{"data":{"skill":{"slug":"samber-golang-cli","name":"golang-cli","icon":"📦","repo":"https://github.com/samber/cc-skills-golang/tree/22c58a55a0a799b901aa251172923180bad9e010/skills/golang-cli","status":"approved","author":"samber","authorVersion":"1.3.0","skillstoreRevision":1},"audit":{"id":"0924da81-b945-414e-abc0-b6aa4a5aadae","skill_id":"1736c069-9a6b-4530-ae85-124387d344a8","version":1,"content_hash":"v3:e5464e662405de6361fdde6b984f9ea865635f64:da9eef3871a94cccbcbab77c2b3a5990e7fe00d9434f3728cb427e520ae77311:85ac42f967d537c2e3d46120c5fda4f9978a40167765ce93283a4ee613c046d2:736b696c6c732f73616d6265722f676f6c616e672d636c69:4f86c449c6fde4f53f36959a29c87849","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 94 static findings are false positives caused by Go syntax, Markdown formatting, Cobra identifiers, completion documentation, and benign build examples. No malicious behavior, prompt injection, data exfiltration, unsafe command execution, or covert system access was found.","remediation":[],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"assets/examples/args.go","line_end":7,"line_start":3},{"file":"assets/examples/cli_test.go","line_end":8,"line_start":3},{"file":"assets/examples/completion.go","line_end":7,"line_start":3},{"file":"assets/examples/config.go","line_end":11,"line_start":3},{"file":"assets/examples/exit_codes.go","line_end":8,"line_start":3},{"file":"assets/examples/flags.go","line_end":6,"line_start":3},{"file":"assets/examples/main.go","line_end":6,"line_start":4},{"file":"assets/examples/output.go","line_end":11,"line_start":3},{"file":"assets/examples/root.go","line_end":12,"line_start":4},{"file":"assets/examples/serve.go","line_end":9,"line_start":4},{"file":"assets/examples/signal.go","line_end":14,"line_start":3},{"file":"assets/examples/version.go","line_end":9,"line_start":4}]},{"factor":"external_commands","evidence":[{"file":"assets/examples/completion.go","line_end":10,"line_start":10},{"file":"assets/examples/completion.go","line_end":14,"line_start":14},{"file":"assets/examples/completion.go","line_end":17,"line_start":17},{"file":"assets/examples/completion.go","line_end":26,"line_start":26},{"file":"assets/examples/completion.go","line_end":27,"line_start":27},{"file":"assets/examples/config.go","line_end":45,"line_start":45},{"file":"assets/examples/config.go","line_end":46,"line_start":46},{"file":"assets/examples/config.go","line_end":47,"line_start":47},{"file":"assets/examples/config.go","line_end":49,"line_start":49},{"file":"assets/examples/config.go","line_end":50,"line_start":50},{"file":"assets/examples/config.go","line_end":51,"line_start":51},{"file":"assets/examples/exit_codes.go","line_end":12,"line_start":12},{"file":"assets/examples/root.go","line_end":28,"line_start":28},{"file":"assets/examples/version.go","line_end":37,"line_start":37},{"file":"assets/examples/version.go","line_end":38,"line_start":38},{"file":"evals/evals.json","line_end":93,"line_start":93},{"file":"evals/evals.json","line_end":322,"line_start":322},{"file":"evals/evals.json","line_end":326,"line_start":326},{"file":"evals/evals.json","line_end":11,"line_start":11},{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":66,"line_start":55},{"file":"SKILL.md","line_end":68,"line_start":66},{"file":"SKILL.md","line_end":72,"line_start":68},{"file":"SKILL.md","line_end":76,"line_start":72},{"file":"SKILL.md","line_end":77,"line_start":76},{"file":"SKILL.md","line_end":78,"line_start":77},{"file":"SKILL.md","line_end":83,"line_start":78},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":92,"line_start":91},{"file":"SKILL.md","line_end":96,"line_start":92},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":113,"line_start":112},{"file":"SKILL.md","line_end":114,"line_start":113},{"file":"SKILL.md","line_end":115,"line_start":114},{"file":"SKILL.md","line_end":116,"line_start":115},{"file":"SKILL.md","line_end":117,"line_start":116},{"file":"SKILL.md","line_end":132,"line_start":117},{"file":"SKILL.md","line_end":139,"line_start":132}]},{"factor":"filesystem","evidence":[{"file":"assets/examples/root.go","line_end":32,"line_start":32},{"file":"evals/evals.json","line_end":35,"line_start":35},{"file":"evals/evals.json","line_end":35,"line_start":35},{"file":"evals/evals.json","line_end":135,"line_start":135}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":12,"line_start":12}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":14,"total_lines":1129,"audit_model":"codex","audited_at":"2026-09-06T11:56:38.516+00:00","created_at":"2026-09-08T15:04:12.206724+00:00","static_findings":[{"id":"scripts:assets/examples/args.go:3:dynamic-import-expression","file":"assets/examples/args.