{"data":{"skill":{"slug":"tencentcloudbase-auth-web-cloudbase","name":"auth-web-cloudbase","icon":"📦","repo":"https://github.com/tencentcloudbase/skills/tree/main/skills/auth-web","status":"approved","author":"tencentcloudbase","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"5e486434-c531-4ae9-a84c-1d4caa8a39a8","skill_id":"6924dc62-c7b0-4ca1-b885-a76b1aa4bea7","version":1,"content_hash":"v2:24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec:c69b56879f695c969c723afe201c6696453bf1e8010b00c075d5b760cdb76732:a185b199ac29e367ec3cf815a0c3039ddb84790267f432fcc738061d7e6fc178:4f27aec96d5050fb69f9d5696f92dbd3","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static command, network, filesystem, and reconnaissance findings are false positives caused by Markdown formatting, public setup links, and frontend auth examples. No prompt injection or malicious exfiltration intent was found. A medium semantic risk remains because the skill tells agents to automatically change CloudBase auth provider settings without an explicit confirmation requirement.","remediation":[{"issue":"Automatic provider enablement instructions","severity":"medium","suggestion":"Require explicit user approval before calling manageAppAuth or enabling SMS, email, anonymous, OAuth, or username password providers."},{"issue":"Parent-directory references to sibling skills","severity":"low","suggestion":"Prefer packaged references or marketplace dependency metadata over ../ sibling paths to reduce scanner noise and installation ambiguity."},{"issue":"Public fallback URLs embedded in the skill text","severity":"low","suggestion":"Document that remote references are read-only setup material and should not receive project secrets or user data."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":91,"line_start":91},{"file":"SKILL.md","line_end":92,"line_start":92},{"file":"SKILL.md","line_end":93,"line_start":93},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":119,"line_start":105},{"file":"SKILL.md","line_end":121,"line_start":119},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":128,"line_start":128}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":328,"line_start":328},{"file":"SKILL.md","line_end":416,"line_start":416},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":50,"line_start":50}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":477,"line_start":477}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Automatic Auth Provider Changes Need Confirmation","locations":[{"file":"SKILL.md","line_end":84,"line_start":83},{"file":"SKILL.md","line_end":128,"line_start":128},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":287,"line_start":287},{"file":"SKILL.md","line_end":296,"line_start":296}],"confidence":0.78,"description":"The skill repeatedly instructs agents to automatically use auth-tool-cloudbase or manageAppAuth to enable login providers, including SMS, email, anonymous, and OAuth. Changing authentication provider settings can expand access paths if done without explicit project owner approval.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The instruction pattern is explicit and repeated, but it is related to legitimate auth setup. The risk is configuration change without user confirmation, not malicious code execution."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":516,"audit_model":"codex","audited_at":"2026-07-09T15:25:05.878+00:00","created_at":"2026-07-09T17:30:21.481053+00:00","static_findings":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If this environment only installed the current skill, start from the CloudBase main entry and use th","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Keep local `references/...` paths for files that ship with the current skill directory. When this fi","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The task is a CloudBase Web login, registration, session, or user profile flow built with `@cloudb","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The user needs a login page, auth modal, session handling, or protected Web route. Read `auth-tool","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `../auth-tool/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudbase/clou","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- In that case, activate `auth-tool-cloudbase` before `auth-web-cloudbase`.","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Creating a detached helper file with `auth.signUp` / `verifyOtp` but never wiring it into the exis","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Using `signInWithEmailAndPassword` or `signUpWithEmailAndPassword` for username-style accounts suc","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Keeping the login or register account input as `type=\"email\"` when the task explicitly says the ac","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Starting implementation before calling `queryAppAuth(action=\"getLoginConfig\")` and enabling `usern","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writing `auth.signInWithPassword(...)` or `auth.signUp(...)` code without first confirming the p","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Treating `auth.getUser()` or deprecated `auth.getLoginState()` as proof of real login.** When th","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Copying old CloudBase auth snippets from training data.** Do not use `auth.getLoginState()`, `au","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Note: anonymous login is now **disabled by default** for new environments and inactive existing envi","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prerequisites**: CloudBase environment ID (`env`)","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Prerequisites**: CloudBase environment Region (`region`)","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Use Case**: Web frontend projects using `@cloudbase/js-sdk@latest` for user authentication","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Key Benefits**: **Supabase-compatible Auth API** — all methods return `{ data, error }`, supports ","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> 📌 **Supabase API Compatibility**: CloudBase Web SDK v3 auth module is designed with Supabase-like","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - All methods return `Promise<{ data, error }>` — always check `error` first","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - `signInWithPassword`, `signInWithOtp`, `signUp`, `signOut`, `getSession`, `getUser` follow the s","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - `onAuthStateChange(callback)` provides reactive auth state observation (events: `INITIAL_SESSION","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - Session management via `getSession()` / `refreshSession()` / `setSession()` mirrors Supabase pat","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - **OTP verification**: Supabase uses a standalone `auth.verifyOtp({ phone, token, type })` call; ","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - **`accessKey`** replaces Supabase's `anonKey`; environment uses `env` + `region` instead of Supa","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> - **`signInWithIdToken`** for direct third-party token login (similar to Supabase's same-named met","category":"external_commands","line_end":77,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use npm installation for modern Web projects. In React, Vue, Vite, and other bundler-based apps, ins","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Automatically use `auth-tool-cloudbase` to check app-side auth readiness via `queryAppAuth` / `man","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `auth-tool-cloudbase` failed, let user go to `https://tcb.cloud.tencent.com/dev?envId={env}#/en","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For username-style