{"data":{"skill":{"slug":"tencentcloudbase-cloud-functions","name":"cloud-functions","icon":"📦","repo":"https://github.com/tencentcloudbase/skills/tree/main/skills/cloud-functions","status":"approved","author":"tencentcloudbase","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"060fe436-2915-4a9d-9cad-fa3f4e5e9449","skill_id":"9adeb2a4-36bf-41e0-98e3-52fa7f47725f","version":1,"content_hash":"v2:24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec:ea7fdcf4752edb8d0c8b19ac1fe3203b57072e400b06e2fba83ce5b76798c4b1:7f63efdf7f6bfb5f5ff521739120863cac3d0e01a7a6fb0ab043246c71b5c40f:1aea6cf4c070e2447d0848520f91c241","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The static findings are false positives from Markdown documentation, CloudBase endpoint examples, and runtime skeletons. I found no prompt injection, secret exfiltration, unauthorized command execution, or malicious intent in the reviewed files.","remediation":[],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"references.md","line_end":56,"line_start":56},{"file":"references/event-functions.md","line_end":3,"line_start":3},{"file":"references/http-functions.md","line_end":259,"line_start":259},{"file":"references/http-functions.md","line_end":288,"line_start":288},{"file":"references/http-functions.md","line_end":132,"line_start":132},{"file":"references/http-functions.md","line_end":133,"line_start":133},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":101,"line_start":101}]},{"factor":"network","evidence":[{"file":"references/event-functions.md","line_end":108,"line_start":108},{"file":"references/http-functions.md","line_end":105,"line_start":105},{"file":"references/http-functions.md","line_end":215,"line_start":215},{"file":"references/http-functions.md","line_end":339,"line_start":339},{"file":"references/http-functions.md","line_end":105,"line_start":105},{"file":"references/http-functions.md","line_end":215,"line_start":215},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":245,"line_start":245},{"file":"SKILL.md","line_end":312,"line_start":312},{"file":"SKILL.md","line_end":245,"line_start":245}]},{"factor":"env_access","evidence":[{"file":"references/event-functions.md","line_end":140,"line_start":140},{"file":"references/event-functions.md","line_end":141,"line_start":141},{"file":"references/event-functions.md","line_end":140,"line_start":140},{"file":"references/event-functions.md","line_end":141,"line_start":141},{"file":"references/event-functions.md","line_end":140,"line_start":140},{"file":"references/http-functions-custom-image.md","line_end":151,"line_start":151},{"file":"references/http-functions-custom-image.md","line_end":157,"line_start":157},{"file":"references/http-functions-custom-image.md","line_end":172,"line_start":172}]},{"factor":"filesystem","evidence":[{"file":"references/http-functions-custom-image.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43}]},{"factor":"external_commands","evidence":[{"file":"references/http-functions.md","line_end":371,"line_start":370},{"file":"references/http-functions.md","line_end":382,"line_start":380},{"file":"references/http-functions.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":105,"line_start":105},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":128,"line_start":128}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":7,"total_lines":1354,"audit_model":"codex","audited_at":"2026-07-09T15:33:16.878+00:00","created_at":"2026-07-09T17:30:21.820236+00:00","static_findings":[{"id":"scripts:references.md:56:dynamic-function-constructor","file":"references.md","pattern":"Dynamic function constructor","snippet":"- Custom Image HTTP Function (`Runtime: CustomImage`) still listens on the fixed port `9000` and is ","category":"scripts","line_end":56,"severity":"high","line_start":56},{"id":"scripts:references/event-functions.md:3:dynamic-function-constructor","file":"references/event-functions.md","pattern":"Dynamic function constructor","snippet":"Use this reference when the task is clearly about an Event Function (`exports.main(event, context)`)","category":"scripts","line_end":3,"severity":"high","line_start":3},{"id":"network:references/event-functions.md:108:hardcoded-url","file":"references/event-functions.md","pattern":"Hardcoded URL","snippet":"https://{envId}.api.tcloudbasegateway.com/v1/functions/{functionName}","category":"network","line_end":108,"severity":"low","line_start":108},{"id":"env_access:references/event-functions.md:140:environment-variable-access-dot-notation","file":"references/event-functions.md","pattern":"Environment variable access (dot notation)","snippet":"const apiKey = process.env.API_KEY;","category":"env_access","line_end":140,"severity":"low","line_start":140},{"id":"env_access:references/event-functions.md:141:environment-variable-access-dot-notation","file":"references/event-functions.md","pattern":"Environment variable access (dot notation)","snippet":"const envId = process.env.ENV_ID;","category":"env_access","line_end":141,"severity":"low","line_start":141},{"id":"env_access:references/event-functions.md:140:environment-variable-object","file":"references/event-functions.md","pattern":"Environment variable object","snippet":"const apiKey = process.env.API_KEY;","category":"env_access","line_end":140,"severity":"low","line_start":140},{"id":"env_access:references/event-functions.md:141:environment-variable-object","file":"references/event-functions.md","pattern":"Environment variable object","snippet":"const envId = process.env.ENV_ID;","category":"env_access","line_end":141,"severity":"low","line_start":141},{"id":"env_access:references/event-functions.md:140:generic-api-secret-keys","file":"references/event-functions.md","pattern":"Generic API/secret keys","snippet":"const apiKey = process.env.API_KEY;","category":"env_access","line_end":140,"severity":"high","line_start":140},{"id":"sensitive:references/event-functions.md:140:environment-file-access","file":"references/event-functions.md","pattern":"Environment