{"data":{"skill":{"slug":"sickn33-environment-setup-guide","name":"environment-setup-guide","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/environment-setup-guide","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"dcb84e3a-458b-4067-9505-502ce8bd179e","skill_id":"b3f3487c-e80e-42d9-a114-5077a48bcd0d","version":4,"content_hash":"v2:959f09e93b0f69d817dd53d39b51bbc2c1dbed76:17390b45014a4882366310f6e070395bbfda39f23e4ef895bf0ff0741eb2fb43:1f10032a707fc51135a23d4499a2e1c6c66a7f9e63ddc69f0b275efc0881d8b5:997d8bd7a1369ce6f85fc2a9e1dc54dd","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"No prompt injection or covert data exfiltration was found in the Markdown skill. Most static hits are formatting or documentation false positives. Real risks remain in remote installers, sudo commands, Docker group membership, shell profile edits, and weak example credentials.","remediation":[{"issue":"Remote installer scripts are downloaded and executed.","severity":"high","suggestion":"Prefer official package manager steps, require source verification, and add checksum or signature checks before any shell execution."},{"issue":"Several setup steps require sudo or privileged account changes.","severity":"high","suggestion":"Add explicit confirmation gates and explain the security impact before sudo commands or Docker group membership changes."},{"issue":"The guide appends PATH changes to ~/.bashrc.","severity":"medium","suggestion":"Show the exact shell profile diff first and tell users to back up or edit the file manually when possible."},{"issue":"Example database credentials use weak placeholder values.","severity":"medium","suggestion":"Use clearly non-secret placeholders and warn users to generate unique local passwords outside of source control."},{"issue":"Environment file guidance could lead users to expose secrets.","severity":"medium","suggestion":"State that real .env values, API keys, npm tokens, and git credentials must not be pasted into AI chats or committed."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":44,"line_start":38},{"file":"SKILL.md","line_end":73,"line_start":44},{"file":"SKILL.md","line_end":84,"line_start":73},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":114,"line_start":114},{"file":"SKILL.md","line_end":118,"line_start":118},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":125,"line_start":125},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":137,"line_start":136},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":143,"line_start":143},{"file":"SKILL.md","line_end":146,"line_start":145},{"file":"SKILL.md","line_end":146,"line_start":146},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":155,"line_start":155},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":174,"line_start":174},{"file":"SKILL.md","line_end":179,"line_start":175},{"file":"SKILL.md","line_end":185,"line_start":179},{"file":"SKILL.md","line_end":185,"line_start":185},{"file":"SKILL.md","line_end":187,"line_start":187},{"file":"SKILL.md","line_end":190,"line_start":190},{"file":"SKILL.md","line_end":193,"line_start":193},{"file":"SKILL.md","line_end":196,"line_start":196},{"file":"SKILL.md","line_end":198,"line_start":198},{"file":"SKILL.md","line_end":202,"line_start":202},{"file":"SKILL.md","line_end":205,"line_start":205},{"file":"SKILL.md","line_end":209,"line_start":209},{"file":"SKILL.md","line_end":222,"line_start":222},{"file":"SKILL.md","line_end":226,"line_start":226},{"file":"SKILL.md","line_end":232,"line_start":232},{"file":"SKILL.md","line_end":237,"line_start":236},{"file":"SKILL.md","line_end":237,"line_start":237},{"file":"SKILL.md","line_end":242,"line_start":242},{"file":"SKILL.md","line_end":246,"line_start":246},{"file":"SKILL.md","line_end":251,"line_start":251},{"file":"SKILL.md","line_end":256,"line_start":252},{"file":"SKILL.md","line_end":262,"line_start":256},{"file":"SKILL.md","line_end":262,"line_start":262},{"file":"SKILL.md","line_end":265,"line_start":265},{"file":"SKILL.md","line_end":268,"line_start":268},{"file":"SKILL.md","line_end":276,"line_start":276},{"file":"SKILL.md","line_end":283,"line_start":283},{"file":"SKILL.md","line_end":286,"line_start":286},{"file":"SKILL.md","line_end":290,"line_start":290},{"file":"SKILL.md","line_end":320,"line_start":320},{"file":"SKILL.md","line_end":324,"line_start":324},{"file":"SKILL.md","line_end":333,"line_start":333},{"file":"SKILL.md","line_end":337,"line_start":337},{"file":"SKILL.md","line_end":343,"line_start":343},{"file":"SKILL.md","line_end":380,"line_start":344},{"file":"SKILL.md","line_end":386,"line_start":380},{"file":"SKILL.md","line_end":394,"line_start":386},{"file":"SKILL.md","line_end":399,"line_start":394},{"file":"SKILL.md","line_end":406,"line_start":399},{"file":"SKILL.md","line_end":415,"line_start":406},{"file":"SKILL.md","line_end":423,"line_start":415},{"file":"SKILL.md","line_end":429,"line_start":423},{"file":"SKILL.md","line_end":433,"line_start":429},{"file":"SKILL.md","line_end":435,"line_start":433},{"file":"SKILL.md","line_end":466,"line_start":435},{"file":"SKILL.md","line_end":470,"line_start":466},{"file":"SKILL.md","line_end":471,"line_start":470},{"file":"SKILL.md","line_end":472,"line_start":471},{"file":"SKILL.md","line_end":473,"line_start":472},{"file":"SKILL.md","line_end":487,"line_start":473},{"file":"SKILL.md","line_end":487,"line_start":487},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":94,"line_start":84},{"file":"SKILL.md","line_end":108,"line_start":97},{"file":"SKILL.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":196,"line_start":196},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":436,"line_start":436},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":106,"line_start":105},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":168,"line_start":168},{"file":"SKILL.md","line_end":191,"line_start":191},{"file":"SKILL.md","line_end":192,"line_start":192},{"file":"SKILL.md","line_end":271,"line_start":271},{"file":"SKILL.md","line_end":274,"line_start":274},{"file":"SKILL.md","line_end":392,"line_start":391},{"file":"SKILL.md","line_end":425,"line_start":425}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":250,"line_start":250},{"file":"SKILL.md","line_end":270,"line_start":270},{"file":"SKILL.md","line_end":477,"line_start":477},{"file":"SKILL.md","line_end":478,"line_start":478},{"file":"SKILL.md","line_end":479,"line_start":479},{"file":"SKILL.md","line_end":480,"line_start":480},{"file":"SKILL.md","line_end":481,"line_start":481},{"file":"SKILL.md","line_end":482,"line_start":482},{"file":"SKILL.md","line_end":483,"line_start":483},{"file":"SKILL.md","line_end":250,"line_start":250}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":171,"line_start":171},{"file":"SKILL.