snippet":"os.chmod(wrapper, mode | stat.S_IXUSR | stat.S_IXGRP | stat.S_IXOTH)","category":"filesystem","line_end":150,"severity":"medium","line_start":150},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:257:python-os-file-operations","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python os file operations","snippet":"os.chmod(wrapper, mode | stat.S_IXUSR | stat.S_IXGRP | stat.S_IXOTH)","category":"filesystem","line_end":257,"severity":"medium","line_start":257},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:460:python-os-file-operations","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Python os file operations","snippet":"os.remove(yml_path)","category":"filesystem","line_end":460,"severity":"medium","line_start":460},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:103:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"f\"Invalid azure-sdk-bom version '{version}'. Expected stable MAJOR.MINOR.PATCH.\"","category":"blocker","line_end":103,"severity":"low","line_start":103},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:171:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"gid = dep.find(\"m:groupId\", ns)","category":"blocker","line_end":171,"severity":"low","line_start":171},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:172:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"aid = dep.find(\"m:artifactId\", ns)","category":"blocker","line_end":172,"severity":"low","line_start":172},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:173:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"if gid is not None and aid is not None:","category":"blocker","line_end":173,"severity":"low","line_start":173},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:177:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"gid = dep.find(\"groupId\")","category":"blocker","line_end":177,"severity":"low","line_start":177},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:178:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"aid = dep.find(\"artifactId\")","category":"blocker","line_end":178,"severity":"low","line_start":178},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:179:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"if gid is not None and aid is not None:","category":"blocker","line_end":179,"severity":"low","line_start":179},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:352:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"plugin_line = '    id \"org.openrewrite.rewrite\" version \"latest.release\"'","category":"blocker","line_end":352,"severity":"low","line_start":352},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:414:system-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"System reconnaissance","snippet":"# the following injected plugin id line.","category":"blocker","line_end":414,"severity":"low","line_start":414},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:502:network-reconnaissance","file":"references/languages/java/scripts/upgrade_bom.py","pattern":"Network reconnaissance","snippet":"parser.error(\"project_dir is required unless --get-latest-version is used.\")","category":"blocker","line_end":502,"severity":"low","line_start":502},{"id":"blocker:references/languages/java/templates/PLAN_TEMPLATE.md:10:system-reconnaissance","file":"references/languages/java/templates/PLAN_TEMPLATE.md","pattern":"System reconnaissance","snippet":"- **Incremental upgrades**: Stepwise dependency upgrades to avoid large jumps breaking builds","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:references/languages/java/templates/PLAN_TEMPLATE.md:34:system-reconnaissance","file":"references/languages/java/templates/PLAN_TEMPLATE.md","pattern":"System reconnaissance","snippet":"- **HEAD Commit ID**: <current_commit_id> <!-- replace with actual head commit id when generating --","category":"blocker","line_end":34,"severity":"low","line_start":34},{"id":"blocker:references/languages/java/templates/PLAN_TEMPLATE.md:180:network-reconnaissance","file":"references/languages/java/templates/PLAN_TEMPLATE.md","pattern":"Network reconnaissance","snippet":"- Expected: Compilation SUCCESS + 100% tests pass","category":"blocker","line_end":181,"severity":"low","line_start":180},{"id":"blocker:references/languages/java/templates/PROGRESS_TEMPLATE.md:16:system-reconnaissance","file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","pattern":"System reconnaissance","snippet":"- **NO premature termination**: Token limits, time constraints, or complexity are NEVER valid reason","category":"blocker","line_end":16,"severity":"low","line_start":16},{"id":"blocker:references/languages/java/templates/PROGRESS_TEMPLATE.md:27:system-reconnaissance","file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","pattern":"System reconnaissance","snippet":"- **NO categorical dismissals**: \"Test-specific issues\", \"doesn't affect production\", \"sample/demo c","category":"blocker","line_end":27,"severity":"low","line_start":27},{"id":"blocker:references/languages/java/templates/PROGRESS_TEMPLATE.md:82:network-reconnaissance","file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","pattern":"Network reconnaissance","snippet":"- ⏳ In Progress - Currently working on this