file access","snippet":"const apiKey = process.env.API_KEY;","category":"sensitive","line_end":140,"severity":"high","line_start":140},{"id":"sensitive:references/event-functions.md:141:environment-file-access","file":"references/event-functions.md","pattern":"Environment file access","snippet":"const envId = process.env.ENV_ID;","category":"sensitive","line_end":141,"severity":"high","line_start":141},{"id":"filesystem:references/http-functions-custom-image.md:111:path-traversal-sequence","file":"references/http-functions-custom-image.md","pattern":"Path traversal sequence","snippet":"zip -r ../my-app.zip .","category":"filesystem","line_end":111,"severity":"high","line_start":111},{"id":"env_access:references/http-functions-custom-image.md:151:generic-api-secret-keys","file":"references/http-functions-custom-image.md","pattern":"Generic API/secret keys","snippet":"- The build container injects STS credentials as `$API_SECRET_ID` / `$API_SECRET_KEY` / `$API_TOKEN`","category":"env_access","line_end":151,"severity":"high","line_start":151},{"id":"env_access:references/http-functions-custom-image.md:157:generic-api-secret-keys","file":"references/http-functions-custom-image.md","pattern":"Generic API/secret keys","snippet":"- Never print `$API_SECRET_*` / `$API_TOKEN` or pass them outside the container.","category":"env_access","line_end":157,"severity":"high","line_start":157},{"id":"env_access:references/http-functions-custom-image.md:172:generic-api-secret-keys","file":"references/http-functions-custom-image.md","pattern":"Generic API/secret keys","snippet":"| `$API_SECRET_ID` `$API_SECRET_KEY` `$API_TOKEN` | STS credentials (never print) |","category":"env_access","line_end":172,"severity":"high","line_start":172},{"id":"blocker:references/http-functions-custom-image.md:96:system-reconnaissance","file":"references/http-functions-custom-image.md","pattern":"System reconnaissance","snippet":"| `registryId` | enterprise only | TCR instance id `tcr-xxxxxxxx`. Required when `imageType=enterpri","category":"blocker","line_end":96,"severity":"low","line_start":96},{"id":"blocker:references/http-functions-custom-image.md:169:system-reconnaissance","file":"references/http-functions-custom-image.md","pattern":"System reconnaissance","snippet":"| `$CLOUDBASE_ENV_ID` | Environment id |","category":"blocker","line_end":169,"severity":"low","line_start":169},{"id":"scripts:references/http-functions.md:259:dynamic-function-constructor","file":"references/http-functions.md","pattern":"Dynamic function constructor","snippet":"This document covers the **managed-runtime** HTTP Function (ships `scf_bootstrap`, runs on a languag","category":"scripts","line_end":259,"severity":"high","line_start":259},{"id":"scripts:references/http-functions.md:288:dynamic-function-constructor","file":"references/http-functions.md","pattern":"Dynamic function constructor","snippet":"- `type: \"HTTP\"` — marks the function as an HTTP Function (not an Event Function).","category":"scripts","line_end":288,"severity":"high","line_start":288},{"id":"scripts:references/http-functions.md:132:dynamic-require-with-variable","file":"references/http-functions.md","pattern":"Dynamic require with variable","snippet":"- Choose one Node.js module system and keep it consistent. For simple HTTP Functions, CommonJS is th","category":"scripts","line_end":132,"severity":"medium","line_start":132},{"id":"scripts:references/http-functions.md:133:dynamic-require-with-variable","file":"references/http-functions.md","pattern":"Dynamic require with variable","snippet":"- If you intentionally use ES Modules, use `import ...` consistently and do not rely on CommonJS-onl","category":"scripts","line_end":133,"severity":"medium","line_start":133},{"id":"external_commands:references/http-functions.md:370:ruby-shell-backtick-execution","file":"references/http-functions.md","pattern":"Ruby/shell backtick execution","snippet":"res.write(`data: ${JSON.stringify({ content: \"Hello\" })}\\n\\n`);","category":"external_commands","line_end":371,"severity":"medium","line_start":370},{"id":"external_commands:references/http-functions.md:380:ruby-shell-backtick-execution","file":"references/http-functions.md","pattern":"Ruby/shell backtick execution","snippet":"ws.on(\"message\", (message) => ws.send(`Echo: ${message}`));","category":"external_commands","line_end":382,"severity":"medium","line_start":380},{"id":"external_commands:references/http-functions.md:28:unix-shell-invocation","file":"references/http-functions.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"network:references/http-functions.md:105:hardcoded-url","file":"references/http-functions.md","pattern":"Hardcoded URL","snippet":"const url = new URL(req.url || \"/\", \"http://127.0.0.1\");","category":"network","line_end":105,"severity":"low","line_start":105},{"id":"network:references/http-functions.md:215:hardcoded-url","file":"references/http-functions.md","pattern":"Hardcoded URL","snippet":"const url = new URL(req.url || \"/\", \"http://127.0.0.1\");","category":"network","line_end":215,"severity":"low","line_start":215},{"id":"network:references/http-functions.md:339:hardcoded-url","file":"references/http-functions.md","pattern":"Hardcoded URL","snippet":"curl -L \"https://{envId}.api.tcloudbasegateway.com/v1/functions/{name}?webfn=true\" \\","category":"network","line_end":339,"severity":"low","line_start":339},{"id":"network:references/http-functions.md:105:hardcoded-ip-address","file":"references/http-functions.md","pattern":"Hardcoded IP address","snippet":"const url = new URL(req.url || \"/\", \"http://127.0.0.1\");","category":"network","line_end":105,"severity":"medium","line_start":105},{"id":"network:references/http-functions.md:215:hardcoded-ip-address","file":"references/http-functions.md","pattern":"Hardcoded