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":173,"line_start":173},{"file":"SKILL.md","line_end":396,"line_start":396},{"file":"SKILL.md","line_end":397,"line_start":397},{"file":"SKILL.md","line_end":398,"line_start":398},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":171,"line_start":171},{"file":"SKILL.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":173,"line_start":173},{"file":"SKILL.md","line_end":396,"line_start":396},{"file":"SKILL.md","line_end":397,"line_start":397},{"file":"SKILL.md","line_end":398,"line_start":398},{"file":"SKILL.md","line_end":441,"line_start":441},{"file":"SKILL.md","line_end":442,"line_start":442},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":102,"line_start":102}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":231,"line_start":231},{"file":"SKILL.md","line_end":149,"line_start":149},{"file":"SKILL.md","line_end":240,"line_start":240},{"file":"SKILL.md","line_end":300,"line_start":300},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":241,"line_start":241}]}],"critical_findings":[],"high_findings":[{"title":"Unix shell invocation","locations":[{"file":"SKILL.md","line_end":90,"line_start":90}],"confidence":0.78,"description":"/bin/bash \"$tmpdir/homebrew-install.sh\"","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This instruction executes a downloaded Homebrew installer with /bin/bash after displaying it for review. Running remote installer scripts can modify the host environment if the source is compromised or not verified."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":99,"line_start":99}],"confidence":0.72,"description":"sudo apt update","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This is a user-facing sudo package manager command that modifies system package state. It is expected for setup, but still requires explicit user approval and trusted package sources."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":106,"line_start":106}],"confidence":0.88,"description":"sudo -E bash \"$tmpdir/nodesource-setup.sh\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This runs a downloaded NodeSource setup script with sudo privileges. Combining remote script content with elevated execution is a real host modification risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":107,"line_start":107}],"confidence":0.72,"description":"sudo apt install -y nodejs","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This sudo apt install command changes system packages. It is legitimate setup guidance but still uses elevated privileges and should require user confirmation."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":191,"line_start":191}],"confidence":0.72,"description":"sudo apt update","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This sudo apt update command modifies package manager state. It is normal setup guidance, but elevated commands should be reviewed before execution."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":192,"line_start":192}],"confidence":0.72,"description":"sudo apt install python3.11 python3.11-venv python3-pip","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This sudo apt install command installs Python packages at the system level. It is legitimate setup guidance, but it changes the host and needs user approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":271,"line_start":271}],"confidence":0.9,"description":"sudo sh get-docker.sh","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This runs get-docker.sh with sudo after downloading it from the network. Remote installer execution with root privileges is a high-risk setup pattern."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":274,"line_start":274}],"confidence":0.82,"description":"sudo usermod -aG docker $USER","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This adds the current user to the docker group with sudo. Docker group membership can grant broad host control and should be treated as a privileged change."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":170,"line_start":170}],"confidence":0.74,"description":"mkdir ~/.npm-global","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The guide creates a hidden directory in the user home directory as part of npm permission repair. This is legitimate setup guidance but changes persistent user configuration."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":171,"line_start":171}],"confidence":0.76,"description":"npm config set prefix '~/.npm-global'","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The npm prefix command writes persistent npm configuration under the user profile. Hidden configuration changes should be shown and approved before use."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":172,"line_start":172}],"confidence":0.84,"description":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"This appends a PATH export to ~/.bashrc, changing future shell startup behavior. Modifying shell startup files is persistent and security-sensitive."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":173,"line_start":173}],"confidence":0.7,"description":"source ~/.bashrc","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"This sources ~/.bashrc after modifying it. Loading shell startup files can execute user configuration and should be done only after reviewing the change."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":396,"line_start":396}],"confidence":0.74,"description":"mkdir ~/.npm-global","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The troubleshooting guidance creates a hidden npm directory in the home profile. It is benign in intent but still changes persistent user configuration."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":397,"line_start":397}],"confidence":0.76,"description":"npm config set prefix '~/.npm-global'","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The npm prefix command changes persistent npm configuration. This should be confirmed because it affects future package installs."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":398,"line_start":398}],"confidence":0.84,"description":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"This appends a PATH export to ~/.bashrc. Persistent shell startup file modification can affect future sessions and should be reviewed first."},{"title":"Database connection strings","locations":[{"file":"SKILL.md","line_end":300,"line_start":300}],"confidence":0.78,"description":"- DATABASE_URL=postgresql://postgres:password@db:5432/mydb","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The Docker compose example embeds a database URL with a password-like value. Even as an example, hardcoded credentials can normalize unsafe configuration practices."},{"title":"Remote Installer Execution Without Integrity Verification","locations":[{"file":"SKILL.md","line_end":90,"line_start":88},{"file":"SKILL.md","line_end":106,"line_start":104},{"file":"SKILL.md","line_end":271,"line_start":270}],"confidence":0.9,"description":"The guide downloads installer scripts and then runs them with bash or sudo, but it does not require checksum or signature verification before execution.