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":7,"severity":"medium","line_start":3},{"id":"blocker:assets/examples/args.go:31:system-reconnaissance","file":"assets/examples/args.go","pattern":"System reconnaissance","snippet":"valid := map[string]bool{\"dev\": true, \"staging\": true, \"prod\": true}","category":"blocker","line_end":31,"severity":"low","line_start":31},{"id":"blocker:assets/examples/args.go:33:system-reconnaissance","file":"assets/examples/args.go","pattern":"System reconnaissance","snippet":"return fmt.Errorf(\"invalid environment %q, must be one of: dev, staging, prod\", args[0])","category":"blocker","line_end":33,"severity":"low","line_start":33},{"id":"scripts:assets/examples/cli_test.go:3:dynamic-import-expression","file":"assets/examples/cli_test.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":8,"severity":"medium","line_start":3},{"id":"scripts:assets/examples/completion.go:3:dynamic-import-expression","file":"assets/examples/completion.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":7,"severity":"medium","line_start":3},{"id":"external_commands:assets/examples/completion.go:10:powershell-invocation","file":"assets/examples/completion.go","pattern":"PowerShell invocation","snippet":"// Cobra generates completions for bash, zsh, fish, and PowerShell automatically.","category":"external_commands","line_end":10,"severity":"high","line_start":10},{"id":"external_commands:assets/examples/completion.go:14:powershell-invocation","file":"assets/examples/completion.go","pattern":"PowerShell invocation","snippet":"Use:       \"completion [bash|zsh|fish|powershell]\",","category":"external_commands","line_end":14,"severity":"high","line_start":14},{"id":"external_commands:assets/examples/completion.go:17:powershell-invocation","file":"assets/examples/completion.go","pattern":"PowerShell invocation","snippet":"ValidArgs: []string{\"bash\", \"zsh\", \"fish\", \"powershell\"},","category":"external_commands","line_end":17,"severity":"high","line_start":17},{"id":"external_commands:assets/examples/completion.go:26:powershell-invocation","file":"assets/examples/completion.go","pattern":"PowerShell invocation","snippet":"case \"powershell\":","category":"external_commands","line_end":26,"severity":"high","line_start":26},{"id":"external_commands:assets/examples/completion.go:27:powershell-invocation","file":"assets/examples/completion.go","pattern":"PowerShell invocation","snippet":"return rootCmd.GenPowerShellCompletionWithDesc(os.Stdout)","category":"external_commands","line_end":27,"severity":"high","line_start":27},{"id":"scripts:assets/examples/config.go:3:dynamic-import-expression","file":"assets/examples/config.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":11,"severity":"medium","line_start":3},{"id":"external_commands:assets/examples/config.go:45:ruby-shell-backtick-execution","file":"assets/examples/config.go","pattern":"Ruby/shell backtick execution","snippet":"Port     int    `mapstructure:\"port\"`","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:assets/examples/config.go:46:ruby-shell-backtick-execution","file":"assets/examples/config.go","pattern":"Ruby/shell backtick execution","snippet":"Host     string `mapstructure:\"host\"`","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:assets/examples/config.go:47:ruby-shell-backtick-execution","file":"assets/examples/config.go","pattern":"Ruby/shell backtick execution","snippet":"LogLevel string `mapstructure:\"log-level\"`","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:assets/examples/config.go:49:ruby-shell-backtick-execution","file":"assets/examples/config.go","pattern":"Ruby/shell backtick execution","snippet":"DSN     string `mapstructure:\"dsn\"`","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:assets/examples/config.go:50:ruby-shell-backtick-execution","file":"assets/examples/config.go","pattern":"Ruby/shell backtick execution","snippet":"MaxConn int    `mapstructure:\"max-conn\"`","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:assets/examples/config.go:51:ruby-shell-backtick-execution","file":"assets/examples/config.go","pattern":"Ruby/shell backtick execution","snippet":"} `mapstructure:\"database\"`","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"scripts:assets/examples/exit_codes.go:3:dynamic-import-expression","file":"assets/examples/exit_codes.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":8,"severity":"medium","line_start":3},{"id":"external_commands:assets/examples/exit_codes.go:12:windows-cmd-exe","file":"assets/examples/exit_codes.go","pattern":"Windows cmd.exe","snippet":"if err := cmd.Execute(); err != nil {","category":"external_commands","line_end":12,"severity":"high","line_start":12},{"id":"scripts:assets/examples/flags.go:3:dynamic-import-expression","file":"assets/examples/flags.