{"data":{"skill":{"slug":"microsoft-python-appservice-deploy","name":"python-appservice-deploy","icon":"📦","repo":"https://github.com/microsoft/azure-skills/tree/main/.github/plugins/azure-skills/skills/python-appservice-deploy/","status":"approved","author":"microsoft","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"6b4d4df1-c78f-4bd6-a373-cb09bd2aa96f","skill_id":"ff8799c3-e6b8-4cf4-862f-61a9ebfdd84b","version":3,"content_hash":"v2:1200d2f84325e4a40a4c6cc230f3864179fd6940:084bd2ef7dce6fabaec77f02c48c1d794072fa6770f18c4f180f0c17c703a4c9:9f5ba3173880504ff0b50fcda1c5e0107253aa43c8608eb4b74246f54efafdaf:61e14eb8062bd358264c55b853a93176","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static findings are Markdown examples, Azure CLI snippets, placeholders, or benign device references, so they were adjudicated as false positives. I confirmed the retry wrapper command execution paths because they run caller-provided command strings through eval or PowerShell -Command. No prompt injection or data exfiltration intent was found.","remediation":[{"issue":"Retry wrappers execute concatenated command strings.","severity":"high","suggestion":"Replace eval and powershell -Command with argument arrays or a fixed allowlist of Azure commands and parameters."},{"issue":"User-provided Azure resource values may be interpolated into shell commands.","severity":"high","suggestion":"Validate app, resource group, plan, region, and subscription values before use, and reject shell metacharacters."},{"issue":"The workflow creates paid Azure resources without explicit confirmation.","severity":"medium","suggestion":"Require a clear user confirmation that names the subscription, region, SKU, and resources before creation."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/create-app.md","line_end":38,"line_start":38},{"file":"references/create-app.md","line_end":5,"line_start":5},{"file":"references/create-app.md","line_end":24,"line_start":24},{"file":"references/create-app.md","line_end":40,"line_start":40},{"file":"references/create-app.md","line_end":74,"line_start":74},{"file":"references/create-app.md","line_end":87,"line_start":87},{"file":"references/create-app.md","line_end":96,"line_start":96},{"file":"references/create-app.md","line_end":102,"line_start":102},{"file":"references/deploy-azcli.md","line_end":24,"line_start":22},{"file":"references/deploy-azcli.md","line_end":77,"line_start":76},{"file":"references/deploy-azcli.md","line_end":80,"line_start":78},{"file":"references/deploy-azcli.md","line_end":95,"line_start":95},{"file":"references/deploy-azcli.md","line_end":20,"line_start":20},{"file":"references/deploy-azcli.md","line_end":38,"line_start":38},{"file":"references/deploy-azcli.md","line_end":58,"line_start":58},{"file":"references/deploy-azcli.md","line_end":59,"line_start":59},{"file":"references/deploy-azcli.md","line_end":74,"line_start":74},{"file":"references/deploy-azcli.md","line_end":98,"line_start":98},{"file":"references/deploy-azd.md","line_end":18,"line_start":16},{"file":"references/deploy-azd.md","line_end":22,"line_start":20},{"file":"references/deploy-azd.md","line_end":19,"line_start":19},{"file":"references/deploy-azd.md","line_end":31,"line_start":31},{"file":"references/deploy-azd.md","line_end":72,"line_start":72},{"file":"references/deploy-azd.md","line_end":73,"line_start":73},{"file":"references/errors.md","line_end":8,"line_start":7},{"file":"references/errors.md","line_end":9,"line_start":8},{"file":"references/errors.md","line_end":10,"line_start":9},{"file":"references/errors.md","line_end":10,"line_start":10},{"file":"references/errors.md","line_end":41,"line_start":41},{"file":"references/post-deploy-message.md","line_end":71,"line_start":71},{"file":"references/startup-commands.md","line_end":26,"line_start":26},{"file":"references/startup-commands.md","line_end":47,"line_start":47},{"file":"references/startup-commands.md","line_end":58,"line_start":58},{"file":"references/startup-commands.md","line_end":71,"line_start":71},{"file":"references/transient-retry.md","line_end":42,"line_start":40},{"file":"references/transient-retry.md","line_end":37,"line_start":37},{"file":"references/transient-retry.md","line_end":38,"line_start":38},{"file":"scripts/generate-app-name.ps1","line_end":5,"line_start":5},{"file":"scripts/generate-app-name.sh","line_end":4,"line_start":4},{"file":"scripts/generate-app-name.sh","line_end":23,"line_start":23},{"file":"scripts/generate-app-name.sh","line_end":28,"line_start":26},{"file":"scripts/generate-app-name.sh","line_end":37,"line_start":37},{"file":"scripts/generate-app-name.sh","line_end":40,"line_start":40},{"file":"scripts/generate-app-name.sh","line_end":46,"line_start":46},{"file":"scripts/generate-app-name.sh","line_end":58,"line_start":58},{"file":"scripts/retry-az-create.ps1","line_end":3,"line_start":3},{"file":"scripts/retry-az-create.ps1","line_end":13,"line_start":13},{"file":"scripts/retry-az-create.ps1","line_end":15,"line_start":15},{"file":"scripts/retry-az-create.ps1","line_end":18,"line_start":17},{"file":"scripts/retry-az-create.ps1","line_end":22,"line_start":21},{"file":"scripts/retry-az-create.ps1","line_end":36,"line_start":36},{"file":"scripts/retry-az-create.ps1","line_end":39,"line_start":39},{"file":"scripts/retry-az-create.ps1","line_end":40,"line_start":40},{"file":"scripts/retry-az-create.sh","line_end":3,"line_start":3},{"file":"scripts/retry-az-create.sh","line_end":11,"line_start":11},{"file":"scripts/retry-az-create.sh","line_end":13,"line_start":13},{"file":"scripts/retry-az-create.sh","line_end":36,"line_start":36},{"file":"scripts/retry-az-create.sh","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":36,"line_start":36}]},{"factor":"filesystem","evidence":[{"file":"references/create-app.md","line_end":23,"line_start":23},{"file":"references/create-app.md","line_end":24,"line_start":24},{"file":"references/create-app.md","line_end":5,"line_start":5},{"file":"references/create-app.md","line_end":38,"line_start":38},{"file":"references/create-app.md","line_end":71,"line_start":71},{"file":"references/create-app.md","line_end":84,"line_start":84},{"file":"references/create-app.md","line_end":99,"line_start":99},{"file":"references/transient-retry.md","line_end":31,"line_start":31},{"file":"references/transient-retry.md","line_end":37,"line_start":37},{"file":"scripts/generate-app-name.sh","line_end":36,"line_start":36},{"file":"scripts/generate-app-name.sh","line_end":39,"line_start":39},{"file":"scripts/generate-app-name.sh","line_end":40,"line_start":40},{"file":"scripts/retry-az-create.sh","line_end":36,"line_start":36}]},{"factor":"network","evidence":[{"file":"references/deploy-azcli.md","line_end":96,"line_start":96},{"file":"references/deploy-azcli.md","line_end":100,"line_start":100},{"file":"references/deploy-azcli.md","line_end":36,"line_start":36},{"file":"references/deploy-azcli.md","line_end":40,"line_start":40},{"file":"references/detect.md","line_end":68,"line_start":68},{"file":"references/post-deploy-message.md","line_end":19,"line_start":19},{"file":"references/post-deploy-message.md","line_end":36,"line_start":36},{"file":"references/post-deploy-message.md","line_end":49,"line_start":49},{"file":"references/post-deploy-message.md","line_end":51,"line_start":51},{"file":"references/startup-commands.md","line_end":24,"line_start":24},{"file":"references/startup-commands.md","line_end":28,"line_start":28},{"file":"references/startup-commands.md","line_end":45,"line_start":45},{"file":"references/startup-commands.md","line_end":49,"line_start":49},{"file":"references/startup-commands.md","line_end":56,"line_start":56},{"file":"references/startup-commands.md","line_end":60,"line_start":60},{"file":"references/startup-commands.md","line_end":69,"line_start":69},{"file":"references/startup-commands.