IP address","snippet":"const url = new URL(req.url || \"/\", \"http://127.0.0.1\");","category":"network","line_end":215,"severity":"medium","line_start":215},{"id":"blocker:references/http-functions.md:91:system-reconnaissance","file":"references/http-functions.md","pattern":"System reconnaissance","snippet":"reject(new Error(\"Invalid JSON body\"));","category":"blocker","line_end":91,"severity":"low","line_start":91},{"id":"blocker:references/http-functions.md:201:system-reconnaissance","file":"references/http-functions.md","pattern":"System reconnaissance","snippet":"reject(new Error(\"Invalid JSON body\"));","category":"blocker","line_end":201,"severity":"low","line_start":201},{"id":"blocker:references/http-functions.md:290:system-reconnaissance","file":"references/http-functions.md","pattern":"System reconnaissance","snippet":"- `runtime` — the execution runtime. Must match the `scf_bootstrap` binary path. Default is `\"Nodejs","category":"blocker","line_end":290,"severity":"low","line_start":290},{"id":"scripts:SKILL.md:100:dynamic-require-with-variable","file":"SKILL.md","pattern":"Dynamic require with variable","snippet":"- For Node.js HTTP Functions, choose one module system up front and keep it consistent. Default to C","category":"scripts","line_end":100,"severity":"medium","line_start":100},{"id":"scripts:SKILL.md:101:dynamic-require-with-variable","file":"SKILL.md","pattern":"Dynamic require with variable","snippet":"- If you do choose ES Modules (`\"type\": \"module\"` + `import ...`), do not mix in CommonJS-only globa","category":"scripts","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If this environment only installed the current skill, start from the CloudBase main entry and use th","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Keep local `references/...` paths for files that ship with the current skill directory. When this fi","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Change Safety Protocol: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Deployment Gate: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The request mentions function runtime, function logs, `scf_bootstrap`, function triggers, or funct","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The task mentions `manageFunctions`, `queryFunctions`, `manageGateway`, or legacy function-tool na","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The task might require `callCloudApi` as a fallback for logs or gateway setup.","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Detailed reference routing -> `./references.md`","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Auth setup or provider-related backend work -> `../auth-tool/SKILL.md` (standalone fallback: `http","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CloudBase Integration Center generated WeChat Pay or Official Account functions -> `../cloudbase-w","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- AI in functions -> `../ai-model-nodejs/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/c","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Long-lived container services or Agent runtimes -> `../cloudrun-development/SKILL.md` (standalone ","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Calling CloudBase official platform APIs from a client or script -> `../http-api/SKILL.md` (standa","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Creating Integration Center instances through guessed APIs. For WeChat Pay or Official Account gen","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Tasks that the CloudBase JS SDK can handle directly** — simple data reads/writes, leaderboards, ","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Mixing Event Function code shape (`exports.main(event, context)`) with HTTP Function code shape (`","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Assuming `db.collection(\"name\").add(...)` will create a missing document-database collection autom","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Forgetting that HTTP Functions must ship `scf_bootstrap`, listen on port `9000`, and include depen","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Forgetting to configure function security rules after creating an HTTP Function. Default rules rej","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Mismatching the `scf_bootstrap` Node.js binary path with the function runtime (e.g. using `/var/la","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For Custom Image HTTP Functions: forgetting that TCR, the CloudApp build, and SCF must be in the s","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Assuming MCP covers the whole image pipeline. `manageFunctions` covers SCF image deploy (Stage B) ","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Making code or configuration changes without first following the Change Safety Protocol (`cloudbas","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Exposing functions publicly or deploying without first completing the checks in `cloudbase-platfor","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **HTTP Functions**: standard web services for HTTP endpoints, SSE, or WebSocket workloads. By defa","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the request is for SDK calls, timers, or event-driven workflows, write an **Event Function** wi","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the request is for REST APIs, browser-facing endpoints, SSE, or WebSocket, write an **HTTP Func","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For Node.js HTTP Functions, default to the native `http` module unless the user explicitly asks fo","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the HTTP Function needs custom system libraries or an arbitrary runtime but should still be SCF","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Do not write an HTTP Function as `exports.main(event, context)`. That is the Event Function contra","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Treat the function as a standard web server process that must listen on port `9000`.","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- With Node.js, prefer `http.createServer((req, res) => { ... })` by default so the runtime contract","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- With the Node.js native `http` module, do not assume Express-style helpers exist. `req.body`, `req","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For Node.js HTTP Functions, choose one module system up front and keep it consistent. Default to C","category":"external_commands","line_end":100,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If you do choose ES Modules (`\"type\": \"module\"` + `import ...