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The linked lines show direct download followed by shell execution, including sudo for NodeSource and Docker. The guide asks for review in some cases but does not require cryptographic verification."},{"title":"Root-Equivalent Docker Group Enrollment","locations":[{"file":"SKILL.md","line_end":274,"line_start":274}],"confidence":0.84,"description":"The Docker setup adds the current user to the docker group without explaining that this can grant broad control over the host.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The exact command adds $USER to the docker group with sudo. Docker group access is widely treated as equivalent to elevated host control on many systems."}],"medium_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":88,"line_start":88}],"confidence":0.82,"description":"curl -fsSLo \"$tmpdir/homebrew-install.sh\" https://raw.githubusercontent.com/Homebrew/install/HEAD/in","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The URL downloads the Homebrew installer script that the guide later executes. This is a real supply-chain risk if the source is not verified."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":104,"line_start":104}],"confidence":0.84,"description":"curl -fsSLo \"$tmpdir/nodesource-setup.sh\" https://deb.nodesource.com/setup_20.x","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The URL downloads a NodeSource setup script that the guide later runs with sudo. Hardcoded remote installer downloads should include integrity or source verification."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":270,"line_start":270}],"confidence":0.88,"description":"curl -fsSL https://get.docker.com -o get-docker.sh","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The URL downloads get-docker.sh immediately before a sudo shell execution. This creates a concrete remote installer execution risk."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":170,"line_start":170}],"confidence":0.74,"description":"mkdir ~/.npm-global","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The guide creates ~/.npm-global, a hidden path in the user profile. This is legitimate setup work but still modifies persistent user configuration."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":171,"line_start":171}],"confidence":0.76,"description":"npm config set prefix '~/.npm-global'","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The command changes npm configuration to use a hidden home directory path. This is an intentional but persistent configuration change."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":172,"line_start":172}],"confidence":0.84,"description":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The command appends to ~/.bashrc, a shell startup file. Startup file edits can affect later shell behavior and need review."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":173,"line_start":173}],"confidence":0.7,"description":"source ~/.bashrc","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The command sources ~/.bashrc after the PATH change. This is expected troubleshooting, but it executes shell startup configuration in the current session."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":396,"line_start":396}],"confidence":0.74,"description":"mkdir ~/.npm-global","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The troubleshooting snippet creates ~/.npm-global under the user profile. It is a persistent hidden-path configuration change."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":397,"line_start":397}],"confidence":0.76,"description":"npm config set prefix '~/.npm-global'","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The npm prefix command writes persistent npm configuration. This is legitimate but should be disclosed before use."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":398,"line_start":398}],"confidence":0.84,"description":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The command appends PATH configuration to ~/.bashrc. Persistent shell configuration edits are security-sensitive user-environment changes."},{"title":"Weak Example Database Credentials","locations":[{"file":"SKILL.md","line_end":311,"line_start":300}],"confidence":0.86,"description":"The Docker compose example uses a password-like value in the database URL and sets POSTGRES_PASSWORD to a weak literal example.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The example contains a database URL with password@db and POSTGRES_PASSWORD=password. It is likely a local example, but it can normalize unsafe defaults if copied."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":493,"audit_model":"codex","audited_at":"2026-07-08T13:25:53.303+00:00","created_at":"2026-07-08T14:40:13.059734+00:00","static_findings":[{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":44,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":73,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":84,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":94,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":111,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":114,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":118,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":125,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create a \\`.env\\` file:","category":"external_commands","line_end":137,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":143,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Example \\`.env\\` content:","category":"external_commands","line_end":146,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":146,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":151,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Solution:** Restart your terminal or run \\`source ~/.bashrc\\` (Linux) or \\`source ~/.zshrc\\` (macO","category":"external_commands","line_end":165,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":179,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":185,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":185,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":187,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":190,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":193,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":196,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":198,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":202,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":205,"severity":"medium","line_start":205},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":209,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":222,"severity":"medium","line_start":222},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":226,"severity":"medium","line_start":226},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":232,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create \\`.env\\` file:","category":"external_commands","line_end":237,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":242,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":246,"severity":"medium","line_start":246},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":251,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":256,"severity":"medium","line_start":252},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":262,"severity":"medium","line_start":256},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":262,"severity":"medium","line_start":262},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":265,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":268,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":276,"severity":"medium","line_start":276},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":283,"severity":"medium","line_start":283},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":286,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`yaml","category":"external_commands","line_end":290,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":320,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":324,"severity":"medium","line_start":324},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":333,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":337,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":343,"severity":"medium","line_start":343},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":380,"severity":"medium","line_start":344},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":386,"severity":"medium","line_start":380},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":394,"severity":"medium","line_start":386},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":399,"severity":"medium","line_start":394},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":406,"severity":"medium","line_start":399},{"id":"external_commands:SKILL.md:406:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":415,"severity":"medium","line_start":406},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":423,"severity":"medium","line_start":415},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":429,"severity":"medium","line_start":423},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":433,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create a `setup.sh` script to automate setup:","category":"external_commands","line_end":435,"severity":"medium","line_start":433},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":466,"severity":"medium","line_start":435},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":470,"severity":"medium","line_start":466},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@brainstorming` - Plan environment requirements before setup","category":"external_commands","line_end":471,"severity":"medium","line_start":470},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@systematic-debugging` - Debug environment issues","category":"external_commands","line_end":472,"severity":"medium","line_start":471},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@doc-coauthoring` - Create setup documentation","category":"external_commands","line_end":473,"severity":"medium","line_start":472},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@git-pushing` - Set up Git configuration","category":"external_commands","line_end":487,"severity":"medium","line_start":473},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Pro Tip:** Create a `setup.sh` or `setup.ps1` script to automate the entire setup process. Test it","category":"external_commands","line_end":487,"severity":"medium","line_start":487},{"id":"external_commands:SKILL.md:86:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"tmpdir=\"$(mktemp -d)\"","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:102:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"tmpdir=\"$(mktemp -d)\"","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:84:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":94,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:97:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":108,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:111:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":111,"severity":"high","line_start":111},{"id":"external_commands:SKILL.md:196:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":196,"severity":"high","line_start":196},{"id":"external_commands:SKILL.md:90:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"/bin/bash \"$tmpdir/homebrew-install.sh\"","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:436:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":436,"severity":"medium","line_start":436},{"id":"external_commands:SKILL.md:99:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt update","category":"external_commands","line_end":99,"severity":"high","line_start":99},{"id":"external_commands:SKILL.md:105:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"cat \"$tmpdir/nodesource-setup.sh\"  # review the full installer before sudo","category":"external_commands","line_end":106,"severity":"high","line_start":105},{"id":"external_commands:SKILL.md:106:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo -E bash \"$tmpdir/nodesource-setup.sh\"","category":"external_commands","line_end":106,"severity":"high","line_start":106},{"id":"external_commands:SKILL.md:107:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install -y nodejs","category":"external_commands","line_end":107,"severity":"high","line_start":107},{"id":"external_commands:SKILL.md:168:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"**Solution:** Don't use sudo with npm. Fix permissions:","category":"external_commands","line_end":168,"severity":"high","line_start":168},{"id":"external_commands:SKILL.md:191:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt update","category":"external_commands","line_end":191,"severity":"high","line_start":191},{"id":"external_commands:SKILL.md:192:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install python3.11 python3.11-venv python3-pip","category":"external_commands","line_end":192,"severity":"high","line_start":192},{"id":"external_commands:SKILL.md:271:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo sh get-docker.sh","category":"external_commands","line_end":271,"severity":"high","line_start":271},{"id":"external_commands:SKILL.md:274:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo usermod -aG docker $USER","category":"external_commands","line_end":274,"severity":"high","line_start":274},{"id":"external_commands:SKILL.md:391:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"- Don't use sudo","category":"external_commands","line_end":392,"severity":"high","line_start":391},{"id":"external_commands:SKILL.md:425:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl status postgresql","category":"external_commands","line_end":425,"severity":"high","line_start":425},{"id":"network:SKILL.md:88:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -fsSLo \"$tmpdir/homebrew-install.sh\" https://raw.githubusercontent.com/Homebrew/install/HEAD/in","category":"network","line_end":88,"severity":"low","line_start":88},{"id":"network:SKILL.md:104:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -fsSLo \"$tmpdir/nodesource-setup.sh\" https://deb.nodesource.com/setup_20.x","category":"network","line_end":104,"severity":"low","line_start":104},{"id":"network:SKILL.md:127:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"git clone https://github.com/your-repo/project.git","category":"network","line_end":127,"severity":"low","line_start":127},{"id":"network:SKILL.md:159:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# Should see: Server running on http://localhost:3000","category":"network","line_end":159,"severity":"low","line_start":159},{"id":"network:SKILL.md:250:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# Should see: Running on http://127.0.0.1:5000","category":"network","line_end":250,"severity":"low","line_start":250},{"id":"network:SKILL.md:270:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -fsSL https://get.docker.com -o get-docker.sh","category":"network","line_end":270,"severity":"low","line_start":270},{"id":"network:SKILL.md:477:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Node.js Installation Guide](https://nodejs.org/en/download/)","category":"network","line_end":477,"severity":"low","line_start":477},{"id":"network:SKILL.md:478:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Python Virtual Environments](https://docs.python.org/3/tutorial/venv.html)","category":"network","line_end":478,"severity":"low","line_start":478},{"id":"network:SKILL.md:479:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Docker Documentation](https://docs.docker.com/get-started/)","category":"network","line_end":479,"severity":"low","line_start":479},{"id":"network:SKILL.md:480:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Homebrew (macOS)](https://brew.sh/)","category":"network","line_end":480,"severity":"low","line_start":480},{"id":"network:SKILL.md:481:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Chocolatey (Windows)](https://chocolatey.org/)","category":"network","line_end":481,"severity":"low","line_start":481},{"id":"network:SKILL.md:482:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [nvm (Node Version Manager)](https://github.com/nvm-sh/nvm)","category":"network","line_end":482,"severity":"low","line_start":482},{"id":"network:SKILL.md:483:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [pyenv (Python Version Manager)](https://github.com/pyenv/pyenv)","category":"network","line_end":483,"severity":"low","line_start":483},{"id":"network:SKILL.md:250:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"# Should see: Running on http://127.0.0.1:5000","category":"network","line_end":250,"severity":"medium","line_start":250},{"id":"filesystem:SKILL.md:165:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"**Solution:** Restart your terminal or run \\`source ~/.bashrc\\` (Linux) or \\`source ~/.zshrc\\` (macO","category":"filesystem","line_end":165,"severity":"high","line_start":165},{"id":"filesystem:SKILL.md:170:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":170,"severity":"high","line_start":170},{"id":"filesystem:SKILL.md:171:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":171,"severity":"high","line_start":171},{"id":"filesystem:SKILL.md:172:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":172,"severity":"high","line_start":172},{"id":"filesystem:SKILL.md:173:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"source ~/.bashrc","category":"filesystem","line_end":173,"severity":"high","line_start":173},{"id":"filesystem:SKILL.md:396:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":396,"severity":"high","line_start":396},{"id":"filesystem:SKILL.md:397:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":397,"severity":"high","line_start":397},{"id":"filesystem:SKILL.md:398:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":398,"severity":"high","line_start":398},{"id":"filesystem:SKILL.md:165:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"**Solution:** Restart your terminal or run \\`source ~/.bashrc\\` (Linux) or \\`source ~/.zshrc\\` (macO","category":"filesystem","line_end":165,"severity":"medium","line_start":165},{"id":"filesystem:SKILL.md:170:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":170,"severity":"medium","line_start":170},{"id":"filesystem:SKILL.md:171:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":171,"severity":"medium","line_start":171},{"id":"filesystem:SKILL.md:172:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":172,"severity":"medium","line_start":172},{"id":"filesystem:SKILL.md:173:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"source ~/.bashrc","category":"filesystem","line_end":173,"severity":"medium","line_start":173},{"id":"filesystem:SKILL.md:396:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":396,"severity":"medium","line_start":396},{"id":"filesystem:SKILL.md:397:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":397,"severity":"medium","line_start":397},{"id":"filesystem:SKILL.md:398:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":398,"severity":"medium","line_start":398},{"id":"filesystem:SKILL.md:441:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"command -v node >/dev/null 2>&1 || { echo \"❌ Node.js not installed\"; exit 1; }","category":"filesystem","line_end":441,"severity":"low","line_start":441},{"id":"filesystem:SKILL.md:442:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"command -v git >/dev/null 2>&1 || { echo \"❌ Git not installed\"; exit 1; }","category":"filesystem","line_end":442,"severity":"low","line_start":442},{"id":"filesystem:SKILL.md:86:temp-file-creation","file":"SKILL.md","pattern":"Temp file creation","snippet":"tmpdir=\"$(mktemp -d)\"","category":"filesystem","line_end":86,"severity":"low","line_start":86},{"id":"filesystem:SKILL.md:102:temp-file-creation","file":"SKILL.md","pattern":"Temp file creation","snippet":"tmpdir=\"$(mktemp -d)\"","category":"filesystem","line_end":102,"severity":"low","line_start":102},{"id":"env_access:SKILL.md:231:dotenv-library","file":"SKILL.md","pattern":"dotenv library","snippet":"pip install flask sqlalchemy