step","category":"blocker","line_end":82,"severity":"low","line_start":82},{"id":"filesystem:references/languages/java/workflow/phase-1-precheck.md:3:path-traversal-sequence","file":"references/languages/java/workflow/phase-1-precheck.md","pattern":"Path traversal sequence","snippet":"Load this file when executing Phase 1. Refer back to [`upgrade-success-criteria`](../rules/upgrade-s","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"blocker:references/languages/java/workflow/phase-1-precheck.md:9:system-reconnaissance","file":"references/languages/java/workflow/phase-1-precheck.md","pattern":"System reconnaissance","snippet":"| Invalid Goal        | No legacy Azure SDK deps found   | STOP — nothing to migrate                ","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"filesystem:references/languages/java/workflow/phase-2-plan.md:3:path-traversal-sequence","file":"references/languages/java/workflow/phase-2-plan.md","pattern":"Path traversal sequence","snippet":"Load this file when executing Phase 2. Refer back to [`upgrade-success-criteria`](../rules/upgrade-s","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/languages/java/workflow/phase-3-execute.md:3:path-traversal-sequence","file":"references/languages/java/workflow/phase-3-execute.md","pattern":"Path traversal sequence","snippet":"Load this file when executing Phase 3. Refer back to [`upgrade-success-criteria`](../rules/upgrade-s","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/languages/java/workflow/phase-3-execute.md:24:path-traversal-sequence","file":"references/languages/java/workflow/phase-3-execute.md","pattern":"Path traversal sequence","snippet":"- **Final Validation Step**: Achieve **Upgrade Success Criteria** — iterative test & fix loop until ","category":"filesystem","line_end":24,"severity":"high","line_start":24},{"id":"filesystem:references/languages/java/workflow/phase-4-summarize.md:3:path-traversal-sequence","file":"references/languages/java/workflow/phase-4-summarize.md","pattern":"Path traversal sequence","snippet":"Load this file when executing Phase 4. Refer back to [`upgrade-success-criteria`](../rules/upgrade-s","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"blocker:references/services/functions/assessment.md:20:system-reconnaissance","file":"references/services/functions/assessment.md","pattern":"System reconnaissance","snippet":"7. **Check Blob Triggers** — Verify blob triggers use EventGrid source (container polling not suppor","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:references/services/functions/assessment.md:56:system-reconnaissance","file":"references/services/functions/assessment.md","pattern":"System reconnaissance","snippet":"| Blob triggers use EventGrid | ✅ / ⚠️ / N/A | |","category":"blocker","line_end":56,"severity":"low","line_start":56},{"id":"external_commands:references/services/functions/automation.md:139:ruby-shell-backtick-execution","file":"references/services/functions/automation.md","pattern":"Ruby/shell backtick execution","snippet":"--query \"[?contains(name, 'azurewebsites.net')==\\`false\\`]\" --output table","category":"external_commands","line_end":143,"severity":"medium","line_start":139},{"id":"external_commands:references/services/functions/automation.md:110:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"app_settings=$(az functionapp config appsettings list --name $appName --resource-group $rgName)","category":"external_commands","line_end":110,"severity":"medium","line_start":110},{"id":"external_commands:references/services/functions/automation.md:152:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"systemUserId=$(az functionapp identity show --name $appName --resource-group $rgName \\","category":"external_commands","line_end":153,"severity":"medium","line_start":152},{"id":"external_commands:references/services/functions/automation.md:164:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"userIdentities=$(az functionapp identity show --name $appName --resource-group $rgName \\","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:references/services/functions/automation.md:169:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"echo \"User-assigned identity: $(echo \"$identity\" | jq -r '.key' | sed 's|.*/userAssignedIdentities/|","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:references/services/functions/automation.md:171:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"az role assignment list --assignee $(echo \"$identity\" | jq -r '.value.principalId') --all --output j","category":"external_commands","line_end":171,"severity":"medium","line_start":171},{"id":"external_commands:references/services/functions/automation.md:213:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"storageConnection=$(az functionapp config appsettings list --name $appName --resource-group $rgName ","category":"external_commands","line_end":214,"severity":"medium","line_start":213},{"id":"external_commands:references/services/functions/automation.md:217:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"packageName=$(az storage blob list --connection-string $storageConnection --container-name scm-relea","category":"external_commands","line_end":218,"severity":"medium","line_start":217},{"id":"external_commands:references/services/functions/automation.md:354:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"DEFAULT_HOST=$(az