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":6,"severity":"medium","line_start":3},{"id":"blocker:assets/examples/flags.go:19:system-reconnaissance","file":"assets/examples/flags.go","pattern":"System reconnaissance","snippet":"serveCmd.Flags().String(\"host\", \"\", \"hostname to bind to\")","category":"blocker","line_end":19,"severity":"low","line_start":19},{"id":"scripts:assets/examples/main.go:4:dynamic-import-expression","file":"assets/examples/main.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":6,"severity":"medium","line_start":4},{"id":"scripts:assets/examples/output.go:3:dynamic-import-expression","file":"assets/examples/output.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":11,"severity":"medium","line_start":3},{"id":"scripts:assets/examples/root.go:4:dynamic-import-expression","file":"assets/examples/root.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":12,"severity":"medium","line_start":4},{"id":"external_commands:assets/examples/root.go:28:windows-cmd-exe","file":"assets/examples/root.go","pattern":"Windows cmd.exe","snippet":"return rootCmd.Execute()","category":"external_commands","line_end":28,"severity":"high","line_start":28},{"id":"filesystem:assets/examples/root.go:32:hidden-file-access","file":"assets/examples/root.go","pattern":"Hidden file access","snippet":"rootCmd.PersistentFlags().StringVar(&cfgFile, \"config\", \"\", \"config file (default $HOME/.myapp.yaml)","category":"filesystem","line_end":32,"severity":"medium","line_start":32},{"id":"scripts:assets/examples/serve.go:4:dynamic-import-expression","file":"assets/examples/serve.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":9,"severity":"medium","line_start":4},{"id":"scripts:assets/examples/signal.go:3:dynamic-import-expression","file":"assets/examples/signal.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":14,"severity":"medium","line_start":3},{"id":"scripts:assets/examples/version.go:4:dynamic-import-expression","file":"assets/examples/version.go","pattern":"Dynamic import() expression","snippet":"import (","category":"scripts","line_end":9,"severity":"medium","line_start":4},{"id":"external_commands:assets/examples/version.go:37:shell-command-substitution","file":"assets/examples/version.go","pattern":"Shell command substitution","snippet":"//     -X github.com/you/myapp/cmd/myapp.commit=$(git rev-parse --short HEAD) \\","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:assets/examples/version.go:38:shell-command-substitution","file":"assets/examples/version.go","pattern":"Shell command substitution","snippet":"//     -X github.com/you/myapp/cmd/myapp.date=$(date -u +%Y-%m-%dT%H:%M:%SZ)\" \\","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:evals/evals.json:93:ruby-shell-backtick-execution","file":"evals/evals.json","pattern":"Ruby/shell backtick execution","snippet":"\"prompt\": \"Write a Go CLI command 'list-users' using Cobra that fetches users from a database and pr","category":"external_commands","line_end":93,"severity":"medium","line_start":93},{"id":"external_commands:evals/evals.json:322:powershell-invocation","file":"evals/evals.json","pattern":"PowerShell invocation","snippet":"\"text\": \"Creates a 'completion' subcommand that supports bash, zsh, fish, and powershell as argument","category":"external_commands","line_end":322,"severity":"high","line_start":322},{"id":"external_commands:evals/evals.json:326:powershell-invocation","file":"evals/evals.json","pattern":"PowerShell invocation","snippet":"\"text\": \"Uses Cobra's built-in completion generators (GenBashCompletionV2, GenZshCompletion, GenFish","category":"external_commands","line_end":326,"severity":"high","line_start":326},{"id":"external_commands:evals/evals.json:11:windows-cmd-exe","file":"evals/evals.json","pattern":"Windows cmd.exe","snippet":"\"text\": \"main.go only calls Execute() (or rootCmd.Execute()) and os.Exit on error — no configuration","category":"external_commands","line_end":11,"severity":"high","line_start":11},{"id":"filesystem:evals/evals.json:35:hidden-file-in-home-directory","file":"evals/evals.json","pattern":"Hidden file in home directory","snippet":"\"prompt\": \"I'm building a Go CLI server tool with Cobra. It needs a --port flag (default 3000) that ","category":"filesystem","line_end":35,"severity":"high","line_start":35},{"id":"filesystem:evals/evals.json:35:hidden-file-access","file":"evals/evals.json","pattern":"Hidden file access","snippet":"\"prompt\": \"I'm building a Go CLI server tool with Cobra. It needs a --port flag (default 3000) that ","category":"filesystem","line_end":35,"severity":"medium","line_start":35},{"id":"filesystem:evals/evals.json:135:hard-link-creation","file":"evals/evals.json","pattern":"Hard link creation","snippet":"\"text\": \"The version command uses cmd.OutOrStdout() for output, not fmt.Println or os.Stdout directl","category":"filesystem","line_end":135,"severity":"medium","line_start":135},{"id":"blocker:evals/evals.json:44:system-reconnaissance","file":"evals/evals.json","pattern":"System