{"data":{"skill":{"slug":"tencentcloudbase-cloudbase-document-database-web-sdk","name":"cloudbase-document-database-web-sdk","icon":"📦","repo":"https://github.com/tencentcloudbase/skills/tree/main/skills/no-sql-web-sdk","status":"approved","author":"tencentcloudbase","authorVersion":"2.23.8","skillstoreRevision":1},"audit":{"id":"8b8cadf3-dcaa-4dfd-bb10-c2aa15152c85","skill_id":"dd7752d8-26e0-49b8-b221-ca64c717d4b3","version":2,"content_hash":"v3:24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec:0efc18c6ba16c5e5178d15902b0c7b2b89399ce8868d8122ddff4e4470818353:2231285a8902a966813579abc2cd0a7a0f79da6d909c716f5be30626e2188700:736b696c6c732f74656e63656e74636c6f7564626173652f636c6f7564626173652d646f63756d656e742d64617461626173652d7765622d73646b:c144946d89b5c9121000ecb7d2ccd370","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static findings are false positives from JavaScript examples, Markdown backticks, _id or uid identifiers, and Object.keys usage. I confirmed the SKILL.md raw fallback URLs and parent-directory sibling references because they can load mutable or out-of-scope instructions at runtime. No prompt injection phrases were found in the reviewed files.","remediation":[{"issue":"Mutable remote fallback instructions","severity":"high","suggestion":"Bundle sibling skill references in the package or pin remote URLs to immutable commits with checksums."},{"issue":"Parent-directory sibling skill references","severity":"high","suggestion":"Replace ../ sibling paths with packaged references or explicit marketplace dependencies that are audited together."},{"issue":"Hardcoded raw instruction URLs","severity":"low","suggestion":"Use stable documentation links for user reference only, not runtime instruction loading."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"geolocation.md","line_end":315,"line_start":314},{"file":"pagination.md","line_end":141,"line_start":140},{"file":"pagination.md","line_end":142,"line_start":141},{"file":"security-rules.md","line_end":974,"line_start":972},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":102,"line_start":93},{"file":"SKILL.md","line_end":112,"line_start":102},{"file":"SKILL.md","line_end":113,"line_start":112},{"file":"SKILL.md","line_end":114,"line_start":113},{"file":"SKILL.md","line_end":115,"line_start":114},{"file":"SKILL.md","line_end":116,"line_start":115},{"file":"SKILL.md","line_end":117,"line_start":116},{"file":"SKILL.md","line_end":118,"line_start":117},{"file":"SKILL.md","line_end":126,"line_start":118},{"file":"SKILL.md","line_end":131,"line_start":126},{"file":"SKILL.md","line_end":132,"line_start":131},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":133,"line_start":133},{"file":"SKILL.md","line_end":134,"line_start":134},{"file":"SKILL.md","line_end":139,"line_start":139},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":143,"line_start":143},{"file":"SKILL.md","line_end":153,"line_start":149},{"file":"SKILL.md","line_end":157,"line_start":153},{"file":"SKILL.md","line_end":165,"line_start":157},{"file":"SKILL.md","line_end":169,"line_start":165},{"file":"SKILL.md","line_end":175,"line_start":169},{"file":"SKILL.md","line_end":179,"line_start":175},{"file":"SKILL.md","line_end":183,"line_start":179},{"file":"SKILL.md","line_end":196,"line_start":183}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35}]}],"critical_findings":[],"high_findings":[{"title":"Path traversal sequence","locations":[{"file":"SKILL.md","line_end":33,"line_start":33}],"confidence":0.84,"description":"- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit."},{"title":"Path traversal sequence","locations":[{"file":"SKILL.md","line_end":34,"line_start":34}],"confidence":0.84,"description":"- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit."},{"title":"Path traversal sequence","locations":[{"file":"SKILL.md","line_end":35,"line_start":35}],"confidence":0.84,"description":"- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit."},{"title":"Mutable Remote Instruction Loading","locations":[{"file":"SKILL.md","line_end":15,"line_start":10},{"file":"SKILL.md","line_end":35,"line_start":33}],"confidence":0.9,"description":"SKILL.md directs agents to use published fallback URLs for sibling skills when local references are absent. This can load mutable external instructions outside the audited package.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The instructions explicitly point agents to raw remote SKILL.md files as fallback sources. This is not exfiltration, but it materially expands the instruction trust boundary."}],"medium_findings":[],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":12,"line_start":12}],"confidence":0.78,"description":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":13,"line_start":13}],"confidence":0.78,"description":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":33,"line_start":33}],"confidence":0.78,"description":"- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":34,"line_start":34}],"confidence":0.78,"description":"- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":35,"line_start":35}],"confidence":0.78,"description":"- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package."