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":22,"line_start":22}]}],"critical_findings":[],"high_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"scripts/retry-az-create.ps1","line_end":39,"line_start":39}],"confidence":0.86,"description":"$script = \"$ShowCommand -o none 2>`$null; if (`$LASTEXITCODE -ne 0) { $CreateCommand -o none }\"","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line builds a PowerShell command string from caller-provided ShowCommand and CreateCommand values. The string is executed on the next line, creating command-injection exposure if interpolated values are unsafe."},{"title":"PowerShell invocation","locations":[{"file":"scripts/retry-az-create.ps1","line_end":40,"line_start":40}],"confidence":0.93,"description":"& powershell -NoProfile -Command $script 2>&1","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This invokes powershell -Command on a dynamically assembled script string. That is a real command-execution risk when the input command strings include unescaped user-controlled Azure names."},{"title":"Shell command substitution","locations":[{"file":"scripts/retry-az-create.sh","line_end":36,"line_start":36}],"confidence":0.92,"description":"if err=$({ eval \"$SHOW_CMD -o none 2>/dev/null\" || eval \"$CREATE_CMD -o none\"; } 2>&1); then","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line executes caller-provided command strings with eval after appending arguments. If resource values are not shell escaped before reaching the wrapper, shell metacharacters can become commands."},{"title":"Unsanitized Command Strings in Retry Wrappers","locations":[{"file":"references/create-app.md","line_end":9,"line_start":9},{"file":"scripts/retry-az-create.sh","line_end":36,"line_start":29},{"file":"scripts/retry-az-create.ps1","line_end":40,"line_start":25}],"confidence":0.9,"description":"The workflow permits user-supplied Azure values, while retry wrappers execute whole command strings through eval or PowerShell -Command. Unsafe interpolation could allow shell metacharacters to run as commands.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The scripts accept full command strings and execute them dynamically. The deployment guide says to use user-requested resource values verbatim, so injection depends on caller escaping."}],"medium_findings":[{"title":"Billable Azure Resources Created Without Explicit Confirmation","locations":[{"file":"references/create-app.md","line_end":63,"line_start":46},{"file":"references/create-app.md","line_end":105,"line_start":79},{"file":"SKILL.md","line_end":24,"line_start":18}],"confidence":0.86,"description":"The guide derives resource names, prints defaults, and tells the agent not to ask for confirmation before creating a P0v3 App Service plan and web app. This can spend money or change cloud state after a single deployment request.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The cited lines explicitly skip confirmation and create or reuse paid Azure resources. This is intentional deployment behavior, but it is a marketplace safety risk."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":13,"total_lines":985,"audit_model":"codex","audited_at":"2026-07-08T05:43:17.615+00:00","created_at":"2026-07-08T06:37:51.823559+00:00","static_findings":[{"id":"external_commands:references/create-app.md:38:shell-command-substitution","file":"references/create-app.md","pattern":"Shell command substitution","snippet":"REGION=$(az config get defaults.location -o tsv 2>/dev/null) || REGION=\"\"","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:references/create-app.md:5:powershell-invocation","file":"references/create-app.md","pattern":"PowerShell invocation","snippet":"> 💡 **Shell note**: Bash blocks below use `\\` line continuation, `||`, `2>/dev/null`, `$(...)`. Pow","category":"external_commands","line_end":5,"severity":"high","line_start":5},{"id":"external_commands:references/create-app.md:24:powershell-invocation","file":"references/create-app.md","pattern":"PowerShell invocation","snippet":"- PowerShell: [`scripts/generate-app-name.ps1`](../scripts/generate-app-name.ps1) → `$appName = & .\\","category":"external_commands","line_end":24,"severity":"high","line_start":24},{"id":"external_commands:references/create-app.md:40:powershell-invocation","file":"references/create-app.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":40,"severity":"high","line_start":40},{"id":"external_commands:references/create-app.md:74:powershell-invocation","file":"references/create-app.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":74,"severity":"high","line_start":74},{"id":"external_commands:references/create-app.md:87:powershell-invocation","file":"references/create-app.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":87,"severity":"high","line_start":87},{"id":"external_commands:references/create-app.md:96:powershell-invocation","file":"references/create-app.md","pattern":"PowerShell invocation","snippet":"> ⚠️ **Shell safety**: Always use the **colon** form `PYTHON:3.14` — never the pipe form `PYTHON|3.1","category":"external_commands","line_end":96,"severity":"high","line_start":96},{"id":"external_commands:references/create-app.md:102:powershell-invocation","file":"references/create-app.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":102,"severity":"high","line_start":102},{"id":"filesystem:references/create-app.md:23:path-traversal-sequence","file":"references/create-app.md","pattern":"Path traversal sequence","snippet":"- Bash / zsh: [`scripts/generate-app-name.sh`](../scripts/generate-app-name.sh) → `APP_NAME=$(./scri","category":"filesystem","line_end":23,"severity":"high","line_start":23},{"id":"filesystem:references/create-app.md:24:path-traversal-sequence","file":"references/create-app.md","pattern":"Path traversal sequence","snippet":"- PowerShell: [`scripts/generate-app-name.ps1`](../scripts/generate-app-name.ps1) → `$appName = & .\\","category":"filesystem","line_end":24,"severity":"high","line_start":24},{"id":"filesystem:references/create-app.md:5:standard-device-file-access","file":"references/create-app.md","pattern":"Standard device file access","snippet":"> 💡 **Shell note**: Bash blocks below use `\\` line continuation, `||`, `2>/dev/null`, `$(...)