identifiers, the required precondition is `loginMethods.usernamePassword === tr","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the conversation only provides an environment alias, nickname, or other shorthand, resolve it w","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Treat CloudBase Web Auth as **Supabase-like**, not “every `supabase-js` auth example is valid unch","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- When `queryAppAuth` / `manageAppAuth` returns `sdkStyle: \"supabase-like\"` and `sdkHints`, follow t","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `auth.signInWithOtp({ phone })` and `auth.signUp({ phone })` use the phone number in a `phone` fie","category":"external_commands","line_end":92,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `auth.signInWithOtp({ email })` and `auth.signUp({ email })` use `email`","category":"external_commands","line_end":93,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `auth.signInWithPassword({ username, password })` is the canonical Web login path for username/pas","category":"external_commands","line_end":94,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Treat direct Web `auth.signUp({ username, password })` as conditional. Verify `sdkHints` and the i","category":"external_commands","line_end":95,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the task gives accounts like `admin`, `editor`, or another plain string without `@`, treat it a","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `verifyOtp({ token })` expects the SMS or email code in `token`","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `accessKey` is the publishable key from `queryAppAuth` / `manageAppAuth` via `auth-tool-cloudbase`","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`accessKey` triggers automatic anonymous session creation** — the deprecated `auth.getLoginState","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Never set `accessKey` to `envId`, a username, or any placeholder string. If you do not have a real","category":"external_commands","line_end":100,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the task mentions provider setup, stop and read `auth-tool-cloudbase` before writing frontend c","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":119,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":121,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the current task has not retrieved a real Publishable Key, omit `accessKey` instead of inventing ","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Automatically use `auth-tool-cloudbase` to turn on `SMS Login` through `manageAppAuth`","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Send the phone number to `auth.signInWithOtp({ phone, ... })`, then call the returned `verifyOtp({","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `signInWithOtp` can automatically create a new user if the user does not exist; control this via `","category":"external_commands","line_end":130,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":134,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":137,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Automatically use `auth-tool-cloudbase` to turn on `Email Login` through `manageAppAuth`","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":141,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":145,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All auth methods return `{ data, error }`. Always check `error` first:","category":"external_commands","line_end":145,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":163,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":166,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":202,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":206,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Username/password login can use plain identifiers such as `admin` or `editor`, but raw signup APIs","category":"external_commands","line_end":206,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":227,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":229,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When the project already has `handleSendCode` / `handleRegister` or similar UI handlers, wire the SD","category":"external_commands","line_end":229,"severity":"medium","line_start":229},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":252,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":254,"severity":"medium","line_start":252},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Do not use email OTP or email-only helpers for these flows unless the task explicitly says the accou","category":"external_commands","line_end":254,"severity":"medium","line_start":254},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```tsx","category":"external_commands","line_end":280,"severity":"medium","line_start":256},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":284,"severity":"medium","line_start":280},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> ⚠️ **Anonymous login is disabled by default for new environments.** The SDK initialized with `acce","category":"external_commands","line_end":284,"severity":"medium","line_start":284},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Automatically use `auth-tool-cloudbase` to turn on `Anonymous Login` through `manageAppAuth` (must","category":"external_commands","line_end":287,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":293,"severity":"medium","line_start":288},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":296,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Automatically use `auth-tool-cloudbase` to turn on `Google Login` or `WeChat Login` through `manag","category":"external_commands","line_end":296,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Supported providers: `google`, `wechat`, `github`, `facebook`, `apple`","category":"external_commands","line_end":297,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- By default, OAuth callback is auto-handled when `auth.detectSessionInUrl: true` is set in init","category":"external_commands","line_end":299,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":313,"severity":"medium","line_start":299},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":316,"severity":"medium","line_start":313},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `detectSessionInUrl` is not set, call `verifyOAuth` manually after redirect:","category":"external_commands","line_end":316,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":326,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":331,"severity":"medium","line_start":326},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":334,"severity":"medium","line_start":331},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":340,"severity":"medium","line_start":334},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":343,"severity":"medium","line_start":340},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":350,"severity":"medium","line_start":343},{"id":"external_commands:SKILL.md:350:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":356,"severity":"medium","line_start":350},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":417,"severity":"medium","line_start":356},{"id":"external_commands:SKILL.md:417:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"headers: { Authorization: `Bearer ${sessionResult.data.session?.access_token}` },","category":"external_commands","line_end":429,"severity":"medium","line_start":417},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":435,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```ts","category":"external_commands","line_end":467,"severity":"medium","line_start":435},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":473,"severity":"medium","line_start":467},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":506,"severity":"medium","line_start":473},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"btn.innerText = `Resend in ${countdown}s`","category":"external_commands","line_end":515,"severity":"medium","line_start":506},{"id":"network:SKILL.md:328:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"const res = await fetch('/api/ticket')","category":"network","line_end":328,"severity":"low","line_start":328},{"id":"network:SKILL.md:416:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"await fetch('/api/protected', {","category":"network","line_end":416,"severity":"low","line_start":416},{"id":"network:SKILL.md:12:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:29:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `../auth-tool/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-","category":"network","line_end":29,"severity":"low","line_start":29},{"id":"network:SKILL.md:30:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudbase/clou","category":"network","line_end":30,"severity":"low","line_start":30},{"id":"network:SKILL.md:84:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- If `auth-tool-cloudbase` failed, let user go to `https://tcb.cloud.tencent.com/dev?envId={env}#/en","category":"network","line_end":84,"severity":"low","line_start":84},{"id":"network:SKILL.md:50:email-sending-capability","file":"SKILL.md","pattern":"Email sending capability","snippet":"- **Writing `auth.signInWithPassword(...)` or `auth.signUp(...)` code without first confirming the p","category":"network","line_end":50,"severity":"medium","line_start":50},{"id":"filesystem:SKILL.md:29:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- `../auth-tool/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-","category":"filesystem","line_end":29,"severity":"high","line_start":29},{"id":"filesystem:SKILL.md:30:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudbase/clou","category":"filesystem","line_end":30,"severity":"high","line_start":30},{"id":"filesystem:SKILL.md:477:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"if (!/^1[3-9]\\d{9}$/.test(phone)) return alert('Invalid phone')","category":"filesystem","line_end":477,"severity":"medium","line_start":477},{"id":"blocker:SKILL.md:45:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Reusing this flow in Flutter, React Native, or native iOS/Android code.","category":"blocker","line_end":45,"severity":"low","line_start":45},{"id":"blocker:SKILL.md:51:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Treating `auth.getUser()` or deprecated `auth.getLoginState()` as proof of real login.** When th","category":"blocker","line_end":51,"severity":"low","line_start":51},{"id":"blocker:SKILL.md:90:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Treat CloudBase Web Auth as **Supabase-like**, not “every `supabase-js` auth example is valid unch","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"blocker:SKILL.md:99:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **`accessKey` triggers automatic anonymous session creation** — the deprecated `auth.getLoginState","category":"blocker","line_end":99,"severity":"low","line_start":99},{"id":"blocker:SKILL.md:155:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// data.user.id is the uid; data.session contains the active session","category":"blocker","line_end":155,"severity":"low","line_start":155},{"id":"blocker:SKILL.md:156:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"const uid = data.user.id","category":"blocker","line_end":156,"severity":"low","line_start":156},{"id":"blocker:SKILL.md:169:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// Why: getLoginState() returns an object with uid even when only accessKey is","category":"blocker","line_end":169,"severity":"low","line_start":169},{"id":"blocker:SKILL.md:201:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// ❌ Do NOT use auth.getUser(), !!loginState, or !!loginState.uid as auth checks","category":"blocker","line_end":201,"severity":"low","line_start":201},{"id":"blocker:SKILL.md:249:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// Login succeeded — data.user.id is the uid","category":"blocker","line_end":249,"severity":"low","line_start":249},{"id":"blocker:SKILL.md:477:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"if (!/^1[3-9]\\d{9}$/.test(phone)) return alert('Invalid phone')","category":"blocker","line_end":477,"severity":"low","line_start":477},{"id":"blocker:SKILL.md:96:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- If the task gives accounts like `admin`, `editor`, or another plain string without `@`, treat it a","category":"blocker","line_end":97,"severity":"low","line_start":96}],"finding_verdicts":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:10 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:12 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:13 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:15 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:21 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:25 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:29 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:30 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:35 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:46 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:47 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:48 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:49 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:50 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:51 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:52 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:54 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:58 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:59 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:65 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:66 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:68 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:69 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:70 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:71 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:72 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:75 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:76 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:77 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:79 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:83 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:84 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:88 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:89 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:90 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:91 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:92 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:93 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:94 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:95 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:96 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:97 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:98 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:99 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:100 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:101 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:105 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:119 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:121 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:128 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:129 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:130 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:131 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:134 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:137 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:138 