functionapp show --name <NEW_APP_NAME> --resource-group <RESOURCE_GROUP> \\","category":"external_commands","line_end":355,"severity":"medium","line_start":354},{"id":"external_commands:references/services/functions/automation.md:357:shell-command-substitution","file":"references/services/functions/automation.md","pattern":"Shell command substitution","snippet":"HTTP_STATUS=$(curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST\")","category":"external_commands","line_end":357,"severity":"medium","line_start":357},{"id":"external_commands:references/services/functions/automation.md:4:powershell-invocation","file":"references/services/functions/automation.md","pattern":"PowerShell invocation","snippet":"> All scripts use `bash` syntax compatible with Azure Cloud Shell. For PowerShell, adapt accordingly","category":"external_commands","line_end":4,"severity":"high","line_start":4},{"id":"external_commands:references/services/functions/automation.md:57:powershell-invocation","file":"references/services/functions/automation.md","pattern":"PowerShell invocation","snippet":"Supported stacks: `dotnet-isolated`, `node`, `java`, `python`, `powershell`, `custom`.","category":"external_commands","line_end":57,"severity":"high","line_start":57},{"id":"external_commands:references/services/functions/automation.md:68:powershell-invocation","file":"references/services/functions/automation.md","pattern":"PowerShell invocation","snippet":"Replace `<REGION>` with the app's region and `<LANGUAGE_STACK>` with one of: `dotnet-isolated`, `jav","category":"external_commands","line_end":68,"severity":"high","line_start":68},{"id":"network:references/services/functions/automation.md:357:hardcoded-url","file":"references/services/functions/automation.md","pattern":"Hardcoded URL","snippet":"HTTP_STATUS=$(curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST\")","category":"network","line_end":357,"severity":"low","line_start":357},{"id":"network:references/services/functions/automation.md:375:hardcoded-url","file":"references/services/functions/automation.md","pattern":"Hardcoded URL","snippet":"curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST/api/<FUNCTION_NAME>\"","category":"network","line_end":375,"severity":"low","line_start":375},{"id":"filesystem:references/services/functions/automation.md:357:standard-device-file-access","file":"references/services/functions/automation.md","pattern":"Standard device file access","snippet":"HTTP_STATUS=$(curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST\")","category":"filesystem","line_end":357,"severity":"low","line_start":357},{"id":"filesystem:references/services/functions/automation.md:375:standard-device-file-access","file":"references/services/functions/automation.md","pattern":"Standard device file access","snippet":"curl -s -o /dev/null -w \"%{http_code}\" \"https://$DEFAULT_HOST/api/<FUNCTION_NAME>\"","category":"filesystem","line_end":375,"severity":"low","line_start":375},{"id":"sensitive:references/services/functions/automation.md:169:certificate-key-files","file":"references/services/functions/automation.md","pattern":"Certificate/key files","snippet":"echo \"User-assigned identity: $(echo \"$identity\" | jq -r '.key' | sed 's|.*/userAssignedIdentities/|","category":"sensitive","line_end":169,"severity":"high","line_start":169},{"id":"blocker:references/services/functions/automation.md:91:system-reconnaissance","file":"references/services/functions/automation.md","pattern":"System reconnaissance","snippet":"# Find blob triggers NOT using EventGrid source","category":"blocker","line_end":91,"severity":"low","line_start":91},{"id":"blocker:references/services/functions/automation.md:138:system-reconnaissance","file":"references/services/functions/automation.md","pattern":"System reconnaissance","snippet":"az functionapp config hostname list --webapp-name $appName --resource-group $rgName \\","category":"blocker","line_end":138,"severity":"low","line_start":138},{"id":"blocker:references/services/functions/automation.md:245:system-reconnaissance","file":"references/services/functions/automation.md","pattern":"System reconnaissance","snippet":"- `--skip-hostnames` — skip migrating custom domains","category":"blocker","line_end":245,"severity":"low","line_start":245},{"id":"blocker:references/services/functions/automation.md:269:system-reconnaissance","file":"references/services/functions/automation.md","pattern":"System reconnaissance","snippet":"az functionapp config hostname list --webapp-name <NEW_APP_NAME> --resource-group <RESOURCE_GROUP> \\","category":"blocker","line_end":269,"severity":"low","line_start":269},{"id":"external_commands:references/services/functions/consumption-to-flex.md:47:powershell-invocation","file":"references/services/functions/consumption-to-flex.md","pattern":"PowerShell invocation","snippet":"| `powershell` | PowerShell | ✅ Yes |","category":"external_commands","line_end":47,"severity":"high","line_start":47},{"id":"blocker:references/services/functions/consumption-to-flex.md:57:system-reconnaissance","file":"references/services/functions/consumption-to-flex.md","pattern":"System reconnaissance","snippet":"| Blob trigger (polling) | ❌ Only EventGrid source | Convert `LogsAndContainerScan` → `EventGrid` |","category":"blocker","line_end":57,"severity":"low","line_start":57},{"id":"blocker:references/services/functions/consumption-to-flex.md:139:system-reconnaissance","file":"references/services/functions/consumption-to-flex.md","pattern":"System reconnaissance","snippet":"1. **Smoke test** — Get the app’s default hostname via `az functionapp show --query defaultHostName ","category":"blocker","line_end":139,"severity":"low","line_start":139},{"id":"blocker:references/services/functions/consumption-to-flex.md:159:system-reconnaissance","file":"references/services/functions/consumption-to-flex.md","pattern":"System reconnaissance","snippet":"| Azure Event Grid | Medium | Recreate event subscriptions; ensure idempotent functions |","category":"blocker","line_end":159,"severity":"low","line_start":159},{"id":"blocker:references/services/functions/consumption-to-flex.md:164:system-reconnaissance","file":"references/services/functions/consumption-to-flex.md","pattern":"System reconnaissance","snippet":"| Timer | Low | Offset schedules during cutover to avoid simultaneous execution |","category":"blocker","line_end":164,"severity":"low","line_start":164},{"id":"external_commands:references/services/redis/redis-to-amr.md:10:powershell-invocation","file":"references/services/redis/redis-to-amr.md","pattern":"PowerShell invocation","snippet":"| Source SKU | ARM Resource Type | CLI / PowerShell | Dedicated Skill | Repo |","category":"external_commands","line_end":10,"severity":"high","line_start":10},{"id":"external_commands:references/services/redis/redis-to-amr.md:25:powershell-invocation","file":"references/services/redis/redis-to-amr.md","pattern":"PowerShell invocation","snippet":"- PowerShell: `New-AzRedisCache`, `Get-AzRedisCache`, etc.","category":"external_commands","line_end":25,"severity":"high","line_start":25},{"id":"external_commands:references/services/redis/redis-to-amr.md:33:powershell-invocation","file":"references/services/redis/redis-to-amr.md","pattern":"PowerShell invocation","snippet":"- PowerShell: `New-AzRedisEnterpriseCache`, `Get-AzRedisEnterpriseCache`, etc.","category":"external_commands","line_end":33,"severity":"high","line_start":33},{"id":"external_commands:references/services/redis/redis-to-amr.md:44:powershell-invocation","file":"references/services/redis/redis-to-amr.md","pattern":"PowerShell invocation","snippet":"- Real-time pricing scripts (PowerShell + bash) with HA, clustering, and MRPP logic","category":"external_commands","line_end":44,"severity":"high","line_start":44},{"id":"external_commands:references/services/redis/redis-to-amr.md:54:powershell-invocation","file":"references/services/redis/redis-to-amr.md","pattern":"PowerShell invocation","snippet":"- Three modes: automation-script update (ARM/Bicep/CLI/PowerShell/Terraform checklist), interactive ","category":"external_commands","line_end":54,"severity":"high","line_start":54},{"id":"blocker:references/services/redis/redis-to-amr.md:46:system-reconnaissance","file":"references/services/redis/redis-to-amr.md","pattern":"System reconnaissance","snippet":"- Automated migration via ARM REST APIs with **DNS switching** (old hostname keeps working; port sti","category":"blocker","line_end":46,"severity":"low","line_start":46},{"id":"blocker:references/services/redis/redis-to-amr.md:84:system-reconnaissance","file":"references/services/redis/redis-to-amr.md","pattern":"System reconnaissance","snippet":"- **DNS-switch automated migration** keeps old hostname working, but the port change still applies —","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> This skill handles **assessment and automated upgrades** of existing Azure workloads from one Azur","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Use `mcp_azure_mcp_get_azure_bestpractices` and `mcp_azure_mcp_documentation` MCP tools","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. Destructive actions require `ask_user` — [global-rules](references/global-rules.md)","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Legacy Azure Java SDK (`com.microsoft.azure.*`) | Modern Azure Java SDK (`com.azure.*`) | [languag","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> No matching scenario? Use `mcp_azure_mcp_documentation` and `mcp_azure_mcp_get_azure_bestpractices","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mcp_azure_mcp_get_azure_bestpractices` | Get Azure best practices for the target service |","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mcp_azure_mcp_documentation` | Look up Azure documentation for upgrade scenarios |","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mcp_azure_mcp_appservice` | Query App Service and Functions plan details |","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `mcp_azure_mcp_applicationinsights` | Verify monitoring configuration |","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. **Hand off** to `azure-validate` for deep validation or `azure-deploy` for CI/CD setup","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Track progress in `upgrade-status.md` inside the workspace root.","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `azure-validate` — for thorough post-upgrade validation","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `azure-deploy` — if the user wants