`. Pow","category":"filesystem","line_end":5,"severity":"low","line_start":5},{"id":"filesystem:references/create-app.md:38:standard-device-file-access","file":"references/create-app.md","pattern":"Standard device file access","snippet":"REGION=$(az config get defaults.location -o tsv 2>/dev/null) || REGION=\"\"","category":"filesystem","line_end":38,"severity":"low","line_start":38},{"id":"filesystem:references/create-app.md:71:standard-device-file-access","file":"references/create-app.md","pattern":"Standard device file access","snippet":"az group show -n <rg> --only-show-errors 2>/dev/null || \\","category":"filesystem","line_end":71,"severity":"low","line_start":71},{"id":"filesystem:references/create-app.md:84:standard-device-file-access","file":"references/create-app.md","pattern":"Standard device file access","snippet":"az appservice plan show -n <plan> -g <rg> --only-show-errors 2>/dev/null || \\","category":"filesystem","line_end":84,"severity":"low","line_start":84},{"id":"filesystem:references/create-app.md:99:standard-device-file-access","file":"references/create-app.md","pattern":"Standard device file access","snippet":"az webapp show -n <app> -g <rg> --only-show-errors 2>/dev/null || \\","category":"filesystem","line_end":99,"severity":"low","line_start":99},{"id":"blocker:references/create-app.md:13:system-reconnaissance","file":"references/create-app.md","pattern":"System reconnaissance","snippet":"az account show --query id -o tsv","category":"blocker","line_end":13,"severity":"low","line_start":13},{"id":"blocker:references/create-app.md:28:system-reconnaissance","file":"references/create-app.md","pattern":"System reconnaissance","snippet":"### 1c. Derived names (use only when user did not specify)","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"blocker:references/create-app.md:109:system-reconnaissance","file":"references/create-app.md","pattern":"System reconnaissance","snippet":"The 8-hex-char GUID suffix from §1b is sufficient for global hostname uniqueness; the optional `--do","category":"blocker","line_end":109,"severity":"low","line_start":109},{"id":"external_commands:references/deploy-azcli.md:22:ruby-shell-backtick-execution","file":"references/deploy-azcli.md","pattern":"Ruby/shell backtick execution","snippet":"-n <app> -g <rg> `","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:references/deploy-azcli.md:76:ruby-shell-backtick-execution","file":"references/deploy-azcli.md","pattern":"Ruby/shell backtick execution","snippet":"-n <app> -g <rg> `","category":"external_commands","line_end":77,"severity":"medium","line_start":76},{"id":"external_commands:references/deploy-azcli.md:78:ruby-shell-backtick-execution","file":"references/deploy-azcli.md","pattern":"Ruby/shell backtick execution","snippet":"--type zip `","category":"external_commands","line_end":80,"severity":"medium","line_start":78},{"id":"external_commands:references/deploy-azcli.md:95:shell-command-substitution","file":"references/deploy-azcli.md","pattern":"Shell command substitution","snippet":"HOST=$(az webapp show -n <app> -g <rg> --query defaultHostName -o tsv)","category":"external_commands","line_end":95,"severity":"medium","line_start":95},{"id":"external_commands:references/deploy-azcli.md:20:powershell-invocation","file":"references/deploy-azcli.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":20,"severity":"high","line_start":20},{"id":"external_commands:references/deploy-azcli.md:38:powershell-invocation","file":"references/deploy-azcli.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":38,"severity":"high","line_start":38},{"id":"external_commands:references/deploy-azcli.md:58:powershell-invocation","file":"references/deploy-azcli.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":58,"severity":"high","line_start":58},{"id":"external_commands:references/deploy-azcli.md:59:powershell-invocation","file":"references/deploy-azcli.md","pattern":"PowerShell invocation","snippet":"# PowerShell","category":"external_commands","line_end":59,"severity":"high","line_start":59},{"id":"external_commands:references/deploy-azcli.md:74:powershell-invocation","file":"references/deploy-azcli.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":74,"severity":"high","line_start":74},{"id":"external_commands:references/deploy-azcli.md:98:powershell-invocation","file":"references/deploy-azcli.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":98,"severity":"high","line_start":98},{"id":"network:references/deploy-azcli.md:96:hardcoded-url","file":"references/deploy-azcli.md","pattern":"Hardcoded URL","snippet":"echo \"https://$HOST\"","category":"network","line_end":96,"severity":"low","line_start":96},{"id":"network:references/deploy-azcli.md:100:hardcoded-url","file":"references/deploy-azcli.md","pattern":"Hardcoded URL","snippet":"\"https://$host_\"","category":"network","line_end":100,"severity":"low","line_start":100},{"id":"network:references/deploy-azcli.md:36:hardcoded-ip-address","file":"references/deploy-azcli.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"python -m uvicorn main:app --host 0.0.0.0\"","category":"network","line_end":36,"severity":"medium","line_start":36},{"id":"network:references/deploy-azcli.md:40:hardcoded-ip-address","file":"references/deploy-azcli.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"python -m uvicorn main:app --host 0.0.0.0\"","category":"network","line_end":40,"severity":"medium","line_start":40},{"id":"sensitive:references/deploy-azcli.md:55:environment-file-access","file":"references/deploy-azcli.md","pattern":"Environment file access","snippet":"-x \"*.pyc\" -x \".env\" -x \"node_modules/*\"","category":"sensitive","line_end":55,"severity":"high","line_start":55},{"id":"external_commands:references/deploy-azd.md:16:ruby-shell-backtick-execution","file":"references/deploy-azd.md","pattern":"Ruby/shell backtick execution","snippet":"# Look for `host: appservice` under services in azure.yaml","category":"external_commands","line_end":18,"severity":"medium","line_start":16},{"id":"external_commands:references/deploy-azd.md:20:ruby-shell-backtick-execution","file":"references/deploy-azd.md","pattern":"Ruby/shell backtick execution","snippet":"# Look for `host: appservice` under services in azure.yaml","category":"external_commands","line_end":22,"severity":"medium","line_start":20},{"id":"external_commands:references/deploy-azd.md:19:powershell-invocation","file":"references/deploy-azd.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":19,"severity":"high","line_start":19},{"id":"external_commands:references/deploy-azd.md:31:powershell-invocation","file":"references/deploy-azd.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":31,"severity":"high","line_start":31},{"id":"external_commands:references/deploy-azd.md:72:powershell-invocation","file":"references/deploy-azd.