`), do not mix in CommonJS-only globa","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- With the native `http` module, parse `req.url` yourself with `new URL(...)`, collect the request b","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Return responses explicitly with `res.writeHead(...)` and `res.end(...)`, including `Content-Type`","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Respond to `OPTIONS` preflight with `200` and CORS headers","category":"external_commands","line_end":105,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Include `Access-Control-Allow-Origin: *` (or specific origin) on all responses","category":"external_commands","line_end":106,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Include `Access-Control-Allow-Methods: GET, POST, OPTIONS` as needed","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Include `Access-Control-Allow-Headers: Content-Type` for JSON requests","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Keep routing and method handling explicit. Unknown paths should return `404`, and known paths with","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Needs custom system libraries / arbitrary runtime, but still SCF request-driven + scale-to-zero? |","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Event Function -> `exports.main(event, context)`","category":"external_commands","line_end":127,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- HTTP Function -> web server on port `9000`","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Reads -> `queryFunctions`, `queryGateway`","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Writes -> `manageFunctions`, `manageGateway`","category":"external_commands","line_end":133,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `manageFunctions(action=\"createFunction\")` for creation","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `manageFunctions(action=\"updateFunctionCode\")` for code updates","category":"external_commands","line_end":138,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `manageFunctions(action=\"updateFunctionConfig\")` for config updates (timeout, memorySize, envV","category":"external_commands","line_end":139,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For a Custom Image HTTP Function, call `manageFunctions(action=\"createFunction\")` with `func.runti","category":"external_commands","line_end":140,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Keep `functionRootPath` as the directory that directly contains function folders (e.g., `cloudfunc","category":"external_commands","line_end":141,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Prefer MCP tools over CLI** — when MCP tools are available, use `manageFunctions` and `queryFunc","category":"external_commands","line_end":142,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For batch updates (multiple functions), call `manageFunctions(action=\"updateFunctionConfig\")` indi","category":"external_commands","line_end":144,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If a task falls back to `callCloudApi`, first check the official docs or knowledge-base entry for ","category":"external_commands","line_end":147,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Event Function details -> `./references/event-functions.md`","category":"external_commands","line_end":152,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- HTTP Function details -> `./references/http-functions.md`","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- HTTP Function from a container image (`Runtime: CustomImage`, TCR image pipeline) -> `./references","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Logs, gateway, env vars, and legacy mappings -> `./references/operations-and-config.md`","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `db.collection(\"feedback\").add(...)` only inserts into an existing collection; it does not auto-cr","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Entry shape | `exports.main(event, context)` | web server with `req` / `res` |","category":"external_commands","line_end":168,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Port | No port | Must listen on `9000` |","category":"external_commands","line_end":169,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `scf_bootstrap` | Not required | Required |","category":"external_commands","line_end":170,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Dependencies | Auto-installed from `package.json` | Must be packaged with function code |","category":"external_commands","line_end":171,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`cloudfunctions/hello-event/index.js`","category":"external_commands","line_end":178,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":188,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":190,"severity":"medium","line_start":188},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`cloudfunctions/hello-event/package.json`","category":"external_commands","line_end":192,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":197,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":201,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`cloudfunctions/hello-http/index.js`","category":"external_commands","line_end":203,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":258,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":260,"severity":"medium","line_start":258},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For