to set up CI/CD for the new app","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"network:SKILL.md:81:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Redis (ACR or ACRE) to AMR Migration](references/services/redis/redis-to-amr.md) — routes to dedi","category":"network","line_end":81,"severity":"low","line_start":81}],"finding_verdicts":[{"id":"external_commands:references/languages/java/bom-migration/bom-gradle.md:12:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-gradle.md:121:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-gradle.md:122:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-maven.md:12:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-maven.md:111:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:9:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:15:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:17:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/bom-migration/bom-migration.md:31:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/INSTRUCTION.md:17:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/INSTRUCTION.md:19:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/INSTRUCTION.md:25:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/INSTRUCTION.md:82:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/languages/java/INSTRUCTION.md:84:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:21:getenv-function-call","reason":"The guide discusses legacy authentication examples and warns against credential files. The skill itself does not read these environment variables or exfiltrate secrets.","verdict":"false_positive","confidence":0.9},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:25:getenv-function-call","reason":"The guide discusses legacy authentication examples and warns against credential files. The skill itself does not read these environment variables or exfiltrate secrets.","verdict":"false_positive","confidence":0.9},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:21:azure-credential-environment-variables","reason":"The guide discusses legacy authentication examples and warns against credential files. The skill itself does not read these environment variables or exfiltrate secrets.","verdict":"false_positive","confidence":0.9},{"id":"env_access:references/languages/java/package-specific/com.microsoft.azure.management.md:61:azure-credential-environment-variables","reason":"The guide discusses legacy authentication examples and warns against credential files. The skill itself does not read these environment variables or exfiltrate secrets.","verdict":"false_positive","confidence":0.9},{"id":"blocker:references/languages/java/package-specific/com.microsoft.azure.management.md:8:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/rules/troubleshooting.md:7:system-reconnaissance","reason":"The mandatory rule says token limits, time constraints, and complexity are never valid reasons to stop. This is not reconnaissance, but it is a real prompt-control risk.","verdict":"confirmed","severity":"medium","confidence":0.76},{"id":"blocker:references/languages/java/rules/troubleshooting.md:10:system-reconnaissance","reason":"The rule forbids categorical dismissals of failures. It can override normal risk triage in edge cases, so it is kept as a low-confidence control risk.","verdict":"confirmed","severity":"medium","confidence":0.66},{"id":"blocker:references/languages/java/rules/troubleshooting.md:12:system-reconnaissance","reason":"The rule allows limitations only after exhaustive attempts. That can conflict with practical stopping criteria and user-directed scope limits.","verdict":"confirmed","severity":"medium","confidence":0.64},{"id":"blocker:references/languages/java/rules/troubleshooting.md:19:system-reconnaissance","reason":"The rule forbids partial migration as a stopping point. In a marketplace skill, this can push broad code modification beyond the user-approved scope.","verdict":"confirmed","severity":"medium","confidence":0.69},{"id":"filesystem:references/languages/java/rules/upgrade-strategy.md:7:path-traversal-sequence","reason":"The ../ sequence is a relative Markdown link to another skill reference file. It is not used for file access with user-controlled input.","verdict":"false_positive","confidence":0.95},{"id":"blocker:references/languages/java/rules/upgrade-strategy.md:3:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:references/languages/java/scripts/upgrade_bom.py:195:python-subprocess-run","reason":"The script runs Maven and OpenRewrite in the target project. Even without shell=True, project build tools can execute project-controlled plugins and scripts.","verdict":"confirmed","severity":"high","confidence":0.84},{"id":"external_commands:references/languages/java/scripts/upgrade_bom.py:433:python-subprocess-run","reason":"The script runs Gradle rewriteRun in the target project. Gradle builds can execute project-controlled code and alter files during migration.","verdict":"confirmed","severity":"high","confidence":0.84},{"id":"external_commands:references/languages/java/scripts/upgrade_bom.py:371:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"network:references/languages/java/scripts/upgrade_bom.py:40:python-http-libraries","reason":"The imported urllib module is used by the same