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":72,"severity":"high","line_start":72},{"id":"external_commands:references/deploy-azd.md:73:powershell-invocation","file":"references/deploy-azd.md","pattern":"PowerShell invocation","snippet":"# PowerShell","category":"external_commands","line_end":73,"severity":"high","line_start":73},{"id":"network:references/detect.md:68:hardcoded-ip-address","file":"references/detect.md","pattern":"Hardcoded IP address","snippet":"python -m uvicorn main:app --host 0.0.0.0","category":"network","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:references/errors.md:7:ruby-shell-backtick-execution","file":"references/errors.md","pattern":"Ruby/shell backtick execution","snippet":"├─ Check `az webapp log tail` first","category":"external_commands","line_end":8,"severity":"medium","line_start":7},{"id":"external_commands:references/errors.md:8:ruby-shell-backtick-execution","file":"references/errors.md","pattern":"Ruby/shell backtick execution","snippet":"├─ Then `az webapp log deployment list` for build-time errors","category":"external_commands","line_end":9,"severity":"medium","line_start":8},{"id":"external_commands:references/errors.md:9:ruby-shell-backtick-execution","file":"references/errors.md","pattern":"Ruby/shell backtick execution","snippet":"├─ Then `az webapp config show` to verify runtime + startup","category":"external_commands","line_end":10,"severity":"medium","line_start":9},{"id":"external_commands:references/errors.md:10:ruby-shell-backtick-execution","file":"references/errors.md","pattern":"Ruby/shell backtick execution","snippet":"└─ For `Connection reset` / `429` / `502-504` on create commands,","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:references/errors.md:41:powershell-invocation","file":"references/errors.md","pattern":"PowerShell invocation","snippet":"> ```powershell","category":"external_commands","line_end":41,"severity":"high","line_start":41},{"id":"blocker:references/errors.md:27:system-reconnaissance","file":"references/errors.md","pattern":"System reconnaissance","snippet":"| Deployment hangs in \"Building...\" | Oryx pip install failing on native deps | Run `az webapp log d","category":"blocker","line_end":27,"severity":"low","line_start":27},{"id":"blocker:references/errors.md:54:system-reconnaissance","file":"references/errors.md","pattern":"System reconnaissance","snippet":"| Deployment details | `az webapp log deployment show -n <app> -g <rg> --deployment-id <id>` |","category":"blocker","line_end":54,"severity":"low","line_start":54},{"id":"external_commands:references/post-deploy-message.md:71:powershell-invocation","file":"references/post-deploy-message.md","pattern":"PowerShell invocation","snippet":"> ```powershell","category":"external_commands","line_end":71,"severity":"high","line_start":71},{"id":"network:references/post-deploy-message.md:19:hardcoded-url","file":"references/post-deploy-message.md","pattern":"Hardcoded URL","snippet":"🌐 App URL: https://<app>.azurewebsites.net","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:references/post-deploy-message.md:36:hardcoded-url","file":"references/post-deploy-message.md","pattern":"Hardcoded URL","snippet":"🌐 App URL: https://<app>.azurewebsites.net","category":"network","line_end":36,"severity":"low","line_start":36},{"id":"network:references/post-deploy-message.md:49:hardcoded-ip-address","file":"references/post-deploy-message.md","pattern":"Hardcoded IP address","snippet":"gunicorn --bind=0.0.0.0 --timeout 600 <module>:<callable>","category":"network","line_end":49,"severity":"medium","line_start":49},{"id":"network:references/post-deploy-message.md:51:hardcoded-ip-address","file":"references/post-deploy-message.md","pattern":"Hardcoded IP address","snippet":"python -m uvicorn <module>:<callable> --host 0.0.0.0 --port 8000","category":"network","line_end":51,"severity":"medium","line_start":51},{"id":"blocker:references/post-deploy-message.md:81:system-reconnaissance","file":"references/post-deploy-message.md","pattern":"System reconnaissance","snippet":"| Deployment details | `az webapp log deployment show -n <app> -g <rg> --deployment-id <id>` |","category":"blocker","line_end":81,"severity":"low","line_start":81},{"id":"external_commands:references/startup-commands.md:26:powershell-invocation","file":"references/startup-commands.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":26,"severity":"high","line_start":26},{"id":"external_commands:references/startup-commands.md:47:powershell-invocation","file":"references/startup-commands.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":47,"severity":"high","line_start":47},{"id":"external_commands:references/startup-commands.md:58:powershell-invocation","file":"references/startup-commands.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":58,"severity":"high","line_start":58},{"id":"external_commands:references/startup-commands.md:71:powershell-invocation","file":"references/startup-commands.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":71,"severity":"high","line_start":71},{"id":"network:references/startup-commands.md:24:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"python -m uvicorn main:app --host 0.0.0.0\"","category":"network","line_end":24,"severity":"medium","line_start":24},{"id":"network:references/startup-commands.md:28:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"python -m uvicorn main:app --host 0.0.0.0\"","category":"network","line_end":28,"severity":"medium","line_start":28},{"id":"network:references/startup-commands.md:45:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"gunicorn --bind=0.0.0.0 --timeout 600 <module>:<callable>\"","category":"network","line_end":45,"severity":"medium","line_start":45},{"id":"network:references/startup-commands.md:49:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"gunicorn --bind=0.0.0.0 --timeout 600 <module>:<callable>\"","category":"network","line_end":49,"severity":"medium","line_start":49},{"id":"network:references/startup-commands.md:56:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"python -m uvicorn <module>:<callable> --host 0.0.0.0 --port 8000\"","category":"network","line_end":56,"severity":"medium","line_start":56},{"id":"network:references/startup-commands.md:60:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"python -m uvicorn <module>:<callable> --host 0.0.0.0 --port 8000\"","category":"network","line_end":60,"severity":"medium","line_start":60},{"id":"network:references/startup-commands.md:69:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"gunicorn --bind=0.0.0.0 --timeout 600 <project>.wsgi\"","category":"network","line_end":69,"severity":"medium","line_start":69},{"id":"network:references/startup-commands.md:73:hardcoded-ip-address","file":"references/startup-commands.md","pattern":"Hardcoded IP address","snippet":"--startup-file \"gunicorn --bind=0.0.0.0 --timeout 600 <project>.wsgi\"","category":"network","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:references/transient-retry.md:40:ruby-shell-backtick-execution","file":"references/transient-retry.md","pattern":"Ruby/shell backtick execution","snippet":"-ShowCommand \"az group show -n my-rg --only-show-errors\" `","category":"external_commands","line_end":42,"severity":"medium","line_start":40},{"id":"external_commands:references/transient-retry.md:37:powershell-invocation","file":"references/transient-retry.md","pattern":"PowerShell invocation","snippet":"- PowerShell (Windows): [`scripts/retry-az-create.ps1`](../scripts/retry-az-create.ps1)","category":"external_commands","line_end":37,"severity":"high","line_start":37},{"id":"external_commands:references/transient-retry.md:38:powershell-invocation","file":"references/transient-retry.