{"data":{"skill":{"slug":"sickn33-environment-setup-guide","name":"environment-setup-guide","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/environment-setup-guide","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"f9f53428-4a8a-4a4e-b6c6-73d608d599cd","skill_id":"b3f3487c-e80e-42d9-a114-5077a48bcd0d","version":5,"content_hash":"v3:88a8e9a07f4c54ab105c1c41b6267c287146b07b:17390b45014a4882366310f6e070395bbfda39f23e4ef895bf0ff0741eb2fb43:1f10032a707fc51135a23d4499a2e1c6c66a7f9e63ddc69f0b275efc0881d8b5:736b696c6c732f7369636b6e33332f656e7669726f6e6d656e742d73657475702d6775696465:ba5da0891292138c6c583f307c462ef5","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static findings are false positives caused by Markdown fences, placeholders, local addresses, and ordinary setup references. Confirmed risks include mutable remote installers, root execution, Docker group privileges, and exposed default database credentials. No prompt injection or data-exfiltration intent was found.","remediation":[{"issue":"Mutable remote installer scripts are downloaded and executed, including with root privileges.","severity":"high","suggestion":"Pin installer versions, verify published checksums or signatures, show the reviewed artifact, and request explicit confirmation before execution."},{"issue":"The Docker instructions add the user to a root-equivalent daemon group.","severity":"high","suggestion":"Prefer rootless Docker, explain the privilege impact, and require explicit user approval before changing group membership."},{"issue":"The Compose example publishes PostgreSQL with the password \"password\".","severity":"high","suggestion":"Generate a unique development password, bind the port to loopback, or omit host publishing when external access is unnecessary."},{"issue":"The setup template runs dependency hooks, migrations, and repository scripts automatically.","severity":"medium","suggestion":"Separate checks from changes, inspect package scripts, and request confirmation before installation, migrations, or project-defined commands."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":44,"line_start":38},{"file":"SKILL.md","line_end":73,"line_start":44},{"file":"SKILL.md","line_end":84,"line_start":73},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":114,"line_start":114},{"file":"SKILL.md","line_end":118,"line_start":118},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":125,"line_start":125},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":137,"line_start":136},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":143,"line_start":143},{"file":"SKILL.md","line_end":146,"line_start":145},{"file":"SKILL.md","line_end":146,"line_start":146},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":155,"line_start":155},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":174,"line_start":174},{"file":"SKILL.md","line_end":179,"line_start":175},{"file":"SKILL.md","line_end":185,"line_start":179},{"file":"SKILL.md","line_end":185,"line_start":185},{"file":"SKILL.md","line_end":187,"line_start":187},{"file":"SKILL.md","line_end":190,"line_start":190},{"file":"SKILL.md","line_end":193,"line_start":193},{"file":"SKILL.md","line_end":196,"line_start":196},{"file":"SKILL.md","line_end":198,"line_start":198},{"file":"SKILL.md","line_end":202,"line_start":202},{"file":"SKILL.md","line_end":205,"line_start":205},{"file":"SKILL.md","line_end":209,"line_start":209},{"file":"SKILL.md","line_end":222,"line_start":222},{"file":"SKILL.md","line_end":226,"line_start":226},{"file":"SKILL.md","line_end":232,"line_start":232},{"file":"SKILL.md","line_end":237,"line_start":236},{"file":"SKILL.md","line_end":237,"line_start":237},{"file":"SKILL.md","line_end":242,"line_start":242},{"file":"SKILL.md","line_end":246,"line_start":246},{"file":"SKILL.md","line_end":251,"line_start":251},{"file":"SKILL.md","line_end":256,"line_start":252},{"file":"SKILL.md","line_end":262,"line_start":256},{"file":"SKILL.md","line_end":262,"line_start":262},{"file":"SKILL.md","line_end":265,"line_start":265},{"file":"SKILL.md","line_end":268,"line_start":268},{"file":"SKILL.md","line_end":276,"line_start":276},{"file":"SKILL.md","line_end":283,"line_start":283}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":250,"line_start":250},{"file":"SKILL.md","line_end":270,"line_start":270},{"file":"SKILL.md","line_end":477,"line_start":477},{"file":"SKILL.md","line_end":478,"line_start":478},{"file":"SKILL.md","line_end":479,"line_start":479},{"file":"SKILL.md","line_end":480,"line_start":480},{"file":"SKILL.md","line_end":481,"line_start":481},{"file":"SKILL.md","line_end":482,"line_start":482},{"file":"SKILL.md","line_end":483,"line_start":483},{"file":"SKILL.md","line_end":250,"line_start":250}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":171,"line_start":171},{"file":"SKILL.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":173,"line_start":173},{"file":"SKILL.md","line_end":396,"line_start":396},{"file":"SKILL.md","line_end":397,"line_start":397},{"file":"SKILL.md","line_end":398,"line_start":398},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":171,"line_start":171},{"file":"SKILL.