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:141 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:145 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:146 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:163 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:166 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:202 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:206 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:209 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:227 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:229 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:233 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:252:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:252 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:254 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:256 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:280 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:284 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:287 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:288 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:293 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:296 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:297 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:298 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:299 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:313 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:316 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:317 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:326 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:331 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:334 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:340 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:343:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:343 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:350:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:350 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:356 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:417:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:417 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:429 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:435 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:467 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:473:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:473 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","reason":"The flagged text at SKILL.md:506 is Markdown inline code, a fenced JavaScript example, or a template literal. It does not execute Ruby or shell backticks.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:328:fetch-api-call","reason":"The fetch call at SKILL.md:328 is a documentation example using a relative application endpoint. It does not send data to an external host.","verdict":"false_positive","confidence":0.88},{"id":"network:SKILL.md:416:fetch-api-call","reason":"The fetch call at SKILL.md:416 is a documentation example using a relative application endpoint. It does not send data to an external host.","verdict":"false_positive","confidence":0.88},{"id":"network:SKILL.md:12:hardcoded-url","reason":"The URL at SKILL.md:12 is a public CloudBase source or console reference for setup guidance. No automatic request or data exfiltration is implemented.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL at SKILL.md:13 is a public CloudBase source or console reference for setup guidance. No automatic request or data exfiltration is implemented.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:29:hardcoded-url","reason":"The URL at SKILL.md:29 is a public CloudBase source or console reference for setup guidance. No automatic request or data exfiltration is implemented.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:30:hardcoded-url","reason":"The URL at SKILL.md:30 is a public CloudBase source or console reference for setup guidance. No automatic request or data exfiltration is implemented.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:84:hardcoded-url","reason":"The URL at SKILL.md:84 is a public CloudBase source or console reference for setup guidance. No automatic request or data exfiltration is implemented.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:50:email-sending-capability","reason":"The line tells users to confirm SMTP readiness before email signup. It does not implement email sending, bulk messaging, or credential exfiltration.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:29:path-traversal-sequence","reason":"The ../ reference at SKILL.md:29 points to a named sibling skill document with a public fallback URL. It is not dynamic path traversal or sensitive file access.","verdict":"false_positive","confidence":0.82},{"id":"filesystem:SKILL.md:30:path-traversal-sequence","reason":"The ../ reference at SKILL.md:30 points to a named sibling skill document with a public fallback URL. It is not dynamic path traversal or sensitive file access.","verdict":"false_positive","confidence":0.82},{"id":"filesystem:SKILL.md:477:hidden-file-access","reason":"The flagged text at SKILL.md:477 is a phone-number validation regex. It does not reference hidden files or filesystem paths.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:45:system-reconnaissance","reason":"The flagged text at SKILL.md:45 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:51:system-reconnaissance","reason":"The flagged text at SKILL.md:51 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:90:system-reconnaissance","reason":"The flagged text at SKILL.md:90 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:99:system-reconnaissance","reason":"The flagged text at SKILL.md:99 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:155:system-reconnaissance","reason":"The flagged text at SKILL.md:155 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:156:system-reconnaissance","reason":"The flagged text at SKILL.md:156 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:169:system-reconnaissance","reason":"The flagged text at SKILL.md:169 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:201:system-reconnaissance","reason":"The flagged text at SKILL.md:201 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:249:system-reconnaissance","reason":"The flagged text at SKILL.md:249 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:477:system-reconnaissance","reason":"The flagged text at SKILL.md:477 discusses Web authentication behavior or user identifiers. It does not collect host, OS, process, or environment details.","verdict":"false_positive","confidence":0.92},{"id":"blocker:SKILL.md:96:network-reconnaissance","reason":"The line classifies sample account identifiers such as usernames and email-like strings. It does not request host, port, service, or network enumeration.","verdict":"false_positive","confidence":0.93}],"semantic_findings":[{"title":"Automatic Auth Provider Changes Need Confirmation","severity":"medium","locations":[{"file":"SKILL.md","line_end":84,"line_start":83},{"file":"SKILL.md","line_end":128,"line_start":128},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":287,"line_start":287},{"file":"SKILL.md","line_end":296,"line_start":296}],"confidence":0.78,"description":"The skill repeatedly instructs agents to automatically use auth-tool-cloudbase or manageAppAuth to enable login providers, including SMS, email, anonymous, and OAuth. Changing authentication provider settings can expand access paths if done without explicit project owner approval.","confidence_reasoning":"The instruction pattern is explicit and repeated, but it is related to legitimate auth setup. The risk is configuration change without user confirmation, not malicious code execution."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}