reconnaissance","snippet":"\"text\": \"Sets an env prefix with viper.SetEnvPrefix('MYSERVER' or similar) to namespace env vars and","category":"blocker","line_end":44,"severity":"low","line_start":44},{"id":"blocker:evals/evals.json:151:system-reconnaissance","file":"evals/evals.json","pattern":"System reconnaissance","snippet":"\"prompt\": \"My Go CLI tool needs to report different exit codes for different failure types: invalid ","category":"blocker","line_end":151,"severity":"low","line_start":151},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"description: \"Golang CLI application development. Use when building, modifying, or reviewing a Go CL","category":"external_commands","line_end":3,"severity":"medium","line_start":3},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Review** — auditing an existing CLI for correctness: check the Common Mistakes table, verify `Si","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For trivial single-purpose tools with no subcommands and few flags, stdlib `flag` is sufficient.","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Commands & flags    | `github.com/spf13/cobra`             |","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Configuration       | `github.com/spf13/viper`             |","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Flag parsing        | `github.com/spf13/pflag` (via Cobra) |","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Colored output      | `github.com/fatih/color`             |","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Table output        | `github.com/olekukonko/tablewriter`  |","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Interactive prompts | `github.com/charmbracelet/bubbletea` |","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Version injection   | `go build -ldflags`                  |","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Distribution        | `goreleaser`                         |","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Organize CLI commands in `cmd/myapp/` with one file per command. Keep `main.go` minimal — it only ca","category":"external_commands","line_end":53,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":66,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":68,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`main.go` should be minimal — see [assets/examples/main.go](assets/examples/main.go).","category":"external_commands","line_end":72,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The root command initializes Viper configuration and sets up global behavior via `PersistentPreRunE`","category":"external_commands","line_end":76,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `SilenceUsage: true` MUST be set — prevents printing the full usage text on every error","category":"external_commands","line_end":77,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `SilenceErrors: true` MUST be set — lets you control error output format yourself","category":"external_commands","line_end":78,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `PersistentPreRunE` runs before every subcommand, so config is always initialized","category":"external_commands","line_end":83,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Add subcommands by creating separate files in `cmd/myapp/` and registering them in `init()`. See [as","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Persistent** flags are inherited by all subcommands (e.g., `--config`)","category":"external_commands","line_end":92,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Local** flags only apply to the command they're defined on (e.g., `--port`)","category":"external_commands","line_end":96,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `MarkFlagRequired`, `MarkFlagsMutuallyExclusive`, and `MarkFlagsOneRequired` for flag constraint","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"This ensures `viper.GetInt(\"port\")` returns the flag value, env var `MYAPP_PORT`, or config file val","category":"external_commands","line_end":104,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cobra.NoArgs`              | Fails if any args provided           |","category":"external_commands","line_end":113,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cobra.ExactArgs(n)`        | Requires exactly n args              |","category":"external_commands","line_end":114,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cobra.MinimumNArgs(n)`     | Requires at least n args             |","category":"external_commands","line_end":115,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cobra.MaximumNArgs(n)`     | Allows at most n args                |","category":"external_commands","line_end":116,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cobra.RangeArgs(min, max)` | Requires