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":173,"line_start":173},{"file":"SKILL.md","line_end":396,"line_start":396},{"file":"SKILL.md","line_end":397,"line_start":397},{"file":"SKILL.md","line_end":398,"line_start":398},{"file":"SKILL.md","line_end":441,"line_start":441},{"file":"SKILL.md","line_end":442,"line_start":442},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":102,"line_start":102}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":231,"line_start":231},{"file":"SKILL.md","line_end":149,"line_start":149},{"file":"SKILL.md","line_end":240,"line_start":240},{"file":"SKILL.md","line_end":300,"line_start":300},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":241,"line_start":241}]}],"critical_findings":[],"high_findings":[{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":106,"line_start":106}],"confidence":0.98,"description":"sudo -E bash \"$tmpdir/nodesource-setup.sh\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This runs a downloaded NodeSource script with root privileges and preserves the environment. A compromised response or dependency could modify the entire system."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":271,"line_start":271}],"confidence":0.99,"description":"sudo sh get-docker.sh","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This executes the mutable get.docker.com script as root without an integrity check or review step. Compromise of the download path would yield system control."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":274,"line_start":274}],"confidence":0.98,"description":"sudo usermod -aG docker $USER","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"Adding a user to the docker group grants control of the Docker daemon. That access is commonly equivalent to root privileges on the host."},{"title":"Database connection strings","locations":[{"file":"SKILL.md","line_end":300,"line_start":300}],"confidence":0.97,"description":"- DATABASE_URL=postgresql://postgres:password@db:5432/mydb","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The example embeds the predictable database password \"password\" and publishes PostgreSQL on the host. Reuse outside an isolated machine could expose the database."},{"title":"Default Database Credentials Exposed on Host Port","locations":[{"file":"SKILL.md","line_end":314,"line_start":300}],"confidence":0.98,"description":"The Docker Compose example publishes PostgreSQL on port 5432 while assigning the password \"password\". Other local users or reachable hosts could authenticate.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The configuration directly combines predictable credentials with a published database port. The risk is clear unless the host network is fully isolated."}],"medium_findings":[{"title":"Unix shell invocation","locations":[{"file":"SKILL.md","line_end":90,"line_start":90}],"confidence":0.94,"description":"/bin/bash \"$tmpdir/homebrew-install.sh\"","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This command executes a script downloaded from a mutable URL. Manual review reduces risk, but remote shell code can still compromise the user account."},{"title":"Setup Template Runs Project-Defined Code Without Confirmation","locations":[{"file":"SKILL.md","line_end":463,"line_start":446}],"confidence":0.9,"description":"The setup template runs npm installation, migrations, and setup tests automatically. Dependency lifecycle hooks or project scripts can execute arbitrary code and alter data.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The listed commands execute dependency and project-controlled scripts without a review or confirmation boundary. Their exact behavior depends on the target repository."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":88,"line_start":88}],"confidence":0.93,"description":"curl -fsSLo \"$tmpdir/homebrew-install.sh\" https://raw.githubusercontent.com/Homebrew/install/HEAD/in","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The command downloads a mutable installer from GitHub for later execution. The official host lowers suspicion, but no version pin or checksum protects integrity."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":104,"line_start":104}],"confidence":0.96,"description":"curl -fsSLo \"$tmpdir/nodesource-setup.sh\" https://deb.nodesource.com/setup_20.x","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The command downloads a mutable NodeSource setup script that is later executed as root. No version pin or checksum authenticates the retrieved content."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":270,"line_start":270}],"confidence":0.98,"description":"curl -fsSL https://get.docker.com -o get-docker.sh","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The command downloads a mutable Docker installation script that is immediately executed as root. It provides no checksum or content review step."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":493,"audit_model":"codex","audited_at":"2026-07-23T23:30:47.198+00:00","created_at":"2026-07-26T11:21:58.428173+00:00","static_findings":[{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":44,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":73,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":84,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":94,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":111,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":114,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":118,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":125,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create a \\`.env\\` file:","category":"external_commands","line_end":137,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":143,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Example \\`.env\\` content:","category":"external_commands","line_end":146,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":146,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":151,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Solution:** Restart your terminal or run \\`source ~/.bashrc\\` (Linux) or \\`source ~/.zshrc\\` (macO","category":"external_commands","line_end":165,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":179,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":185,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":185,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":187,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":190,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":193,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":196,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":198,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":202,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":205,"severity":"medium","line_start":205},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":209,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":222,"severity":"medium","line_start":222},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":226,"severity":"medium","line_start":226},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":232,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create \\`.env\\` file:","category":"external_commands","line_end":237,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":237,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":242,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":246,"severity":"medium","line_start":246},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":251,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":256,"severity":"medium","line_start":252},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":262,"severity":"medium","line_start":256},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":262,"severity":"medium","line_start":262},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":265,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":268,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":276,"severity":"medium","line_start":276},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":283,"severity":"medium","line_start":283},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":286,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`yaml","category":"external_commands","line_end":290,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":320,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":324,"severity":"medium","line_start":324},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":333,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":337,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"\\`\\`\\`","category":"external_commands","line_end":343,"severity":"medium","line_start":343},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":380,"severity":"medium","line_start":344},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":386,"severity":"medium","line_start":380},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":394,"severity":"medium","line_start":386},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":399,"severity":"medium","line_start":394},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":406,"severity":"medium","line_start":399},{"id":"external_commands:SKILL.md:406:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":415,"severity":"medium","line_start":406},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":423,"severity":"medium","line_start":415},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":429,"severity":"medium","line_start":423},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":433,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create a `setup.sh` script to automate setup:","category":"external_commands","line_end":435,"severity":"medium","line_start":433},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":466,"severity":"medium","line_start":435},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":470,"severity":"medium","line_start":466},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@brainstorming` - Plan environment requirements before setup","category":"external_commands","line_end":471,"severity":"medium","line_start":470},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@systematic-debugging` - Debug environment issues","category":"external_commands","line_end":472,"severity":"medium","line_start":471},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@doc-coauthoring` - Create setup documentation","category":"external_commands","line_end":473,"severity":"medium","line_start":472},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `@git-pushing` - Set up Git configuration","category":"external_commands","line_end":487,"severity":"medium","line_start":473},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Pro Tip:** Create a `setup.sh` or `setup.ps1` script to automate the entire setup process. Test it","category":"external_commands","line_end":487,"severity":"medium","line_start":487},{"id":"external_commands:SKILL.md:86:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"tmpdir=\"$(mktemp -d)\"","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:102:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"tmpdir=\"$(mktemp -d)\"","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:84:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":94,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:97:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"\\`\\`\\`bash","category":"external_commands","line_end":108,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:111:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":111,"severity":"high","line_start":111},{"id":"external_commands:SKILL.md:196:powershell-invocation","file":"SKILL.md","pattern":"PowerShell invocation","snippet":"\\`\\`\\`powershell","category":"external_commands","line_end":196,"severity":"high","line_start":196},{"id":"external_commands:SKILL.md:90:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"/bin/bash \"$tmpdir/homebrew-install.sh\"","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:436:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":436,"severity":"medium","line_start":436},{"id":"external_commands:SKILL.md:99:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt update","category":"external_commands","line_end":99,"severity":"high","line_start":99},{"id":"external_commands:SKILL.md:105:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"cat \"$tmpdir/nodesource-setup.sh\"  # review the full installer before sudo","category":"external_commands","line_end":106,"severity":"high","line_start":105},{"id":"external_commands:SKILL.md:106:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo -E bash \"$tmpdir/nodesource-setup.sh\"","category":"external_commands","line_end":106,"severity":"high","line_start":106},{"id":"external_commands:SKILL.md:107:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install -y nodejs","category":"external_commands","line_end":107,"severity":"high","line_start":107},{"id":"external_commands:SKILL.md:168:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"**Solution:** Don't use sudo with npm. Fix permissions:","category":"external_commands","line_end":168,"severity":"high","line_start":168},{"id":"external_commands:SKILL.md:191:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt update","category":"external_commands","line_end":191,"severity":"high","line_start":191},{"id":"external_commands:SKILL.md:192:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo apt install python3.11 python3.11-venv python3-pip","category":"external_commands","line_end":192,"severity":"high","line_start":192},{"id":"external_commands:SKILL.md:271:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo sh get-docker.sh","category":"external_commands","line_end":271,"severity":"high","line_start":271},{"id":"external_commands:SKILL.md:274:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo usermod -aG docker $USER","category":"external_commands","line_end":274,"severity":"high","line_start":274},{"id":"external_commands:SKILL.md:391:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"- Don't use sudo","category":"external_commands","line_end":392,"severity":"high","line_start":391},{"id":"external_commands:SKILL.md:425:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo systemctl status postgresql","category":"external_commands","line_end":425,"severity":"high","line_start":425},{"id":"network:SKILL.md:88:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -fsSLo \"$tmpdir/homebrew-install.sh\" https://raw.githubusercontent.com/Homebrew/install/HEAD/in","category":"network","line_end":88,"severity":"low","line_start":88},{"id":"network:SKILL.md:104:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -fsSLo \"$tmpdir/nodesource-setup.sh\" https://deb.nodesource.com/setup_20.x","category":"network","line_end":104,"severity":"low","line_start":104},{"id":"network:SKILL.md:127:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"git clone https://github.com/your-repo/project.git","category":"network","line_end":127,"severity":"low","line_start":127},{"id":"network:SKILL.md:159:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# Should see: Server running on http://localhost:3000","category":"network","line_end":159,"severity":"low","line_start":159},{"id":"network:SKILL.md:250:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# Should see: Running on http://127.0.0.1:5000","category":"network","line_end":250,"severity":"low","line_start":250},{"id":"network:SKILL.md:270:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -fsSL https://get.docker.com -o get-docker.sh","category":"network","line_end":270,"severity":"low","line_start":270},{"id":"network:SKILL.md:477:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Node.js Installation Guide](https://nodejs.org/en/download/)","category":"network","line_end":477,"severity":"low","line_start":477},{"id":"network:SKILL.md:478:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Python Virtual Environments](https://docs.python.org/3/tutorial/venv.html)","category":"network","line_end":478,"severity":"low","line_start":478},{"id":"network:SKILL.md:479:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Docker Documentation](https://docs.docker.com/get-started/)","category":"network","line_end":479,"severity":"low","line_start":479},{"id":"network:SKILL.md:480:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Homebrew (macOS)](https://brew.sh/)","category":"network","line_end":480,"severity":"low","line_start":480},{"id":"network:SKILL.md:481:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Chocolatey (Windows)](https://chocolatey.org/)","category":"network","line_end":481,"severity":"low","line_start":481},{"id":"network:SKILL.md:482:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [nvm (Node Version Manager)](https://github.com/nvm-sh/nvm)","category":"network","line_end":482,"severity":"low","line_start":482},{"id":"network:SKILL.md:483:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [pyenv (Python Version Manager)](https://github.com/pyenv/pyenv)","category":"network","line_end":483,"severity":"low","line_start":483},{"id":"network:SKILL.md:250:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"# Should see: Running on http://127.0.0.1:5000","category":"network","line_end":250,"severity":"medium","line_start":250},{"id":"filesystem:SKILL.md:165:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"**Solution:** Restart your terminal or run \\`source ~/.bashrc\\` (Linux) or \\`source ~/.zshrc\\` (macO","category":"filesystem","line_end":165,"severity":"high","line_start":165},{"id":"filesystem:SKILL.md:170:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":170,"severity":"high","line_start":170},{"id":"filesystem:SKILL.md:171:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":171,"severity":"high","line_start":171},{"id":"filesystem:SKILL.md:172:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":172,"severity":"high","line_start":172},{"id":"filesystem:SKILL.md:173:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"source ~/.bashrc","category":"filesystem","line_end":173,"severity":"high","line_start":173},{"id":"filesystem:SKILL.md:396:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":396,"severity":"high","line_start":396},{"id":"filesystem:SKILL.md:397:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":397,"severity":"high","line_start":397},{"id":"filesystem:SKILL.md:398:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":398,"severity":"high","line_start":398},{"id":"filesystem:SKILL.md:165:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"**Solution:** Restart your terminal or run \\`source ~/.bashrc\\` (Linux) or \\`source ~/.zshrc\\` (macO","category":"filesystem","line_end":165,"severity":"medium","line_start":165},{"id":"filesystem:SKILL.md:170:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":170,"severity":"medium","line_start":170},{"id":"filesystem:SKILL.md:171:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":171,"severity":"medium","line_start":171},{"id":"filesystem:SKILL.md:172:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":172,"severity":"medium","line_start":172},{"id":"filesystem:SKILL.md:173:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"source ~/.bashrc","category":"filesystem","line_end":173,"severity":"medium","line_start":173},{"id":"filesystem:SKILL.md:396:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"mkdir ~/.npm-global","category":"filesystem","line_end":396,"severity":"medium","line_start":396},{"id":"filesystem:SKILL.md:397:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"npm config set prefix '~/.npm-global'","category":"filesystem","line_end":397,"severity":"medium","line_start":397},{"id":"filesystem:SKILL.md:398:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc","category":"filesystem","line_end":398,"severity":"medium","line_start":398},{"id":"filesystem:SKILL.md:441:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"command -v node >/dev/null 2>&1 || { echo \"❌ Node.js not installed\"; exit 1; }","category":"filesystem","line_end":441,"severity":"low","line_start":441},{"id":"filesystem:SKILL.md:442:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"command -v git >/dev/null 2>&1 || { echo \"❌ Git not installed\"; exit 1; }","category":"filesystem","line_end":442,"severity":"low","line_start":442},{"id":"filesystem:SKILL.md:86:temp-file-creation","file":"SKILL.md","pattern":"Temp file creation","snippet":"tmpdir=\"$(mktemp -d)\"","category":"filesystem","line_end":86,"severity":"low","line_start":86},{"id":"filesystem:SKILL.md:102:temp-file-creation","file":"SKILL.md","pattern":"Temp file creation","snippet":"tmpdir=\"$(mktemp -d)\"","category":"filesystem","line_end":102,"severity":"low","line_start":102},{"id":"env_access:SKILL.md:231:dotenv-library","file":"SKILL.md","pattern":"dotenv library","snippet":"pip install flask sqlalchemy python-dotenv","category":"env_access","line_end":231,"severity":"low","line_start":231},{"id":"env_access:SKILL.md:149:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"DATABASE_URL=postgresql://localhost:5432/mydb","category":"env_access","line_end":149,"severity":"high","line_start":149},{"id":"env_access:SKILL.md:240:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"DATABASE_URL=sqlite:///app.db","category":"env_access","line_end":240,"severity":"high","line_start":240},{"id":"env_access:SKILL.md:300:database-connection-strings","file":"SKILL.md","pattern":"Database connection strings","snippet":"- DATABASE_URL=postgresql://postgres:password@db:5432/mydb","category":"env_access","line_end":300,"severity":"high","line_start":300},{"id":"env_access:SKILL.md:150:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"API_KEY=your-api-key-here","category":"env_access","line_end":150,"severity":"high","line_start":150},{"id":"env_access:SKILL.md:241:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"SECRET_KEY=your-secret-key-here","category":"env_access","line_end":241,"severity":"high","line_start":241},{"id":"sensitive:SKILL.md:56:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"- Environment variables (.env files)","category":"sensitive","line_end":56,"severity":"high","line_start":56},{"id":"sensitive:SKILL.md:136:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"Create a \\`.env\\` file:","category":"sensitive","line_end":136,"severity":"high","line_start":136},{"id":"sensitive:SKILL.md:139:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"cp .env.example .env","category":"sensitive","line_end":139,"severity":"high","line_start":139},{"id":"sensitive:SKILL.md:142:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"nano .env","category":"sensitive","line_end":142,"severity":"high","line_start":142},{"id":"sensitive:SKILL.md:145:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"Example \\`.env\\` content:","category":"sensitive","line_end":145,"severity":"high","line_start":145},{"id":"sensitive:SKILL.md:236:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"Create \\`.env\\` file:","category":"sensitive","line_end":236,"severity":"high","line_start":236},{"id":"sensitive:SKILL.md:352:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"- **Create .env.example** - Show required environment variables","category":"sensitive","line_end":352,"severity":"high","line_start":352},{"id":"sensitive:SKILL.md:451:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"if [ ! -f .env ]; then","category":"sensitive","line_end":451,"severity":"high","line_start":451},{"id":"sensitive:SKILL.md:452:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"echo \"📝 Creating .env file...