a more complete example with routing, method checks, and error handling, see `./references/http-","category":"external_commands","line_end":262,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`cloudfunctions/hello-http/scf_bootstrap`","category":"external_commands","line_end":264,"severity":"medium","line_start":262},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":267,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":269,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The `scf_bootstrap` binary path must match the runtime — see the full mapping table in `./references","category":"external_commands","line_end":269,"severity":"medium","line_start":269},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`cloudfunctions/hello-http/package.json`","category":"external_commands","line_end":273,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":278,"severity":"medium","line_start":273},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":284,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryFunctions(action=\"listFunctions\"|\"getFunctionDetail\")`","category":"external_commands","line_end":285,"severity":"medium","line_start":284},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `manageFunctions(action=\"createFunction\")`","category":"external_commands","line_end":286,"severity":"medium","line_start":285},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `manageFunctions(action=\"updateFunctionCode\")`","category":"external_commands","line_end":287,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `manageFunctions(action=\"updateFunctionConfig\")`","category":"external_commands","line_end":291,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Query function logs** — use the `queryFunctions` tool:","category":"external_commands","line_end":293,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryFunctions(action=\"listFunctionLogs\", functionName=\"xxx\")` — list execution logs of a specifi","category":"external_commands","line_end":294,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryFunctions(action=\"getFunctionLogDetail\", requestId=\"xxx\")` — fetch the detail of one log ent","category":"external_commands","line_end":296,"severity":"medium","line_start":294},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**`queryFunctions` vs `queryLogs`**:","category":"external_commands","line_end":296,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryFunctions` queries execution logs of a single cloud function and requires `functionName`","category":"external_commands","line_end":297,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryLogs` searches CLS (cross-service log aggregation) using CLS query syntax","category":"external_commands","line_end":301,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":310,"severity":"medium","line_start":301},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":312,"severity":"medium","line_start":310},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`queryLogs` `queryString` follows CLS syntax (see https://cloud.tencent.com/document/api/876/128127)","category":"external_commands","line_end":312,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Function logs: `(src:app OR src:system) AND log:\"START RequestId\"`","category":"external_commands","line_end":314,"severity":"medium","line_start":313},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Aggregated function request status: `| select request_id, max(status_code) as status where ((reque","category":"external_commands","line_end":315,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Document database (NoSQL): `module:database`","category":"external_commands","line_end":316,"severity":"medium","line_start":315},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Document database slow-query events: `module:database AND eventType:(MongoSlowQuery)` — `MongoSlow","category":"external_commands","line_end":316,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Relational database (MySQL): `module:rdb`","category":"external_commands","line_end":318,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Relational database (MySQL) events: `module:rdb AND eventType:(MysqlFreeze OR MysqlRecover OR Mysq","category":"external_commands","line_end":318,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Workflow (approval flow): `module:workflow`","category":"external_commands","line_end":320,"severity":"medium","line_start":319},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Data model: `module:model`","category":"external_commands","line_end":321,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- User permissions: `module:auth`","category":"external_commands","line_end":322,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- LLM trace logs: `module:llm AND logType:llm-tracelog`","category":"external_commands","line_end":323,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Gateway access logs: `logType:accesslog`","category":"external_commands","line_end":324,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- App publish / delete events: `module:app AND eventType:(AppProdPub OR AppProdDel)` — `AppProdPub` ","category":"external_commands","line_end":324,"severity":"medium","line_start":324},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If these are unavailable, read `./references/operations-and-config.md` before any `callCloudApi` fal","category":"external_commands","line_end":326,"severity":"medium","line_start":326},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `queryGateway(action=\"getAccess\")`","category":"external_commands","line_end":331,"severity":"medium","line_start":330},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `manageGateway(action=\"createAccess\")`","category":"external_commands","line_end":332,"severity":"medium","line_start":331},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If gateway operations need raw cloud API fallback, read `./references/operations-and-config.md` fi","category":"external_commands","line_end":336,"severity":"medium","line_start":332},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `cloudrun-development` -> container services, long-lived runtimes, Agent hosting","category":"external_commands","line_end":337,"severity":"medium","line_start":336},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `http-api` -> raw CloudBase HTTP API invocation patterns","category":"external_commands","line_end":338,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `cloudbase-platform` -> general CloudBase platform decisions","category":"external_commands","line_end":339,"severity":"medium","line_start":338},{"id":"external_commands:SKILL.md:265:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":265,"severity":"medium","line_start":265},{"id":"network:SKILL.md:12:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:18:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Change Safety Protocol: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"network:SKILL.md:19:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Deployment Gate: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:SKILL.md:39:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Auth setup or provider-related backend work -> `../auth-tool/SKILL.md` (standalone fallback: `http","category":"network","line_end":39,"severity":"low","line_start":39},{"id":"network:SKILL.md:40:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- CloudBase Integration Center generated WeChat Pay or Official Account functions -> `../cloudbase-w","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"network:SKILL.md:41:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- AI in functions -> `../ai-model-nodejs/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/c","category":"network","line_end":41,"severity":"low","line_start":41},{"id":"network:SKILL.md:42:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Long-lived container services or Agent runtimes -> `../cloudrun-development/SKILL.md` (standalone ","category":"network","line_end":42,"severity":"low","line_start":42},{"id":"network:SKILL.md:43:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Calling CloudBase official platform APIs from a client or script -> `../http-api/SKILL.md` (standa","category":"network","line_end":43,"severity":"low","line_start":43},{"id":"network:SKILL.md:245:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"const url = new URL(req.url || \"/\", \"http://127.0.0.1\");","category":"network","line_end":245,"severity":"low","line_start":245},{"id":"network:SKILL.md:312:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"`queryLogs` `queryString` follows CLS syntax (see https://cloud.tencent.com/document/api/876/128127)","category":"network","line_end":312,"severity":"low","line_start":312},{"id":"network:SKILL.md:245:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"const url = new URL(req.url || \"/\", \"http://127.0.0.1\");","category":"network","line_end":245,"severity":"medium","line_start":245},{"id":"filesystem:SKILL.md:39:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Auth setup or provider-related backend work -> `../auth-tool/SKILL.md` (standalone fallback: `http","category":"filesystem","line_end":39,"severity":"high","line_start":39},{"id":"filesystem:SKILL.md:40:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- CloudBase Integration Center generated WeChat Pay or Official Account functions -> `../cloudbase-w","category":"filesystem","line_end":40,"severity":"high","line_start":40},{"id":"filesystem:SKILL.md:41:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- AI in functions -> `../ai-model-nodejs/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/c","category":"filesystem","line_end":41,"severity":"high","line_start":41},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Long-lived container services or Agent runtimes -> `../cloudrun-development/SKILL.md` (standalone ","category":"filesystem","line_end":42,"severity":"high","line_start":42},{"id":"filesystem:SKILL.md:43:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Calling CloudBase official platform APIs from a client or script -> `../http-api/SKILL.md` (standa","category":"filesystem","line_end":43,"severity":"high","line_start":43},{"id":"blocker:SKILL.md:305:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// Inspect the log detail for a specific request id","category":"blocker","line_end":306,"severity":"low","line_start":305}],"finding_verdicts":[{"id":"scripts:references.md:56:dynamic-function-constructor","reason":"This is Markdown prose using the CloudBase term Function or a handler signature. It does not call Function() or construct executable code.","verdict":"false_positive","confidence":0.97},{"id":"scripts:references/event-functions.md:3:dynamic-function-constructor","reason":"This is Markdown prose using the CloudBase term Function or a handler signature. It does not call Function() or construct executable code.","verdict":"false_positive","confidence":0.97},{"id":"network:references/event-functions.md:108:hardcoded-url","reason":"This is a documented CloudBase endpoint template for function invocation. It is not a hidden callback or data exfiltration URL.