script to fetch BOM metadata from GitHub. This is an external network dependency that influences migration output.","verdict":"confirmed","severity":"low","confidence":0.72},{"id":"network:references/languages/java/scripts/upgrade_bom.py:82:python-http-libraries","reason":"The script downloads the Azure SDK BOM POM from GitHub to select a version. The fetch is legitimate but remote content affects dependency rewrites.","verdict":"confirmed","severity":"low","confidence":0.86},{"id":"network:references/languages/java/scripts/upgrade_bom.py:45:hardcoded-url","reason":"The hardcoded raw.githubusercontent.com URL is fetched for BOM data. A remote source controls version selection, so integrity and availability matter.","verdict":"confirmed","severity":"low","confidence":0.84},{"id":"network:references/languages/java/scripts/upgrade_bom.py:46:hardcoded-url","reason":"This URL is an XML namespace string used for POM parsing. It is not fetched over the network.","verdict":"false_positive","confidence":0.95},{"id":"network:references/languages/java/scripts/upgrade_bom.py:169:hardcoded-url","reason":"This URL is an XML namespace string used for POM parsing. It is not fetched over the network.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:331:python-file-write-append","reason":"The script writes rewrite.yml in the target project without preserving a preexisting file. Cleanup later can remove the same generic project file.","verdict":"confirmed","severity":"high","confidence":0.93},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:394:python-file-write-append","reason":"The script rewrites the Gradle build file to inject OpenRewrite configuration. This directly modifies project build configuration and can corrupt it if assumptions fail.","verdict":"confirmed","severity":"medium","confidence":0.87},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:425:python-file-write-append","reason":"The script rewrites the Gradle build file again during cleanup. Marker-based cleanup can remove or alter build configuration if the file differs from expectations.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:150:python-os-file-operations","reason":"The script changes executable bits on mvnw in the target project. This is intended wrapper handling but still mutates project file permissions.","verdict":"confirmed","severity":"medium","confidence":0.77},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:257:python-os-file-operations","reason":"The script changes executable bits on gradlew in the target project. This is intended wrapper handling but still mutates project file permissions.","verdict":"confirmed","severity":"medium","confidence":0.77},{"id":"filesystem:references/languages/java/scripts/upgrade_bom.py:460:python-os-file-operations","reason":"The script deletes rewrite.yml during cleanup. Because the name is generic, an existing user OpenRewrite configuration could be removed.","verdict":"confirmed","severity":"high","confidence":0.92},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:103:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:171:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:172:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:173:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:177:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:178:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:179:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:352:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:414:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/scripts/upgrade_bom.py:502:network-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/templates/PLAN_TEMPLATE.md:10:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/templates/PLAN_TEMPLATE.md:34:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/templates/PLAN_TEMPLATE.md:180:network-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/languages/java/templates/PROGRESS_TEMPLATE.md:16:system-reconnaissance","reason":"The template says token limits, time constraints, and complexity are never valid reasons to skip fixing. This can pressure an agent to ignore operational limits.","verdict":"confirmed","severity":"medium","confidence":0.78},{"id":"blocker:references/languages/java/templates/PROGRESS_TEMPLATE.md:27:system-reconnaissance","reason":"The template forbids dismissing failing tests as non-production or sample issues. This can be useful quality guidance, but it also reduces safe stopping discretion.","verdict":"confirmed","severity":"medium","confidence":0.66},{"id":"blocker:references/languages/java/templates/PROGRESS_TEMPLATE.md:82:network-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:references/languages/java/workflow/phase-1-precheck.md:3:path-traversal-sequence","reason":"The ../ sequence is a relative Markdown link to another skill reference file. It is not used for file access with user-controlled input.","verdict":"false_positive","confidence":0.95},{"id":"blocker:references/languages/java/workflow/phase-1-precheck.md:9:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:references/languages/java/workflow/phase-2-plan.md:3:path-traversal-sequence","reason":"The ../ sequence is a relative Markdown link to another skill reference file. It is not used for file access with user-controlled input.