\"","category":"sensitive","line_end":452,"severity":"high","line_start":452},{"id":"sensitive:SKILL.md:453:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"cp .env.example .env","category":"sensitive","line_end":453,"severity":"high","line_start":453},{"id":"sensitive:SKILL.md:454:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"echo \"⚠️  Please edit .env with your configuration\"","category":"sensitive","line_end":454,"severity":"high","line_start":454},{"id":"sensitive:SKILL.md:57:npm-config-file-may-contain-tokens","file":"SKILL.md","pattern":"NPM config file (may contain tokens)","snippet":"- Configuration files (.gitconfig, .npmrc, etc.)","category":"sensitive","line_end":57,"severity":"high","line_start":57},{"id":"sensitive:SKILL.md:57:git-config-file","file":"SKILL.md","pattern":"Git config file","snippet":"- Configuration files (.gitconfig, .npmrc, etc.)","category":"sensitive","line_end":57,"severity":"medium","line_start":57},{"id":"sensitive:SKILL.md:240:sqlite-database-file","file":"SKILL.md","pattern":"SQLite database file","snippet":"DATABASE_URL=sqlite:///app.db","category":"sensitive","line_end":240,"severity":"medium","line_start":240},{"id":"blocker:SKILL.md:78:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Terminal/Command Prompt access","category":"blocker","line_end":79,"severity":"low","line_start":78}],"finding_verdicts":[{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:406:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:415:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:433:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:470:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","reason":"The matched text is a Markdown fence or inline-code marker in documentation, not Ruby or shell backtick execution. It cannot execute by itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:shell-command-substitution","reason":"The fixed mktemp substitution creates an isolated temporary directory, followed by a cleanup trap. It does not evaluate user-controlled command text.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:102:shell-command-substitution","reason":"The fixed mktemp substitution creates an isolated temporary directory, followed by a cleanup trap. It does not evaluate user-controlled command text.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:84:template-literal-with-command-substitution","reason":"The matched characters are an escaped Markdown code-fence label. They are not a program template literal and perform no command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:template-literal-with-command-substitution","reason":"The matched characters are an escaped Markdown code-fence label. They are not a program template literal and perform no command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:powershell-invocation","reason":"The snippet is an escaped Markdown fence naming PowerShell as the example language. It does not launch PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:powershell-invocation","reason":"The snippet is an escaped Markdown fence naming PowerShell as the example language. It does not launch PowerShell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:90:unix-shell-invocation","reason":"This command executes a script downloaded from a mutable URL. Manual review reduces risk, but remote shell code can still compromise the user account.","verdict":"confirmed","severity":"medium","confidence":0.94},{"id":"external_commands:SKILL.md:436:unix-shell-invocation","reason":"The matched text is a shebang inside a documented setup-script template. It only selects Bash if a user separately creates and runs that script.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:sudo-privilege-escalation","reason":"This fixed apt package-management command is expected for Linux environment setup. It uses no user-controlled arguments, downloaded script, or hidden privilege request.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:105:sudo-privilege-escalation","reason":"This line uses the word sudo only in a comment that tells users to review an installer. It performs no privileged operation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:sudo-privilege-escalation","reason":"This runs a downloaded NodeSource script with root privileges and preserves the environment. A compromised response or dependency could modify the entire system.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:SKILL.md:107:sudo-privilege-escalation","reason":"This fixed apt package-management command is expected for Linux environment setup. It uses no user-controlled arguments, downloaded script, or hidden privilege request.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:168:sudo-privilege-escalation","reason":"This is safety guidance telling users not to use sudo. It neither invokes sudo nor requests elevated privileges.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:191:sudo-privilege-escalation","reason":"This fixed apt package-management command is expected for Linux environment setup. It uses no user-controlled arguments, downloaded script, or hidden privilege request.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:192:sudo-privilege-escalation","reason":"This fixed apt package-management command is expected for Linux environment setup. It uses no user-controlled arguments, downloaded script, or hidden privilege request.