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":38,"severity":"high","line_start":38},{"id":"filesystem:references/transient-retry.md:31:path-traversal-sequence","file":"references/transient-retry.md","pattern":"Path traversal sequence","snippet":"- Bash / zsh (Linux, macOS): [`scripts/retry-az-create.sh`](../scripts/retry-az-create.sh)","category":"filesystem","line_end":31,"severity":"high","line_start":31},{"id":"filesystem:references/transient-retry.md:37:path-traversal-sequence","file":"references/transient-retry.md","pattern":"Path traversal sequence","snippet":"- PowerShell (Windows): [`scripts/retry-az-create.ps1`](../scripts/retry-az-create.ps1)","category":"filesystem","line_end":37,"severity":"high","line_start":37},{"id":"external_commands:scripts/generate-app-name.ps1:5:ruby-shell-backtick-execution","file":"scripts/generate-app-name.ps1","pattern":"Ruby/shell backtick execution","snippet":"Produces a name suitable for `az webapp create -n <name>` that satisfies","category":"external_commands","line_end":5,"severity":"medium","line_start":5},{"id":"blocker:scripts/generate-app-name.ps1:3:system-reconnaissance","file":"scripts/generate-app-name.ps1","pattern":"System reconnaissance","snippet":"Generates a valid Azure App Service name from a folder name + 8 hex chars.","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"external_commands:scripts/generate-app-name.sh:4:ruby-shell-backtick-execution","file":"scripts/generate-app-name.sh","pattern":"Ruby/shell backtick execution","snippet":"# of randomness, suitable for `az webapp create -n <name>`.","category":"external_commands","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:scripts/generate-app-name.sh:23:shell-command-substitution","file":"scripts/generate-app-name.sh","pattern":"Shell command substitution","snippet":"INPUT=\"${1:-$(basename \"$PWD\")}\"","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:scripts/generate-app-name.sh:26:shell-command-substitution","file":"scripts/generate-app-name.sh","pattern":"Shell command substitution","snippet":"SLUG=$(echo \"$INPUT\" \\","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:scripts/generate-app-name.sh:37:shell-command-substitution","file":"scripts/generate-app-name.sh","pattern":"Shell command substitution","snippet":"SUFFIX=$(uuidgen | tr '[:upper:]' '[:lower:]' | cut -d- -f1 | cut -c1-8)","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:scripts/generate-app-name.sh:40:shell-command-substitution","file":"scripts/generate-app-name.sh","pattern":"Shell command substitution","snippet":"SUFFIX=$(head -c 4 /dev/urandom | od -An -tx1 | tr -d ' \\n' | cut -c1-8)","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:scripts/generate-app-name.sh:46:shell-command-substitution","file":"scripts/generate-app-name.sh","pattern":"Shell command substitution","snippet":"SLUG=$(echo \"$SLUG\" | cut -c1-$MAX_SLUG_LEN | sed -E 's/-$//')","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:scripts/generate-app-name.sh:58:shell-command-substitution","file":"scripts/generate-app-name.sh","pattern":"Shell command substitution","snippet":"NAME=$(echo \"$NAME\" | cut -c1-40 | sed -E 's/-$//')","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"filesystem:scripts/generate-app-name.sh:36:standard-device-file-access","file":"scripts/generate-app-name.sh","pattern":"Standard device file access","snippet":"if command -v uuidgen >/dev/null 2>&1; then","category":"filesystem","line_end":36,"severity":"low","line_start":36},{"id":"filesystem:scripts/generate-app-name.sh:39:standard-device-file-access","file":"scripts/generate-app-name.sh","pattern":"Standard device file access","snippet":"# Fallback: /dev/urandom + xxd / od.","category":"filesystem","line_end":39,"severity":"low","line_start":39},{"id":"filesystem:scripts/generate-app-name.sh:40:standard-device-file-access","file":"scripts/generate-app-name.sh","pattern":"Standard device file access","snippet":"SUFFIX=$(head -c 4 /dev/urandom | od -An -tx1 | tr -d ' \\n' | cut -c1-8)","category":"filesystem","line_end":40,"severity":"low","line_start":40},{"id":"blocker:scripts/generate-app-name.sh:3:system-reconnaissance","file":"scripts/generate-app-name.sh","pattern":"System reconnaissance","snippet":"# Generates a valid Azure App Service name from a folder name + 8 hex chars","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"external_commands:scripts/retry-az-create.ps1:3:ruby-shell-backtick-execution","file":"scripts/retry-az-create.ps1","pattern":"Ruby/shell backtick execution","snippet":"Wraps an idempotent `az ... show || az ... create` pair with silent","category":"external_commands","line_end":3,"severity":"medium","line_start":3},{"id":"external_commands:scripts/retry-az-create.ps1:13:ruby-shell-backtick-execution","file":"scripts/retry-az-create.ps1","pattern":"Ruby/shell backtick execution","snippet":"The full `az ... show ...` command line as a single string.","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:scripts/retry-az-create.ps1:15:ruby-shell-backtick-execution","file":"scripts/retry-az-create.ps1","pattern":"Ruby/shell backtick execution","snippet":"The full `az ... create ...` command line as a single string.","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:scripts/retry-az-create.ps1:17:ruby-shell-backtick-execution","file":"scripts/retry-az-create.ps1","pattern":"Ruby/shell backtick execution","snippet":".\\retry-az-create.ps1 `","category":"external_commands","line_end":18,"severity":"medium","line_start":17},{"id":"external_commands:scripts/retry-az-create.ps1:21:ruby-shell-backtick-execution","file":"scripts/retry-az-create.ps1","pattern":"Ruby/shell backtick execution","snippet":".\\retry-az-create.ps1 `","category":"external_commands","line_end":22,"severity":"medium","line_start":21},{"id":"external_commands:scripts/retry-az-create.ps1:36:ruby-shell-backtick-execution","file":"scripts/retry-az-create.ps1","pattern":"Ruby/shell backtick execution","snippet":"# Try `show` silently first; if it fails, try `create`. Capture both","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:scripts/retry-az-create.ps1:39:ruby-shell-backtick-execution","file":"scripts/retry-az-create.ps1","pattern":"Ruby/shell backtick execution","snippet":"$script = \"$ShowCommand -o none 2>`$null; if (`$LASTEXITCODE -ne 0) { $CreateCommand -o none }\"","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:scripts/retry-az-create.ps1:40:powershell-invocation","file":"scripts/retry-az-create.ps1","pattern":"PowerShell invocation","snippet":"& powershell -NoProfile -Command $script 2>&1","category":"external_commands","line_end":40,"severity":"high","line_start":40},{"id":"external_commands:scripts/retry-az-create.sh:3:ruby-shell-backtick-execution","file":"scripts/retry-az-create.sh","pattern":"Ruby/shell backtick execution","snippet":"# Wraps the idempotent `(az ... show ...) || (az ... create ...)` pair with","category":"external_commands","line_end":3,"severity":"medium","line_start":3},{"id":"external_commands:scripts/retry-az-create.sh:11:ruby-shell-backtick-execution","file":"scripts/retry-az-create.sh","pattern":"Ruby/shell backtick execution","snippet":"#   - runs `show` first (short-circuits any partially-succeeded prior attempt","category":"external_commands","line_end":11,"severity":"medium","line_start":11},{"id":"external_commands:scripts/retry-az-create.sh:13:ruby-shell-backtick-execution","file":"scripts/retry-az-create.sh","pattern":"Ruby/shell backtick execution","snippet":"#   - if `show` fails, runs `create`;","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:scripts/retry-az-create.sh:36:shell-command-substitution","file":"scripts/retry-az-create.sh","pattern":"Shell command substitution","snippet":"if err=$({ eval \"$SHOW_CMD -o none 2>/dev/null\" || eval \"$CREATE_CMD -o none\"; } 2>&1); then","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:scripts/retry-az-create.sh:51:shell-command-substitution","file":"scripts/retry-az-create.sh","pattern":"Shell command substitution","snippet":"sleep \"$([ \"$attempt\" -eq 1 ] && echo 5 || echo 15)\"","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"filesystem:scripts/retry-az-create.sh:36:standard-device-file-access","file":"scripts/retry-az-create.sh","pattern":"Standard device file access","snippet":"if err=$({ eval \"$SHOW_CMD -o none 2>/dev/null\" || eval \"$CREATE_CMD -o none\"; } 2>&1); then","category":"filesystem","line_end":36,"severity":"low","line_start":36},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Deploys Python (Flask, Django, FastAPI, generic) code to Azure App Service Linux (P0v3, Python 3.14)","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**MCP tools used**: `mcp_azure_mcp_subscription_list`, `mcp_azure_mcp_group_list`, `mcp_azure_mcp_ap","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Resolve context — smart defaults, minimal prompts.