python-dotenv","category":"env_access","line_end":231,"severity":"low","line_start":231},{"id":"env_access:SKILL.md:149:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"DATABASE_URL=postgresql://localhost:5432/mydb","category":"env_access","line_end":149,"severity":"high","line_start":149},{"id":"env_access:SKILL.md:240:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"DATABASE_URL=sqlite:///app.db","category":"env_access","line_end":240,"severity":"high","line_start":240},{"id":"env_access:SKILL.md:300:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"- DATABASE_URL=postgresql://postgres:password@db:5432/mydb","category":"env_access","line_end":300,"severity":"high","line_start":300},{"id":"env_access:SKILL.md:150:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"API_KEY=your-api-key-here","category":"env_access","line_end":150,"severity":"high","line_start":150},{"id":"env_access:SKILL.md:241:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"SECRET_KEY=your-secret-key-here","category":"env_access","line_end":241,"severity":"high","line_start":241},{"id":"sensitive:SKILL.md:56:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"- Environment variables (.env files)","category":"sensitive","line_end":56,"severity":"high","line_start":56},{"id":"sensitive:SKILL.md:136:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"Create a \\`.env\\` file:","category":"sensitive","line_end":136,"severity":"high","line_start":136},{"id":"sensitive:SKILL.md:139:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"cp .env.example .env","category":"sensitive","line_end":139,"severity":"high","line_start":139},{"id":"sensitive:SKILL.md:142:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"nano .env","category":"sensitive","line_end":142,"severity":"high","line_start":142},{"id":"sensitive:SKILL.md:145:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"Example \\`.env\\` content:","category":"sensitive","line_end":145,"severity":"high","line_start":145},{"id":"sensitive:SKILL.md:236:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"Create \\`.env\\` file:","category":"sensitive","line_end":236,"severity":"high","line_start":236},{"id":"sensitive:SKILL.md:352:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"- **Create .env.example** - Show required environment variables","category":"sensitive","line_end":352,"severity":"high","line_start":352},{"id":"sensitive:SKILL.md:451:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"if [ ! -f .env ]; then","category":"sensitive","line_end":451,"severity":"high","line_start":451},{"id":"sensitive:SKILL.md:452:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"echo \"📝 Creating .env file...\"","category":"sensitive","line_end":452,"severity":"high","line_start":452},{"id":"sensitive:SKILL.md:453:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"cp .env.example .env","category":"sensitive","line_end":453,"severity":"high","line_start":453},{"id":"sensitive:SKILL.md:454:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"echo \"⚠️  Please edit .env with your configuration\"","category":"sensitive","line_end":454,"severity":"high","line_start":454},{"id":"sensitive:SKILL.md:57:npm-config-file-may-contain-tokens","file":"SKILL.md","pattern":"NPM config file (may contain tokens)","snippet":"- Configuration files (.gitconfig, .npmrc, etc.)","category":"sensitive","line_end":57,"severity":"high","line_start":57},{"id":"sensitive:SKILL.md:57:git-config-file","file":"SKILL.md","pattern":"Git config file","snippet":"- Configuration files (.gitconfig, .npmrc, etc.)","category":"sensitive","line_end":57,"severity":"medium","line_start":57},{"id":"sensitive:SKILL.md:240:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"DATABASE_URL=sqlite:///app.db","category":"sensitive","line_end":240,"severity":"medium","line_start":240},{"id":"blocker:SKILL.md:78:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Terminal/Command Prompt access","category":"blocker","line_end":79,"severity":"low","line_start":78}],"finding_verdicts":[{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:406:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","reason":"The match is Markdown fencing or inline Markdown formatting, not Ruby backtick command execution. The skill file is documentation and does not execute this text.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:86:shell-command-substitution","reason":"The command substitution is used in a documented bash snippet to create a temporary directory with mktemp. It is not hidden execution by the skill package.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:SKILL.md:102:shell-command-substitution","reason":"The command substitution is used in a documented bash snippet to create a temporary directory with mktemp. It is not hidden execution by the skill package.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:SKILL.md:84:template-literal-with-command-substitution","reason":"The match is an escaped Markdown code fence label inside an example block. It is not template code that evaluates command substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:97:template-literal-with-command-substitution","reason":"The match is an escaped Markdown code fence label inside an example block. It is not template code that evaluates command substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:111:powershell-invocation","reason":"The match is a Markdown powershell code fence for Windows setup instructions. The skill does not invoke PowerShell on its own.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:196:powershell-invocation","reason":"The match is a Markdown powershell code fence for Windows setup instructions. The skill does not invoke PowerShell on its own.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:90:unix-shell-invocation","reason":"This instruction executes a downloaded Homebrew installer with /bin/bash after displaying it for review. Running remote installer scripts can modify the host environment if the source is compromised or not verified.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"external_commands:SKILL.md:436:unix-shell-invocation","reason":"The match is a shebang in a setup script template. The skill does not execute the script or hide command execution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:99:sudo-privilege-escalation","reason":"This is a user-facing sudo package manager command that modifies system package state. It is expected for setup, but still requires explicit user approval and trusted package sources.","verdict":"confirmed","severity":"high","confidence":0.72},{"id":"external_commands:SKILL.md:105:sudo-privilege-escalation","reason":"The line tells users to review the downloaded installer before sudo. It contains the word sudo but does not execute an elevated command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:106:sudo-privilege-escalation","reason":"This runs a downloaded NodeSource setup script with sudo privileges. Combining remote script content with elevated execution is a real host modification risk.","verdict":"confirmed","severity":"high","confidence":0.88},{"id":"external_commands:SKILL.md:107:sudo-privilege-escalation","reason":"This sudo apt install command changes system packages. It is legitimate setup guidance but still uses elevated privileges and should require user confirmation.","verdict":"confirmed","severity":"high","confidence":0.72},{"id":"external_commands:SKILL.md:168:sudo-privilege-escalation","reason":"The line explicitly advises not to use sudo in this context. This is a safety recommendation, not privilege escalation.