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:271:sudo-privilege-escalation","reason":"This executes the mutable get.docker.com script as root without an integrity check or review step. Compromise of the download path would yield system control.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"external_commands:SKILL.md:274:sudo-privilege-escalation","reason":"Adding a user to the docker group grants control of the Docker daemon. That access is commonly equivalent to root privileges on the host.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:SKILL.md:391:sudo-privilege-escalation","reason":"This is safety guidance telling users not to use sudo. It neither invokes sudo nor requests elevated privileges.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:425:sudo-privilege-escalation","reason":"The fixed systemctl status command only checks a local service state. It contains no user-controlled arguments and is normal troubleshooting guidance.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:88:hardcoded-url","reason":"The command downloads a mutable installer from GitHub for later execution. The official host lowers suspicion, but no version pin or checksum protects integrity.","verdict":"confirmed","severity":"low","confidence":0.93},{"id":"network:SKILL.md:104:hardcoded-url","reason":"The command downloads a mutable NodeSource setup script that is later executed as root. No version pin or checksum authenticates the retrieved content.","verdict":"confirmed","severity":"low","confidence":0.96},{"id":"network:SKILL.md:127:hardcoded-url","reason":"This is an explicit placeholder repository URL in a cloning example. It does not identify an attacker-controlled endpoint or transmit private data.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:159:hardcoded-url","reason":"The URL is loopback status text showing where a local development server should appear. It causes no network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:250:hardcoded-url","reason":"The URL is loopback status text showing where a local development server should appear. It causes no network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:270:hardcoded-url","reason":"The command downloads a mutable Docker installation script that is immediately executed as root. It provides no checksum or content review step.","verdict":"confirmed","severity":"low","confidence":0.98},{"id":"network:SKILL.md:477:hardcoded-url","reason":"This is a documentation link to an official project or package-manager resource. It does not send credentials or trigger a request automatically.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:478:hardcoded-url","reason":"This is a documentation link to an official project or package-manager resource. It does not send credentials or trigger a request automatically.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:479:hardcoded-url","reason":"This is a documentation link to an official project or package-manager resource. It does not send credentials or trigger a request automatically.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:480:hardcoded-url","reason":"This is a documentation link to an official project or package-manager resource. It does not send credentials or trigger a request automatically.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:481:hardcoded-url","reason":"This is a documentation link to an official project or package-manager resource. It does not send credentials or trigger a request automatically.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:482:hardcoded-url","reason":"This is a documentation link to an official project or package-manager resource. It does not send credentials or trigger a request automatically.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:483:hardcoded-url","reason":"This is a documentation link to an official project or package-manager resource. It does not send credentials or trigger a request automatically.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:250:hardcoded-ip-address","reason":"The address is the loopback interface in expected Flask status output. It is not a remote target or reconnaissance destination.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:165:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:170:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:171:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:172:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:173:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:396:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:397:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:398:hidden-file-in-home-directory","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:165:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:170:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:171:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:172:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:173:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:396:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:397:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:398:hidden-file-access","reason":"The command configures a documented npm prefix or shell PATH in the current user's home directory. The fixed content is visible and expected for setup.