between min and max         |","category":"external_commands","line_end":117,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cobra.ExactValidArgs(n)`   | Exactly n args, must be in ValidArgs |","category":"external_commands","line_end":132,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":139,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":143,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Flag: `--port 9090`","category":"external_commands","line_end":144,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Env var: `MYAPP_PORT=9090`","category":"external_commands","line_end":145,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Config file: `port: 9090`","category":"external_commands","line_end":149,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Version SHOULD be embedded at compile time using `ldflags`. See [assets/examples/version.go](assets/","category":"external_commands","line_end":172,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Detecting pipe vs terminal**: check `os.ModeCharDevice` on stdout","category":"external_commands","line_end":173,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Machine-readable output**: support `--output` flag for table/json/plain formats","category":"external_commands","line_end":174,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Colors**: use `fatih/color` which auto-disables when output is not a terminal","category":"external_commands","line_end":178,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Signal handling MUST use `signal.NotifyContext` to propagate cancellation through context. See [asse","category":"external_commands","line_end":188,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `cmd.OutOrStdout()` and `cmd.ErrOrStderr()` in commands (instead of `os.Stdout` / `os.Stderr`) s","category":"external_commands","line_end":188,"severity":"medium","line_start":188},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Writing to `os.Stdout` directly | Tests can't capture output. Use `cmd.OutOrStdout()` which tests ","category":"external_commands","line_end":194,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Calling `os.Exit()` inside `RunE` | Cobra's error handling, deferred functions, and cleanup code n","category":"external_commands","line_end":195,"severity":"medium","line_start":195},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Not binding flags to Viper | Flags won't be configurable via env/config. Call `viper.BindPFlag` fo","category":"external_commands","line_end":197,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Missing `viper.SetEnvPrefix` | `PORT` collides with other tools. Use a prefix (`MYAPP_PORT`) to na","category":"external_commands","line_end":197,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Printing usage on every error | Full help text on every error is noise. Set `SilenceUsage: true`, ","category":"external_commands","line_end":199,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Config file required | Users without a config file get a crash. Ignore `viper.ConfigFileNotFoundEr","category":"external_commands","line_end":201,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Not using `PersistentPreRunE` | Config initialization must happen before any subcommand. Use root'","category":"external_commands","line_end":201,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Hardcoded version string | Version gets out of sync with tags. Inject via `ldflags` at build time ","category":"external_commands","line_end":203,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Not supporting `--output` format | Scripts can't parse human-readable output. Add JSON/table/plain","category":"external_commands","line_end":207,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See `samber/cc-skills-golang@golang-project-layout`, `samber/cc-skills-golang@golang-dependency-inje","category":"external_commands","line_end":207,"severity":"medium","line_start":207},{"id":"external_commands:SKILL.md:182:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"Cobra generates completions for bash, zsh, fish, and PowerShell automatically. See [assets/examples/","category":"external_commands","line_end":182,"severity":"high","line_start":182},{"id":"network:SKILL.md:12:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: https://github.com/samber/cc-skills-golang","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"blocker:SKILL.md:159:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| 2     | Usage error       | Invalid flags or arguments                |","category":"blocker","line_end":159,"severity":"low","line_start":159}],"finding_verdicts":[{"id":"scripts:assets/examples/args.