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/event-functions.md:140:environment-variable-access-dot-notation","reason":"The environment variable access appears in a small example that checks configuration values. It does not print or transmit secret contents.","verdict":"false_positive","confidence":0.93},{"id":"env_access:references/event-functions.md:141:environment-variable-access-dot-notation","reason":"The environment variable access appears in a small example that checks configuration values. It does not print or transmit secret contents.","verdict":"false_positive","confidence":0.93},{"id":"env_access:references/event-functions.md:140:environment-variable-object","reason":"The environment variable access appears in a small example that checks configuration values. It does not print or transmit secret contents.","verdict":"false_positive","confidence":0.93},{"id":"env_access:references/event-functions.md:141:environment-variable-object","reason":"The environment variable access appears in a small example that checks configuration values. It does not print or transmit secret contents.","verdict":"false_positive","confidence":0.93},{"id":"env_access:references/event-functions.md:140:generic-api-secret-keys","reason":"The API key name appears in an environment-variable example that returns only a boolean existence check. No secret value is exposed.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:references/event-functions.md:140:environment-file-access","reason":"The process.env reference is an environment-variable example, not file-system access to a .env file. It does not read or disclose a secret file.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:references/event-functions.md:141:environment-file-access","reason":"The process.env reference is an environment-variable example, not file-system access to a .env file. It does not read or disclose a secret file.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/http-functions-custom-image.md:111:path-traversal-sequence","reason":"The relative path is a fixed archive output location in packaging instructions. It is not user-controlled traversal or arbitrary file access.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/http-functions-custom-image.md:151:generic-api-secret-keys","reason":"The text warns about temporary credentials and explicitly says not to print or pass them outside the container. It is defensive guidance, not credential theft.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/http-functions-custom-image.md:157:generic-api-secret-keys","reason":"The text warns about temporary credentials and explicitly says not to print or pass them outside the container. It is defensive guidance, not credential theft.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/http-functions-custom-image.md:172:generic-api-secret-keys","reason":"The text warns about temporary credentials and explicitly says not to print or pass them outside the container. It is defensive guidance, not credential theft.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/http-functions-custom-image.md:96:system-reconnaissance","reason":"The snippet is a CloudBase configuration field, error string, or log-query example. It does not gather host or account reconnaissance data.","verdict":"false_positive","confidence":0.92},{"id":"blocker:references/http-functions-custom-image.md:169:system-reconnaissance","reason":"The snippet is a CloudBase configuration field, error string, or log-query example. It does not gather host or account reconnaissance data.","verdict":"false_positive","confidence":0.92},{"id":"scripts:references/http-functions.md:259:dynamic-function-constructor","reason":"This is Markdown prose using the CloudBase term Function or a handler signature. It does not call Function() or construct executable code.","verdict":"false_positive","confidence":0.97},{"id":"scripts:references/http-functions.md:288:dynamic-function-constructor","reason":"This is Markdown prose using the CloudBase term Function or a handler signature. It does not call Function() or construct executable code.","verdict":"false_positive","confidence":0.97},{"id":"scripts:references/http-functions.md:132:dynamic-require-with-variable","reason":"The line documents CommonJS and ES Module choices with literal require(...) text. It is not a variable-controlled require call.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/http-functions.md:133:dynamic-require-with-variable","reason":"The line documents CommonJS and ES Module choices with literal require(...) text. It is not a variable-controlled require call.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/http-functions.md:370:ruby-shell-backtick-execution","reason":"The backticks are JavaScript template literals inside an HTTP example. They are not Ruby shell backticks or command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/http-functions.md:380:ruby-shell-backtick-execution","reason":"The backticks are JavaScript template literals inside an HTTP example. They are not Ruby shell backticks or command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/http-functions.md:28:unix-shell-invocation","reason":"The shebang is part of a documented scf_bootstrap example for a CloudBase HTTP Function package. The skill itself does not execute it.","verdict":"false_positive","confidence":0.95},{"id":"network:references/http-functions.md:105:hardcoded-url","reason":"The localhost URL is a base value for parsing req.url in an example. It does not initiate an outbound network request.","verdict":"false_positive","confidence":0.98},{"id":"network:references/http-functions.md:215:hardcoded-url","reason":"The localhost URL is a base value for parsing req.url in an example. It does not initiate an outbound network request.","verdict":"false_positive","confidence":0.98},{"id":"network:references/http-functions.md:339:hardcoded-url","reason":"This is a documented CloudBase endpoint template for function invocation. It is not a hidden callback or data exfiltration URL.","verdict":"false_positive","confidence":0.96},{"id":"network:references/http-functions.md:105:hardcoded-ip-address","reason":"The 