}],"dangerous_patterns":[],"files_scanned":8,"total_lines":3395,"audit_model":"codex","audited_at":"2026-07-09T16:06:40.723+00:00","created_at":"2026-07-15T09:20:48.799873+00:00","static_findings":[{"id":"blocker:aggregation.md:212:system-reconnaissance","file":"aggregation.md","pattern":"System reconnaissance","snippet":"_id: 0  // Exclude _id from output","category":"blocker","line_end":212,"severity":"low","line_start":212},{"id":"blocker:aggregation.md:313:system-reconnaissance","file":"aggregation.md","pattern":"System reconnaissance","snippet":"4. **Avoid large groups**: Very large groups can impact performance","category":"blocker","line_end":313,"severity":"low","line_start":313},{"id":"blocker:complex-queries.md:96:system-reconnaissance","file":"complex-queries.md","pattern":"System reconnaissance","snippet":"_id: false          // Exclude _id","category":"blocker","line_end":97,"severity":"low","line_start":96},{"id":"sensitive:crud-operations.md:482:sqlite-database-file","file":"crud-operations.md","pattern":"SQLite database file","snippet":"this.db = db;","category":"sensitive","line_end":482,"severity":"medium","line_start":482},{"id":"blocker:crud-operations.md:13:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// Note: _openid is automatically added by SDK, do not include it in the data","category":"blocker","line_end":13,"severity":"low","line_start":13},{"id":"blocker:crud-operations.md:20:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// _openid is automatically populated from authenticated user session","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:crud-operations.md:117:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// Note: Do not include _openid in update data - it cannot be modified","category":"blocker","line_end":117,"severity":"low","line_start":117},{"id":"blocker:crud-operations.md:123:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// _openid cannot be updated and should not be included","category":"blocker","line_end":123,"severity":"low","line_start":123},{"id":"blocker:crud-operations.md:141:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"- For simple owner-only collections, be careful with `.doc(id).update()` when your rule depends on n","category":"blocker","line_end":141,"severity":"low","line_start":141},{"id":"blocker:crud-operations.md:183:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// Note: _openid cannot be updated and should not be included","category":"blocker","line_end":183,"severity":"low","line_start":183},{"id":"blocker:crud-operations.md:188:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// _openid remains unchanged and cannot be modified","category":"blocker","line_end":188,"severity":"low","line_start":188},{"id":"blocker:crud-operations.md:198:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"\"read\": \"auth.uid != null\",","category":"blocker","line_end":198,"severity":"low","line_start":198},{"id":"blocker:crud-operations.md:199:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"\"create\": \"auth.uid != null\",","category":"blocker","line_end":199,"severity":"low","line_start":199},{"id":"blocker:crud-operations.md:200:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"\"update\": \"auth.uid != null && (get('database.user_roles.' + auth.uid).role == 'admin' || doc.author","category":"blocker","line_end":200,"severity":"low","line_start":200},{"id":"blocker:crud-operations.md:201:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"\"delete\": \"auth.uid != null && (get('database.user_roles.' + auth.uid).role == 'admin' || doc.author","category":"blocker","line_end":201,"severity":"low","line_start":201},{"id":"blocker:crud-operations.md:211:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"\"update\": \"auth.uid == doc.authorId\",","category":"blocker","line_end":211,"severity":"low","line_start":211},{"id":"blocker:crud-operations.md:212:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"\"delete\": \"auth.uid == doc.authorId\"","category":"blocker","line_end":212,"severity":"low","line_start":212},{"id":"blocker:crud-operations.md:216:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"This can work for `where({ authorId: auth.uid }).update(...)`, but it is commonly rejected for `.doc","category":"blocker","line_end":216,"severity":"low","line_start":216},{"id":"blocker:crud-operations.md:242:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"Only use `get('database.user_roles.' + auth.uid)` or `get('database.users.' + auth.uid)` when that r","category":"blocker","line_end":242,"severity":"low","line_start":242},{"id":"blocker:crud-operations.md:588:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"console.error('Invalid data provided');","category":"blocker","line_end":588,"severity":"low","line_start":588},{"id":"blocker:crud-operations.md:641:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// Correct: Do not include _openid","category":"blocker","line_end":642,"severity":"low","line_start":641},{"id":"blocker:crud-operations.md:645:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// _openid is automatically added by SDK","category":"blocker","line_end":645,"severity":"low","line_start":645},{"id":"blocker:crud-operations.md:648:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"// Wrong: Including _openid will cause an error","category":"blocker","line_end":648,"severity":"low","line_start":648},{"id":"blocker:crud-operations.md:652:system-reconnaissance","file":"crud-operations.md","pattern":"System reconnaissance","snippet":"_openid: 'some-id'  // ERROR: Cannot manually set _openid","category":"blocker","line_end":653,"severity":"low","line_start":652},{"id":"external_commands:geolocation.md:314:ruby-shell-backtick-execution","file":"geolocation.