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:441:standard-device-file-access","reason":"The prerequisite check redirects command output to /dev/null. This standard discard operation does not read a device or expose data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:442:standard-device-file-access","reason":"The prerequisite check redirects command output to /dev/null. This standard discard operation does not read a device or expose data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:86:temp-file-creation","reason":"mktemp creates a private temporary directory for installer review, and the adjacent trap removes it. The path is not predictable or shared.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:102:temp-file-creation","reason":"mktemp creates a private temporary directory for installer review, and the adjacent trap removes it. The path is not predictable or shared.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:231:dotenv-library","reason":"The line installs the standard python-dotenv package as an example dependency. It does not read or disclose any environment value.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:149:database-connection-strings","reason":"This is a credential-free localhost PostgreSQL example. It contains no secret and targets only the developer's local service.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:240:database-connection-strings","reason":"This is a local SQLite URI in sample configuration. It contains no credential and opens no remote connection.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:300:database-connection-strings","reason":"The example embeds the predictable database password \"password\" and publishes PostgreSQL on the host. Reuse outside an isolated machine could expose the database.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"env_access:SKILL.md:150:generic-api-secret-keys","reason":"The value is an explicit placeholder telling users where to supply their own development secret. No real key is embedded, read, or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:241:generic-api-secret-keys","reason":"The value is an explicit placeholder telling users where to supply their own development secret. No real key is embedded, read, or transmitted.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:56:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:136:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:139:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:142:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:145:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:236:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:352:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:451:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:452:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:453:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:454:environment-file-access","reason":"The documentation creates a project-local .env from an example or asks the user to edit it. It does not read, print, or transmit existing secrets.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:57:npm-config-file-may-contain-tokens","reason":"The line only lists .npmrc as a configuration-file type the skill may help document. It does not open or inspect any npm token.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:57:git-config-file","reason":"The line only names .gitconfig as a configuration-file example. It does not read, modify, or transmit Git configuration.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:240:sqlite-database-file","reason":"The snippet is a local SQLite URI in sample environment content. It does not access an existing database file or expose its contents.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:78:network-reconnaissance","reason":"The text lists terminal access as a prerequisite. It performs no host discovery, port scan, address lookup, or other network reconnaissance.","verdict":"false_positive","confidence":1}],"semantic_findings":[{"title":"Default Database Credentials Exposed on Host Port","severity":"high","locations":[{"file":"SKILL.md","line_end":314,"line_start":300}],"confidence":0.98,"description":"The Docker Compose example publishes PostgreSQL on port 5432 while assigning the password \"password\". Other local users or reachable hosts could authenticate.","confidence_reasoning":"The configuration directly combines predictable credentials with a published database port. The risk is clear unless the host network is fully isolated."},{"title":"Setup Template Runs Project-Defined Code Without Confirmation","severity":"medium","locations":[{"file":"SKILL.md","line_end":463,"line_start":446}],"confidence":0.9,"description":"The setup template runs npm installation, migrations, and setup tests automatically. Dependency lifecycle hooks or project scripts can execute arbitrary code and alter data.","confidence_reasoning":"The listed commands execute dependency and project-controlled scripts without a review or confirmation boundary. Their exact behavior depends on the target repository."}],"subject_marketplace_commit_sha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","subject_content_hash":"17390b45014a4882366310f6e070395bbfda39f23e4ef895bf0ff0741eb2fb43","subject_tree_hash":"1f10032a707fc51135a23d4499a2e1c6c66a7f9e63ddc69f0b275efc0881d8b5","subject_plugin_path":"skills/sickn33/environment-setup-guide","audit_payload_hash":"ba5da0891292138c6c583f307c462ef5","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","contentHash":"17390b45014a4882366310f6e070395bbfda39f23e4ef895bf0ff0741eb2fb43","treeHash":"1f10032a707fc51135a23d4499a2e1c6c66a7f9e63ddc69f0b275efc0881d8b5","pluginPath":"skills/sickn33/environment-setup-guide","auditPayloadHash":"ba5da0891292138c6c583f307c462ef5"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-environment-setup-guide/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":8,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}