** Only the app name is interactive; RG (`<ap","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Choose path** — `azure.yaml` host: appservice → [deploy-azd.md](references/deploy-azd.md); else","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Ensure RG → Plan (`P0v3 --is-linux`) → Web App (`--runtime \"PYTHON:3.14\"`)** exist. On transien","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Set startup** — Flask/Django: none (Oryx auto-detects). FastAPI: always `python -m uvicorn main","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Set `SCM_DO_BUILD_DURING_DEPLOYMENT=true`**.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. **Deploy** — `azd deploy` or `az webapp deploy --type zip --track-status false`.","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- ⛔ **NO POST-DEPLOY VERIFICATION** — after deploy returns, do not run `az webapp log tail`, `curl`,","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- ⛔ **SHELL SAFETY** — for `--runtime` always use `\"PYTHON:3.14\"` (colon). Never `\"PYTHON|3.14\"` (pi","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- ⛔ **NEVER `az webapp up`** — deprecated. Use Step 7 commands.","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- ✅ **URL FORMAT** — present endpoints as `https://...` URLs.","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See [errors.md](references/errors.md) for the full symptom → cause → fix matrix. Quick triage: missi","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"network:SKILL.md:32:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- ✅ **URL FORMAT** — present endpoints as `https://...` URLs.","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:SKILL.md:22:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"5. **Set startup** — Flask/Django: none (Oryx auto-detects). FastAPI: always `python -m uvicorn main","category":"network","line_end":22,"severity":"medium","line_start":22}],"finding_verdicts":[{"id":"external_commands:references/create-app.md:38:shell-command-substitution","reason":"The substitution is a visible Azure CLI example for deriving deployment values. It does not run silently or exfiltrate data.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:references/create-app.md:5:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/create-app.md:24:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/create-app.md:40:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/create-app.md:74:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/create-app.md:87:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/create-app.md:96:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/create-app.md:102:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:references/create-app.md:23:path-traversal-sequence","reason":"The ../ sequence appears in Markdown links to local helper scripts. It is documentation, not runtime path traversal or file access.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:references/create-app.md:24:path-traversal-sequence","reason":"The ../ sequence appears in Markdown links to local helper scripts. It is documentation, not runtime path traversal or file access.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:references/create-app.md:5:standard-device-file-access","reason":"The device reference is stderr suppression or command existence checking in visible Azure CLI examples. It is not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/create-app.md:38:standard-device-file-access","reason":"The device reference is stderr suppression or command existence checking in visible Azure CLI examples. It is not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/create-app.md:71:standard-device-file-access","reason":"The device reference is stderr suppression or command existence checking in visible Azure CLI examples. It is not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/create-app.md:84:standard-device-file-access","reason":"The device reference is stderr suppression or command existence checking in visible Azure CLI examples. It is not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/create-app.md:99:standard-device-file-access","reason":"The device reference is stderr suppression or command existence checking in visible Azure CLI examples. It is not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/create-app.md:13:system-reconnaissance","reason":"Reading the active Azure subscription id is expected deployment context resolution. The file shows no transmission of that value outside Azure tooling.","verdict":"false_positive","confidence":0.93},{"id":"blocker:references/create-app.md:28:system-reconnaissance","reason":"The flagged line is deployment naming or troubleshooting guidance. It does not perform covert system reconnaissance or collect host details.","verdict":"false_positive","confidence":0.9},{"id":"blocker:references/create-app.md:109:system-reconnaissance","reason":"The flagged line is deployment naming or troubleshooting guidance. It does not perform covert system reconnaissance or collect host details.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:references/deploy-azcli.md:22:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/deploy-azcli.md:76:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/deploy-azcli.md:78:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/deploy-azcli.md:95:shell-command-substitution","reason":"The substitution is a visible Azure CLI example for deriving deployment values. It does not run silently or exfiltrate data.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:references/deploy-azcli.md:20:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azcli.md:38:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azcli.md:58:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azcli.md:59:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azcli.md:74:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azcli.md:98:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"network:references/deploy-azcli.md:96:hardcoded-url","reason":"The URL is a placeholder or derived Azure App Service endpoint shown to the user. It does not send data to a third-party service.