127.0.0.1 value is used only as a local base URL for parsing request paths. It is not an external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"network:references/http-functions.md:215:hardcoded-ip-address","reason":"The 127.0.0.1 value is used only as a local base URL for parsing request paths. It is not an external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/http-functions.md:91:system-reconnaissance","reason":"The snippet is a CloudBase configuration field, error string, or log-query example. It does not gather host or account reconnaissance data.","verdict":"false_positive","confidence":0.92},{"id":"blocker:references/http-functions.md:201:system-reconnaissance","reason":"The snippet is a CloudBase configuration field, error string, or log-query example. It does not gather host or account reconnaissance data.","verdict":"false_positive","confidence":0.92},{"id":"blocker:references/http-functions.md:290:system-reconnaissance","reason":"The snippet is a CloudBase configuration field, error string, or log-query example. It does not gather host or account reconnaissance data.","verdict":"false_positive","confidence":0.92},{"id":"scripts:SKILL.md:100:dynamic-require-with-variable","reason":"The line documents CommonJS and ES Module choices with literal require(...) text. It is not a variable-controlled require call.","verdict":"false_positive","confidence":0.96},{"id":"scripts:SKILL.md:101:dynamic-require-with-variable","reason":"The line documents CommonJS and ES Module choices with literal require(...) text. It is not a variable-controlled require call.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:269:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:319:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline-code formatting or fenced-code markers in documentation. They do not execute shell commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:265:unix-shell-invocation","reason":"The shebang is part of a documented scf_bootstrap example for a CloudBase HTTP Function package. The skill itself does not execute it.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:12:hardcoded-url","reason":"This is a published source or fallback documentation URL for CloudBase skills. It is not an automatic network request or webhook.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:13:hardcoded-url","reason":"This is a published source or fallback documentation URL for CloudBase skills. It is not an automatic network request or webhook.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:18:hardcoded-url","reason":"This is a published source or fallback documentation URL for CloudBase skills. It is not an automatic network request or webhook.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:19:hardcoded-url","reason":"This is a published source or fallback documentation URL for CloudBase skills. It is not an automatic network request or webhook.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:39:hardcoded-url","reason":"The URL appears in documentation for CloudBase workflow reference. No automatic network call or exfiltration behavior is present.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:40:hardcoded-url","reason":"The URL appears in documentation for CloudBase workflow reference. No automatic network call or exfiltration behavior is present.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:41:hardcoded-url","reason":"This is a published source or fallback documentation URL for CloudBase skills. It is not an automatic network request or webhook.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:42:hardcoded-url","reason":"The URL appears in documentation for CloudBase workflow reference. No automatic network call or exfiltration behavior is present.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:43:hardcoded-url","reason":"The URL appears in documentation for CloudBase workflow reference. No automatic network call or exfiltration behavior is present.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:245:hardcoded-url","reason":"The localhost URL is a base value for parsing req.url in an example. It does not initiate an outbound network request.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:312:hardcoded-url","reason":"This is an official documentation link included for operator reference. The skill does not automatically fetch or post data to it.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:245:hardcoded-ip-address","reason":"The 127.0.0.1 value is used only as a local base URL for parsing request paths. It is not an external endpoint.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:39:path-traversal-sequence","reason":"The ../ path is a Markdown reference to sibling skill documentation. It is not runtime filesystem traversal.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:40:path-traversal-sequence","reason":"The ../ path is a Markdown reference to sibling skill documentation. It is not runtime filesystem traversal.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:41:path-traversal-sequence","reason":"The ../ path is a Markdown reference to sibling skill documentation. It is not runtime filesystem traversal.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","reason":"The ../ path is a Markdown reference to sibling skill documentation. It is not runtime filesystem traversal.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:43:path-traversal-sequence","reason":"The ../ path is a Markdown reference to sibling skill documentation. It is not runtime filesystem traversal.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:305:system-reconnaissance","reason":"The snippet is a CloudBase configuration field, error string, or log-query example. It does not gather host or account reconnaissance data.","verdict":"false_positive","confidence":0.92}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}