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/examples/args.go:31:system-reconnaissance","reason":"The matched text describes argument validation, host flags, environment prefixes, or exit-code behavior. It does not inspect the host system or collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/examples/args.go:33:system-reconnaissance","reason":"The matched text describes argument validation, host flags, environment prefixes, or exit-code behavior. It does not inspect the host system or collect system information.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/cli_test.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/completion.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/completion.go:10:powershell-invocation","reason":"This example names PowerShell as a supported completion format and calls Cobra's completion generator. It generates text to stdout and does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/completion.go:14:powershell-invocation","reason":"This example names PowerShell as a supported completion format and calls Cobra's completion generator. It generates text to stdout and does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/completion.go:17:powershell-invocation","reason":"This example names PowerShell as a supported completion format and calls Cobra's completion generator. It generates text to stdout and does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/completion.go:26:powershell-invocation","reason":"This example names PowerShell as a supported completion format and calls Cobra's completion generator. It generates text to stdout and does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/completion.go:27:powershell-invocation","reason":"This example names PowerShell as a supported completion format and calls Cobra's completion generator. It generates text to stdout and does not invoke PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/config.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/config.go:45:ruby-shell-backtick-execution","reason":"The backticks delimit Go struct tags used by Viper's mapstructure decoder. They are compile-time metadata, not Ruby or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/config.go:46:ruby-shell-backtick-execution","reason":"The backticks delimit Go struct tags used by Viper's mapstructure decoder. They are compile-time metadata, not Ruby or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/config.go:47:ruby-shell-backtick-execution","reason":"The backticks delimit Go struct tags used by Viper's mapstructure decoder. They are compile-time metadata, not Ruby or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/config.go:49:ruby-shell-backtick-execution","reason":"The backticks delimit Go struct tags used by Viper's mapstructure decoder. They are compile-time metadata, not Ruby or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/config.go:50:ruby-shell-backtick-execution","reason":"The backticks delimit Go struct tags used by Viper's mapstructure decoder. They are compile-time metadata, not Ruby or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/config.go:51:ruby-shell-backtick-execution","reason":"The backticks delimit Go struct tags used by Viper's mapstructure decoder. They are compile-time metadata, not Ruby or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/exit_codes.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/exit_codes.go:12:windows-cmd-exe","reason":"The identifier cmd is a Go Cobra command object whose Execute method runs the configured command tree. There is no reference to Windows cmd.exe or process spawning.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/flags.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/examples/flags.go:19:system-reconnaissance","reason":"The matched text describes argument validation, host flags, environment prefixes, or exit-code behavior. It does not inspect the host system or collect system information.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/main.go:4:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/output.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/root.go:4:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/root.go:28:windows-cmd-exe","reason":"The identifier cmd is a Go Cobra command object whose Execute method runs the configured command tree. There is no reference to Windows cmd.exe or process spawning.