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:191:sudo-privilege-escalation","reason":"This sudo apt update command modifies package manager state. It is normal setup guidance, but elevated commands should be reviewed before execution.","verdict":"confirmed","severity":"high","confidence":0.72},{"id":"external_commands:SKILL.md:192:sudo-privilege-escalation","reason":"This sudo apt install command installs Python packages at the system level. It is legitimate setup guidance, but it changes the host and needs user approval.","verdict":"confirmed","severity":"high","confidence":0.72},{"id":"external_commands:SKILL.md:271:sudo-privilege-escalation","reason":"This runs get-docker.sh with sudo after downloading it from the network. Remote installer execution with root privileges is a high-risk setup pattern.","verdict":"confirmed","severity":"high","confidence":0.9},{"id":"external_commands:SKILL.md:274:sudo-privilege-escalation","reason":"This adds the current user to the docker group with sudo. Docker group membership can grant broad host control and should be treated as a privileged change.","verdict":"confirmed","severity":"high","confidence":0.82},{"id":"external_commands:SKILL.md:391:sudo-privilege-escalation","reason":"The line explicitly advises not to use sudo in this context. This is a safety recommendation, not privilege escalation.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:425:sudo-privilege-escalation","reason":"The command checks PostgreSQL service status for troubleshooting. It may prompt for privileges, but it is a visible diagnostic step rather than unsafe escalation.","verdict":"false_positive","confidence":0.82},{"id":"network:SKILL.md:88:hardcoded-url","reason":"The URL downloads the Homebrew installer script that the guide later executes. This is a real supply-chain risk if the source is not verified.","verdict":"confirmed","severity":"medium","confidence":0.82},{"id":"network:SKILL.md:104:hardcoded-url","reason":"The URL downloads a NodeSource setup script that the guide later runs with sudo. Hardcoded remote installer downloads should include integrity or source verification.","verdict":"confirmed","severity":"medium","confidence":0.84},{"id":"network:SKILL.md:127:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:159:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:250:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:270:hardcoded-url","reason":"The URL downloads get-docker.sh immediately before a sudo shell execution. This creates a concrete remote installer execution risk.","verdict":"confirmed","severity":"medium","confidence":0.88},{"id":"network:SKILL.md:477:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:478:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:479:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:480:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:481:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:482:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:483:hardcoded-url","reason":"The URL is a placeholder, localhost output, or documentation resource link. It is not used for hidden network access or data exfiltration.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:250:hardcoded-ip-address","reason":"The IP address is the loopback address shown in expected Flask output. It does not create external network access.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:165:hidden-file-in-home-directory","reason":"The match is a mention of shell configuration files in setup documentation. It is not a hidden file read or write by the skill package.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:170:hidden-file-in-home-directory","reason":"The guide creates a hidden directory in the user home directory as part of npm permission repair. This is legitimate setup guidance but changes persistent user configuration.","verdict":"confirmed","severity":"high","confidence":0.74},{"id":"filesystem:SKILL.md:171:hidden-file-in-home-directory","reason":"The npm prefix command writes persistent npm configuration under the user profile. Hidden configuration changes should be shown and approved before use.","verdict":"confirmed","severity":"high","confidence":0.76},{"id":"filesystem:SKILL.md:172:hidden-file-in-home-directory","reason":"This appends a PATH export to ~/.bashrc, changing future shell startup behavior. Modifying shell startup files is persistent and security-sensitive.","verdict":"confirmed","severity":"high","confidence":0.84},{"id":"filesystem:SKILL.md:173:hidden-file-in-home-directory","reason":"This sources ~/.bashrc after modifying it. Loading shell startup files can execute user configuration and should be done only after reviewing the change.","verdict":"confirmed","severity":"high","confidence":0.7},{"id":"filesystem:SKILL.md:396:hidden-file-in-home-directory","reason":"The troubleshooting guidance creates a hidden npm directory in the home profile. It is benign in intent but still changes persistent user configuration.","verdict":"confirmed","severity":"high","confidence":0.74},{"id":"filesystem:SKILL.md:397:hidden-file-in-home-directory","reason":"The npm prefix command changes persistent npm configuration. This should be confirmed because it affects future package installs.","verdict":"confirmed","severity":"high","confidence":0.76},{"id":"filesystem:SKILL.md:398:hidden-file-in-home-directory","reason":"This appends a PATH export to ~/.bashrc. Persistent shell startup file modification can affect future sessions and should be reviewed first.","verdict":"confirmed","severity":"high","confidence":0.84},{"id":"filesystem:SKILL.md:165:hidden-file-access","reason":"The match is a documented reference to shell configuration paths. It is not covert access by executable code.