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deploy-azcli.md:100:hardcoded-url","reason":"The URL is a placeholder or derived Azure App Service endpoint shown to the user. It does not send data to a third-party service.","verdict":"false_positive","confidence":0.94},{"id":"network:references/deploy-azcli.md:36:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/deploy-azcli.md:40:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:references/deploy-azcli.md:55:environment-file-access","reason":"The .env reference is an exclusion pattern for the deployment archive. It reduces secret exposure by keeping environment files out of app.zip.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/deploy-azd.md:16:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/deploy-azd.md:20:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/deploy-azd.md:19:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azd.md:31:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azd.md:72:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/deploy-azd.md:73:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"network:references/detect.md:68:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:references/errors.md:7:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/errors.md:8:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/errors.md:9:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/errors.md:10:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/errors.md:41:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"blocker:references/errors.md:27:system-reconnaissance","reason":"The flagged line is deployment naming or troubleshooting guidance. It does not perform covert system reconnaissance or collect host details.","verdict":"false_positive","confidence":0.9},{"id":"blocker:references/errors.md:54:system-reconnaissance","reason":"The flagged line is deployment naming or troubleshooting guidance. It does not perform covert system reconnaissance or collect host details.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:references/post-deploy-message.md:71:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"network:references/post-deploy-message.md:19:hardcoded-url","reason":"The URL is a placeholder or derived Azure App Service endpoint shown to the user. It does not send data to a third-party service.","verdict":"false_positive","confidence":0.94},{"id":"network:references/post-deploy-message.md:36:hardcoded-url","reason":"The URL is a placeholder or derived Azure App Service endpoint shown to the user. It does not send data to a third-party service.","verdict":"false_positive","confidence":0.94},{"id":"network:references/post-deploy-message.md:49:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/post-deploy-message.md:51:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"blocker:references/post-deploy-message.md:81:system-reconnaissance","reason":"The flagged line is deployment naming or troubleshooting guidance. It does not perform covert system reconnaissance or collect host details.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:references/startup-commands.md:26:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/startup-commands.md:47:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/startup-commands.md:58:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/startup-commands.md:71:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"network:references/startup-commands.md:24:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/startup-commands.md:28:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/startup-commands.md:45:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/startup-commands.md:49:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/startup-commands.md:56:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/startup-commands.md:60:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/startup-commands.md:69:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"network:references/startup-commands.md:73:hardcoded-ip-address","reason":"The address 0.0.0.0 is a local bind address required for App Service container routing. It is not a remote endpoint or tracking destination.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:references/transient-retry.md:40:ruby-shell-backtick-execution","reason":"The backticks are Markdown code formatting or PowerShell line-continuation examples. They do not execute commands by themselves.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:references/transient-retry.md:37:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:references/transient-retry.md:38:powershell-invocation","reason":"This is a visible PowerShell example or shell note in documentation for Azure deployment. It is not hidden execution or an attempt to bypass review.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:references/transient-retry.md:31:path-traversal-sequence","reason":"The ../ sequence appears in Markdown links to local helper scripts. It is documentation, not runtime path traversal or file access.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:references/transient-retry.md:37:path-traversal-sequence","reason":"The ../ sequence appears in Markdown links to local helper scripts. It is documentation, not runtime path traversal or file access.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:scripts/generate-app-name.ps1:5:ruby-shell-backtick-execution","reason":"The flagged text is a PowerShell comment, example, or escape sequence, not Ruby backtick execution. The real dynamic execution risk is captured separately where the script is assembled and run.","verdict":"false_positive","confidence":0.88},{"id":"blocker:scripts/generate-app-name.ps1:3:system-reconnaissance","reason":"The flagged line is deployment naming or troubleshooting guidance. It does not perform covert system reconnaissance or collect host details.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:scripts/generate-app-name.sh:4:ruby-shell-backtick-execution","reason":"The flagged text is a shell comment or quoted documentation text. It does not execute as Ruby or shell backtick syntax.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:scripts/generate-app-name.sh:23:shell-command-substitution","reason":"The command substitution is quoted and used to normalize a local app name or generate a suffix. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:scripts/generate-app-name.sh:26:shell-command-substitution","reason":"The command substitution is quoted and used to normalize a local app name or generate a suffix. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:scripts/generate-app-name.sh:37:shell-command-substitution","reason":"The command substitution is quoted and used to normalize a local app name or generate a suffix. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:scripts/generate-app-name.sh:40:shell-command-substitution","reason":"The command substitution is quoted and used to normalize a local app name or generate a suffix. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:scripts/generate-app-name.sh:46:shell-command-substitution","reason":"The command substitution is quoted and used to normalize a local app name or generate a suffix. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:scripts/generate-app-name.sh:58:shell-command-substitution","reason":"The command substitution is quoted and used to normalize a local app name or generate a suffix. It does not execute user-provided command text.