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/languages/java/workflow/phase-3-execute.md:3:path-traversal-sequence","reason":"The ../ sequence is a relative Markdown link to another skill reference file. It is not used for file access with user-controlled input.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/languages/java/workflow/phase-3-execute.md:24:path-traversal-sequence","reason":"The ../ sequence is a relative Markdown link to another skill reference file. It is not used for file access with user-controlled input.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/languages/java/workflow/phase-4-summarize.md:3:path-traversal-sequence","reason":"The ../ sequence is a relative Markdown link to another skill reference file. It is not used for file access with user-controlled input.","verdict":"false_positive","confidence":0.95},{"id":"blocker:references/services/functions/assessment.md:20:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/functions/assessment.md:56:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:references/services/functions/automation.md:139:ruby-shell-backtick-execution","reason":"The backticks are escaped JMESPath syntax inside an Azure CLI query. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/services/functions/automation.md:110:shell-command-substitution","reason":"The script reads all Function App settings and then prints them. App settings often contain secrets, connection strings, or tokens.","verdict":"confirmed","severity":"high","confidence":0.91},{"id":"external_commands:references/services/functions/automation.md:152:shell-command-substitution","reason":"The script enumerates system-assigned managed identity principal IDs. This is read-only but exposes cloud identity metadata.","verdict":"confirmed","severity":"medium","confidence":0.74},{"id":"external_commands:references/services/functions/automation.md:164:shell-command-substitution","reason":"The script enumerates user-assigned managed identities. This is legitimate assessment work but reveals cloud identity metadata.","verdict":"confirmed","severity":"medium","confidence":0.74},{"id":"external_commands:references/services/functions/automation.md:169:shell-command-substitution","reason":"The loop prints user-assigned identity names derived from resource IDs. This can disclose identity inventory during migration.","verdict":"confirmed","severity":"medium","confidence":0.73},{"id":"external_commands:references/services/functions/automation.md:171:shell-command-substitution","reason":"The script lists all role assignments for each identity principal. RBAC enumeration can reveal privilege paths and should be handled carefully.","verdict":"confirmed","severity":"medium","confidence":0.82},{"id":"external_commands:references/services/functions/automation.md:213:shell-command-substitution","reason":"The script reads AzureWebJobsStorage into a shell variable. This value is a credential-bearing connection string and may be exposed through logs or shell state.","verdict":"confirmed","severity":"high","confidence":0.92},{"id":"external_commands:references/services/functions/automation.md:217:shell-command-substitution","reason":"The script uses the storage connection string to list deployment packages. It combines credential use with unquoted shell variables in runnable guidance.","verdict":"confirmed","severity":"high","confidence":0.88},{"id":"external_commands:references/services/functions/automation.md:354:shell-command-substitution","reason":"The script discovers the migrated app default hostname for validation. This is low-impact cloud resource discovery but still executes Azure CLI.","verdict":"confirmed","severity":"medium","confidence":0.67},{"id":"external_commands:references/services/functions/automation.md:357:shell-command-substitution","reason":"The script performs an HTTP smoke test against the migrated app. This is legitimate validation but calls a live endpoint.","verdict":"confirmed","severity":"medium","confidence":0.71},{"id":"external_commands:references/services/functions/automation.md:4:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/services/functions/automation.md:57:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/services/functions/automation.md:68:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"network:references/services/functions/automation.md:357:hardcoded-url","reason":"The curl command sends a request to the app hostname. The URL is dynamic, but the line still performs a network call to a live Azure endpoint.","verdict":"confirmed","severity":"low","confidence":0.7},{"id":"network:references/services/functions/automation.md:375:hardcoded-url","reason":"The curl command can invoke a live HTTP trigger endpoint. If the function is not idempotent, validation may have side effects.","verdict":"confirmed","severity":"medium","confidence":0.74},{"id":"filesystem:references/services/functions/automation.md:357:standard-device-file-access","reason":"The curl command writes output to /dev/null to discard the response body. This is normal shell output handling, not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/services/functions/automation.md:375:standard-device-file-access","reason":"The curl command writes output to /dev/null to discard the