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:170:hidden-file-access","reason":"The guide creates ~/.npm-global, a hidden path in the user profile. This is legitimate setup work but still modifies persistent user configuration.","verdict":"confirmed","severity":"medium","confidence":0.74},{"id":"filesystem:SKILL.md:171:hidden-file-access","reason":"The command changes npm configuration to use a hidden home directory path. This is an intentional but persistent configuration change.","verdict":"confirmed","severity":"medium","confidence":0.76},{"id":"filesystem:SKILL.md:172:hidden-file-access","reason":"The command appends to ~/.bashrc, a shell startup file. Startup file edits can affect later shell behavior and need review.","verdict":"confirmed","severity":"medium","confidence":0.84},{"id":"filesystem:SKILL.md:173:hidden-file-access","reason":"The command sources ~/.bashrc after the PATH change. This is expected troubleshooting, but it executes shell startup configuration in the current session.","verdict":"confirmed","severity":"medium","confidence":0.7},{"id":"filesystem:SKILL.md:396:hidden-file-access","reason":"The troubleshooting snippet creates ~/.npm-global under the user profile. It is a persistent hidden-path configuration change.","verdict":"confirmed","severity":"medium","confidence":0.74},{"id":"filesystem:SKILL.md:397:hidden-file-access","reason":"The npm prefix command writes persistent npm configuration. This is legitimate but should be disclosed before use.","verdict":"confirmed","severity":"medium","confidence":0.76},{"id":"filesystem:SKILL.md:398:hidden-file-access","reason":"The command appends PATH configuration to ~/.bashrc. Persistent shell configuration edits are security-sensitive user-environment changes.","verdict":"confirmed","severity":"medium","confidence":0.84},{"id":"filesystem:SKILL.md:441:standard-device-file-access","reason":"The /dev/null redirection is part of a common command-existence check in a setup script template. It does not access sensitive device files.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:442:standard-device-file-access","reason":"The /dev/null redirection is part of a common command-existence check in a setup script template. It does not access sensitive device files.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:86:temp-file-creation","reason":"The mktemp use creates a temporary directory and installs a cleanup trap in a documented installer review flow. It is not suspicious persistence or data collection.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:SKILL.md:102:temp-file-creation","reason":"The mktemp use creates a temporary directory and installs a cleanup trap in a documented installer review flow. It is not suspicious persistence or data collection.","verdict":"false_positive","confidence":0.9},{"id":"env_access:SKILL.md:231:dotenv-library","reason":"The match is the python-dotenv package name in an example dependency install. It does not read or expose environment variables.","verdict":"false_positive","confidence":0.93},{"id":"env_access:SKILL.md:149:database-connection-strings","reason":"The match is a local example connection string or SQLite path used as documentation. It is not a real secret or exfiltration target.","verdict":"false_positive","confidence":0.88},{"id":"env_access:SKILL.md:240:database-connection-strings","reason":"The match is a local example connection string or SQLite path used as documentation. It is not a real secret or exfiltration target.","verdict":"false_positive","confidence":0.88},{"id":"env_access:SKILL.md:300:database-connection-strings","reason":"The Docker compose example embeds a database URL with a password-like value. Even as an example, hardcoded credentials can normalize unsafe configuration practices.","verdict":"confirmed","severity":"high","confidence":0.78},{"id":"env_access:SKILL.md:150:generic-api-secret-keys","reason":"The value is an obvious placeholder for documentation. No real key material appears in the skill file.","verdict":"false_positive","confidence":0.9},{"id":"env_access:SKILL.md:241:generic-api-secret-keys","reason":"The value is an obvious placeholder for documentation. No real key material appears in the skill file.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:SKILL.md:56:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:136:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:139:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:142:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:145:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:236:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:352:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:451:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:452:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:453:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:454:environment-file-access","reason":"The match is guidance for creating or documenting .env files with placeholders. The skill does not read, print, or transmit actual environment secrets.","verdict":"false_positive","confidence":0.86},{"id":"sensitive:SKILL.md:57:npm-config-file-may-contain-tokens","reason":"The line lists configuration file types as setup topics. It does not read .npmrc or expose npm tokens.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:SKILL.md:57:git-config-file","reason":"The line lists .gitconfig as a configuration topic. It does not read or modify a real git config file.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:SKILL.md:240:sqlite-database-file","reason":"The SQLite URI is a local example value in documentation. It is not accessing a real database file.","verdict":"false_positive","confidence":0.91},{"id":"blocker:SKILL.md:78:network-reconnaissance","reason":"The line says terminal access is a prerequisite. It does not perform scanning, probing, or reconnaissance.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Remote Installer Execution Without Integrity Verification","severity":"high","locations":[{"file":"SKILL.md","line_end":90,"line_start":88},{"file":"SKILL.md","line_end":106,"line_start":104},{"file":"SKILL.md","line_end":271,"line_start":270}],"confidence":0.9,"description":"The guide downloads installer scripts and then runs them with bash or sudo, but it does not require checksum or signature verification before execution.","confidence_reasoning":"The linked lines show direct download followed by shell execution, including sudo for NodeSource and Docker. The guide asks for review in some cases but does not require cryptographic verification."},{"title":"Root-Equivalent Docker Group Enrollment","severity":"high","locations":[{"file":"SKILL.md","line_end":274,"line_start":274}],"confidence":0.84,"description":"The Docker setup adds the current user to the docker group without explaining that this can grant broad control over the host.","confidence_reasoning":"The exact command adds $USER to the docker group with sudo. Docker group access is widely treated as equivalent to elevated host control on many systems."},{"title":"Weak Example Database Credentials","severity":"medium","locations":[{"file":"SKILL.md","line_end":311,"line_start":300}],"confidence":0.86,"description":"The Docker compose example uses a password-like value in the database URL and sets POSTGRES_PASSWORD to a weak literal example.","confidence_reasoning":"The example contains a database URL with password@db and POSTGRES_PASSWORD=password. It is likely a local example, but it can normalize unsafe defaults if copied."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":3,"capabilityReviewCount":26,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}