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:scripts/generate-app-name.sh:36:standard-device-file-access","reason":"The device reference is stderr suppression or command existence checking in visible Azure CLI examples. It is not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:scripts/generate-app-name.sh:39:standard-device-file-access","reason":"The /dev/urandom access generates a short random suffix for an Azure app name. It does not read user files or secrets.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:scripts/generate-app-name.sh:40:standard-device-file-access","reason":"The /dev/urandom access generates a short random suffix for an Azure app name. It does not read user files or secrets.","verdict":"false_positive","confidence":0.96},{"id":"blocker:scripts/generate-app-name.sh:3:system-reconnaissance","reason":"The flagged line is deployment naming or troubleshooting guidance. It does not perform covert system reconnaissance or collect host details.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:scripts/retry-az-create.ps1:3:ruby-shell-backtick-execution","reason":"The flagged text is a PowerShell comment, example, or escape sequence, not Ruby backtick execution. The real dynamic execution risk is captured separately where the script is assembled and run.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/retry-az-create.ps1:13:ruby-shell-backtick-execution","reason":"The flagged text is a PowerShell comment, example, or escape sequence, not Ruby backtick execution. The real dynamic execution risk is captured separately where the script is assembled and run.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/retry-az-create.ps1:15:ruby-shell-backtick-execution","reason":"The flagged text is a PowerShell comment, example, or escape sequence, not Ruby backtick execution. The real dynamic execution risk is captured separately where the script is assembled and run.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/retry-az-create.ps1:17:ruby-shell-backtick-execution","reason":"The flagged text is a PowerShell comment, example, or escape sequence, not Ruby backtick execution. The real dynamic execution risk is captured separately where the script is assembled and run.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/retry-az-create.ps1:21:ruby-shell-backtick-execution","reason":"The flagged text is a PowerShell comment, example, or escape sequence, not Ruby backtick execution. The real dynamic execution risk is captured separately where the script is assembled and run.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/retry-az-create.ps1:36:ruby-shell-backtick-execution","reason":"The flagged text is a PowerShell comment, example, or escape sequence, not Ruby backtick execution. The real dynamic execution risk is captured separately where the script is assembled and run.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:scripts/retry-az-create.ps1:39:ruby-shell-backtick-execution","reason":"This line builds a PowerShell command string from caller-provided ShowCommand and CreateCommand values. The string is executed on the next line, creating command-injection exposure if interpolated values are unsafe.","verdict":"confirmed","severity":"high","confidence":0.86},{"id":"external_commands:scripts/retry-az-create.ps1:40:powershell-invocation","reason":"This invokes powershell -Command on a dynamically assembled script string. That is a real command-execution risk when the input command strings include unescaped user-controlled Azure names.","verdict":"confirmed","severity":"high","confidence":0.93},{"id":"external_commands:scripts/retry-az-create.sh:3:ruby-shell-backtick-execution","reason":"The flagged text is a shell comment or quoted documentation text. It does not execute as Ruby or shell backtick syntax.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:scripts/retry-az-create.sh:11:ruby-shell-backtick-execution","reason":"The flagged text is a shell comment or quoted documentation text. It does not execute as Ruby or shell backtick syntax.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:scripts/retry-az-create.sh:13:ruby-shell-backtick-execution","reason":"The flagged text is a shell comment or quoted documentation text. It does not execute as Ruby or shell backtick syntax.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:scripts/retry-az-create.sh:36:shell-command-substitution","reason":"This line executes caller-provided command strings with eval after appending arguments. If resource values are not shell escaped before reaching the wrapper, shell metacharacters can become commands.","verdict":"confirmed","severity":"high","confidence":0.92},{"id":"external_commands:scripts/retry-az-create.sh:51:shell-command-substitution","reason":"The substitution is used for local control flow, such as choosing a sleep duration. It does not introduce command execution from user input.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:scripts/retry-az-create.sh:36:standard-device-file-access","reason":"The device reference is stderr suppression or command existence checking in visible Azure CLI examples. It is not sensitive file access.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code delimiters describing commands and files. They are not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:32:hardcoded-url","reason":"The URL is a placeholder or derived Azure App Service endpoint shown to the user. It does not send data to a third-party service.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:22:hardcoded-ip-address","reason":"No malicious behavior was found for this static pattern in context. The text appears to be visible deployment guidance for Azure App Service.","verdict":"false_positive","confidence":0.8}],"semantic_findings":[{"title":"Unsanitized Command Strings in Retry Wrappers","severity":"high","locations":[{"file":"references/create-app.md","line_end":9,"line_start":9},{"file":"scripts/retry-az-create.sh","line_end":36,"line_start":29},{"file":"scripts/retry-az-create.ps1","line_end":40,"line_start":25}],"confidence":0.9,"description":"The workflow permits user-supplied Azure values, while retry wrappers execute whole command strings through eval or PowerShell -Command. Unsafe interpolation could allow shell metacharacters to run as commands.","confidence_reasoning":"The scripts accept full command strings and execute them dynamically. The deployment guide says to use user-requested resource values verbatim, so injection depends on caller escaping."},{"title":"Billable Azure Resources Created Without Explicit Confirmation","severity":"medium","locations":[{"file":"references/create-app.md","line_end":63,"line_start":46},{"file":"references/create-app.md","line_end":105,"line_start":79},{"file":"SKILL.md","line_end":24,"line_start":18}],"confidence":0.86,"description":"The guide derives resource names, prints defaults, and tells the agent not to ask for confirmation before creating a P0v3 App Service plan and web app. This can spend money or change cloud state after a single deployment request.","confidence_reasoning":"The cited lines explicitly skip confirmation and create or reuse paid Azure resources. This is intentional deployment behavior, but it is a marketplace safety risk."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}