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:assets/examples/root.go:32:hidden-file-access","reason":"The match is a conventional, user-selected YAML configuration path in the home directory. It does not target credentials, enumerate hidden files, or transmit file contents.","verdict":"false_positive","confidence":0.98},{"id":"scripts:assets/examples/serve.go:4:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/signal.go:3:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"scripts:assets/examples/version.go:4:dynamic-import-expression","reason":"The matched text is a standard Go import block with fixed package names. Go import syntax is not a dynamic import expression and does not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/examples/version.go:37:shell-command-substitution","reason":"The substitution appears only in a commented build example that derives version metadata from git and date. It is transparent developer documentation, not automatic execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:assets/examples/version.go:38:shell-command-substitution","reason":"The substitution appears only in a commented build example that derives version metadata from git and date. It is transparent developer documentation, not automatic execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:evals/evals.json:93:ruby-shell-backtick-execution","reason":"The backticks quote an example pipeline inside a natural-language evaluation prompt. The JSON contains test data and does not execute the command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:evals/evals.json:322:powershell-invocation","reason":"This is evaluation text describing Cobra's PowerShell completion support. It contains no process launch, command interpreter call, or executable script.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:evals/evals.json:326:powershell-invocation","reason":"This is evaluation text describing Cobra's PowerShell completion support. It contains no process launch, command interpreter call, or executable script.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:evals/evals.json:11:windows-cmd-exe","reason":"The identifier cmd is a Go Cobra command object whose Execute method runs the configured command tree. There is no reference to Windows cmd.exe or process spawning.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:evals/evals.json:35:hidden-file-in-home-directory","reason":"The match is a conventional, user-selected YAML configuration path in the home directory. It does not target credentials, enumerate hidden files, or transmit file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:evals/evals.json:35:hidden-file-access","reason":"The match is a conventional, user-selected YAML configuration path in the home directory. It does not target credentials, enumerate hidden files, or transmit file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:evals/evals.json:135:hard-link-creation","reason":"The matched text names Cobra's OutOrStdout method in an evaluation assertion. It does not call a filesystem linking API or create a hard link.","verdict":"false_positive","confidence":0.99},{"id":"blocker:evals/evals.json:44:system-reconnaissance","reason":"The matched text describes argument validation, host flags, environment prefixes, or exit-code behavior. It does not inspect the host system or collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:evals/evals.json:151:system-reconnaissance","reason":"The matched text describes argument validation, host flags, environment prefixes, or exit-code behavior. It does not inspect the host system or collect system information.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code formatting or fenced examples in Go CLI documentation. Markdown delimiters do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:182:powershell-invocation","reason":"This documentation sentence lists PowerShell as a Cobra completion target. It neither invokes PowerShell nor instructs an agent to execute generated output.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:12:hardcoded-url","reason":"The URL is repository homepage metadata. No code fetches the URL, sends data to it, or otherwise performs a network request.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:159:system-reconnaissance","reason":"The matched text describes argument validation, host flags, environment prefixes, or exit-code behavior. It does not inspect the host system or collect system information.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"e5464e662405de6361fdde6b984f9ea865635f64","subject_content_hash":"da9eef3871a94cccbcbab77c2b3a5990e7fe00d9434f3728cb427e520ae77311","subject_tree_hash":"85ac42f967d537c2e3d46120c5fda4f9978a40167765ce93283a4ee613c046d2","subject_plugin_path":"skills/samber/golang-cli","audit_payload_hash":"4f86c449c6fde4f53f36959a29c87849","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"e5464e662405de6361fdde6b984f9ea865635f64","contentHash":"da9eef3871a94cccbcbab77c2b3a5990e7fe00d9434f3728cb427e520ae77311","treeHash":"85ac42f967d537c2e3d46120c5fda4f9978a40167765ce93283a4ee613c046d2","pluginPath":"skills/samber/golang-cli","auditPayloadHash":"4f86c449c6fde4f53f36959a29c87849"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/samber-golang-cli/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}