response body. This is normal shell output handling, not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:references/services/functions/automation.md:169:certificate-key-files","reason":"The .key reference is a JSON object key for an Azure user-assigned identity resource ID. It is not a certificate or private key file.","verdict":"false_positive","confidence":0.92},{"id":"blocker:references/services/functions/automation.md:91:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/functions/automation.md:138:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/functions/automation.md:245:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/functions/automation.md:269:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:references/services/functions/consumption-to-flex.md:47:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/services/functions/consumption-to-flex.md:57:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/functions/consumption-to-flex.md:139:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/functions/consumption-to-flex.md:159:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/functions/consumption-to-flex.md:164:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:references/services/redis/redis-to-amr.md:10:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/services/redis/redis-to-amr.md:25:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/services/redis/redis-to-amr.md:33:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/services/redis/redis-to-amr.md:44:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/services/redis/redis-to-amr.md:54:powershell-invocation","reason":"This line is a Markdown mention, code fence, supported runtime label, or compatibility note about PowerShell. It does not execute PowerShell programmatically.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/services/redis/redis-to-amr.md:46:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"blocker:references/services/redis/redis-to-amr.md:84:system-reconnaissance","reason":"This line is migration guidance, template text, XML parsing, or status wording. It does not perform system or network reconnaissance.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline code formatting or a source-code comment. They do not invoke a shell command.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:81:hardcoded-url","reason":"This is a documentation link or placeholder URL reference, not a runtime network request from the skill code.","verdict":"false_positive","confidence":0.88}],"semantic_findings":[{"title":"Overbroad Agent Autonomy Instructions","severity":"high","locations":[{"file":"references/languages/java/templates/PROGRESS_TEMPLATE.md","line_end":27,"line_start":15},{"file":"references/languages/java/rules/troubleshooting.md","line_end":20,"line_start":7},{"file":"references/languages/java/workflow/phase-2-plan.md","line_end":44,"line_start":40}],"confidence":0.88,"description":"The Java workflow tells the agent to avoid pausing, treats token and time limits as invalid, and proceeds directly to execution. These instructions can conflict with host limits, user confirmation, and safe scope control.","confidence_reasoning":"The cited text directly imposes no-pause and no-stop behavior. It does not claim system authority, but it can override user or host boundaries."},{"title":"Project Configuration Overwrite and Deletion Risk","severity":"high","locations":[{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":333,"line_start":300},{"file":"references/languages/java/scripts/upgrade_bom.py","line_end":463,"line_start":459}],"confidence":0.93,"description":"The BOM helper writes rewrite.yml in the project root and later removes that path. A preexisting OpenRewrite configuration can be overwritten or deleted.","confidence_reasoning":"The code constructs a fixed rewrite.yml path, writes it, and removes it during cleanup. There is no check, backup, or restore for an existing user file."},{"title":"Sensitive Azure Configuration Disclosure","severity":"high","locations":[{"file":"references/services/functions/automation.md","line_end":111,"line_start":109},{"file":"references/services/functions/automation.md","line_end":218,"line_start":212}],"confidence":0.91,"description":"The automation guidance collects and prints app settings, then reads the AzureWebJobsStorage connection string for storage access. These values commonly contain secrets.","confidence_reasoning":"The cited commands explicitly collect app settings and a storage connection string. Azure app settings commonly include credentials and tokens."},{"title":"Unquoted Deployment Package Filename","severity":"medium","locations":[{"file":"references/services/functions/automation.md","line_end":222,"line_start":217}],"confidence":0.78,"description":"The package name returned from blob storage is used unquoted as the local output file path. Blob names with spaces, option-like prefixes, or path separators can cause unintended behavior.","confidence_reasoning":"The package name comes from remote blob metadata and is expanded unquoted in a shell command. This creates plausible parsing and file path risks."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":10,"capabilityReviewCount":22,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}