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Distance: ${delivery.distance}m, Fee: $${delivery.fee}`);","category":"external_commands","line_end":315,"severity":"medium","line_start":314},{"id":"external_commands:pagination.md:140:ruby-shell-backtick-execution","file":"pagination.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Page ${result.pagination.currentPage} of ${result.pagination.totalPages}`);","category":"external_commands","line_end":141,"severity":"medium","line_start":140},{"id":"external_commands:pagination.md:141:ruby-shell-backtick-execution","file":"pagination.md","pattern":"Ruby/shell backtick execution","snippet":"console.log(`Total items: ${result.pagination.totalCount}`);","category":"external_commands","line_end":142,"severity":"medium","line_start":141},{"id":"sensitive:pagination.md:67:certificate-key-files","file":"pagination.md","pattern":"Certificate/key files","snippet":"if (Object.keys(whereConditions).length > 0) {","category":"sensitive","line_end":67,"severity":"high","line_start":67},{"id":"sensitive:pagination.md:107:certificate-key-files","file":"pagination.md","pattern":"Certificate/key files","snippet":"if (Object.keys(whereConditions).length > 0) {","category":"sensitive","line_end":107,"severity":"high","line_start":107},{"id":"external_commands:security-rules.md:972:ruby-shell-backtick-execution","file":"security-rules.md","pattern":"Ruby/shell backtick execution","snippet":"\"write\": \"get(`database.roles.${doc.id}`).roles[auth.uid] in ['owner', 'writer']\"","category":"external_commands","line_end":974,"severity":"medium","line_start":972},{"id":"blocker:security-rules.md:26:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"- If you define a read/write rule: `auth.openid == doc._openid`","category":"blocker","line_end":26,"severity":"low","line_start":26},{"id":"blocker:security-rules.md:244:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// Correct: Do not include _openid in write operations","category":"blocker","line_end":244,"severity":"low","line_start":244},{"id":"blocker:security-rules.md:248:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// _openid is automatically added by SDK","category":"blocker","line_end":248,"severity":"low","line_start":248},{"id":"blocker:security-rules.md:251:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// Wrong: Including _openid will cause an error","category":"blocker","line_end":251,"severity":"low","line_start":251},{"id":"blocker:security-rules.md:254:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"_openid: 'some-id'  // ERROR: Cannot manually set _openid","category":"blocker","line_end":255,"severity":"low","line_start":254},{"id":"blocker:security-rules.md:257:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// Correct: Use _openid in security rules for permission checks","category":"blocker","line_end":257,"severity":"low","line_start":257},{"id":"blocker:security-rules.md:259:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"doc._openid == auth.openid\",","category":"blocker","line_end":259,"severity":"low","line_start":259},{"id":"blocker:security-rules.md:260:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"doc._openid == auth.openid\"","category":"blocker","line_end":260,"severity":"low","line_start":260},{"id":"blocker:security-rules.md:275:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"auth.uid == doc.user_id\",","category":"blocker","line_end":275,"severity":"low","line_start":275},{"id":"blocker:security-rules.md:276:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"auth.uid == doc.user_id\"","category":"blocker","line_end":276,"severity":"low","line_start":276},{"id":"blocker:security-rules.md:292:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"update\": \"auth.uid == doc.author_id\",","category":"blocker","line_end":292,"severity":"low","line_start":292},{"id":"blocker:security-rules.md:293:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"delete\": \"auth.uid == doc.author_id\"","category":"blocker","line_end":293,"severity":"low","line_start":293},{"id":"blocker:security-rules.md:311:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"update\": \"doc.author_id == auth.uid\",","category":"blocker","line_end":311,"severity":"low","line_start":311},{"id":"blocker:security-rules.md:312:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"delete\": \"doc.author_id == auth.uid\"","category":"blocker","line_end":312,"severity":"low","line_start":312},{"id":"blocker:security-rules.md:337:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"auth.uid == doc.user_id\",","category":"blocker","line_end":337,"severity":"low","line_start":337},{"id":"blocker:security-rules.md:339:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"update\": \"auth.uid == doc.user_id && (doc.price == request.data.price || request.data.price == unde","category":"blocker","line_end":339,"severity":"low","line_start":339},{"id":"blocker:security-rules.md:354:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"auth.uid == doc.user_id\",","category":"blocker","line_end":354,"severity":"low","line_start":354},{"id":"blocker:security-rules.md:355:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"auth.uid == doc.user_id\",","category":"blocker","line_end":355,"severity":"low","line_start":355},{"id":"blocker:security-rules.md:371:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **==** | Equal to | `auth.uid == 'zzz'` | User's uid is zzz |","category":"blocker","line_end":371,"severity":"low","line_start":371},{"id":"blocker:security-rules.md:372:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **!=** | Not equal to | `auth.uid != 'zzz'` | User's uid is not zzz |","category":"blocker","line_end":372,"severity":"low","line_start":372},{"id":"blocker:security-rules.md:377:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **in** | Exists in collection | `auth.uid in ['zzz','aaa']` | User's uid is one of ['zzz','aaa'] |","category":"blocker","line_end":377,"severity":"low","line_start":377},{"id":"blocker:security-rules.md:378:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **!(xx in [])** | Does not exist in collection | `!(auth.uid in ['zzz','aaa'])` | User's uid is no","category":"blocker","line_end":378,"severity":"low","line_start":378},{"id":"blocker:security-rules.md:379:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **&&** | Logical AND | `auth.uid == 'zzz' && doc.age > 10` | User's uid is zzz AND query condition","category":"blocker","line_end":379,"severity":"low","line_start":379},{"id":"blocker:security-rules.md:380:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **\\|\\|** | Logical OR | `auth.uid == 'zzz' \\|\\| doc.age > 10` | User's uid is zzz OR query conditi","category":"blocker","line_end":380,"severity":"low","line_start":380},{"id":"blocker:security-rules.md:381:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **.** | Object element access | `auth.uid` | User's uid |","category":"blocker","line_end":381,"severity":"low","line_start":381},{"id":"blocker:security-rules.md:382:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| **[]** | Array access operator | `get('database.collection_a.user')[auth.uid] == 'zzz'` | In colle","category":"blocker","line_end":382,"severity":"low","line_start":382},{"id":"blocker:security-rules.md:418:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"auth.uid == doc.user_id\"","category":"blocker","line_end":418,"severity":"low","line_start":418},{"id":"blocker:security-rules.md:424:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"auth.uid in ['admin1', 'admin2']\"","category":"blocker","line_end":424,"severity":"low","line_start":424},{"id":"blocker:security-rules.md:427:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"auth.uid == doc.user_id && doc.status == 'active'\"","category":"blocker","line_end":427,"severity":"low","line_start":427},{"id":"blocker:security-rules.md:465:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"get('database.user_roles.' + auth.uid + '.role') == 'admin'\"","category":"blocker","line_end":465,"severity":"low","line_start":465},{"id":"blocker:security-rules.md:497:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"auth.uid != null\",","category":"blocker","line_end":497,"severity":"low","line_start":497},{"id":"blocker:security-rules.md:498:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"create\": \"auth.uid != null\",","category":"blocker","line_end":498,"severity":"low","line_start":498},{"id":"blocker:security-rules.md:499:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"update\": \"auth.uid != null && (get('database.user_roles.' + auth.uid).role == 'admin' || doc.author","category":"blocker","line_end":499,"severity":"low","line_start":499},{"id":"blocker:security-rules.md:500:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"delete\": \"auth.uid != null && (get('database.user_roles.' + auth.uid).role == 'admin' || doc.author","category":"blocker","line_end":500,"severity":"low","line_start":500},{"id":"blocker:security-rules.md:509:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"auth.uid == get('database.projects.' + doc.projectId).owner\"","category":"blocker","line_end":509,"severity":"low","line_start":509},{"id":"blocker:security-rules.md:537:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"- **Performance Considerations:** Avoid excessive `get()` function calls","category":"blocker","line_end":537,"severity":"low","line_start":537},{"id":"blocker:security-rules.md:544:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"4. **Avoid Complex Expressions:** Keep custom rules simple and readable","category":"blocker","line_end":544,"severity":"low","line_start":544},{"id":"blocker:security-rules.md:559:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"| Using `ADMINWRITE` for cart/order collections | `.add()` or `.update()` fails<br>Keeps loading or ","category":"blocker","line_end":559,"severity":"low","line_start":559},{"id":"blocker:security-rules.md:584:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"### Valid Queries","category":"blocker","line_end":584,"severity":"low","line_start":584},{"id":"blocker:security-rules.md:665:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"create\": \"auth.uid != null && request.data.userId == auth.uid\"","category":"blocker","line_end":665,"severity":"low","line_start":665},{"id":"blocker:security-rules.md:669:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// Written data includes userId matching current user's uid","category":"blocker","line_end":670,"severity":"low","line_start":669},{"id":"blocker:security-rules.md:670:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// Note: _openid is automatically added by SDK, do not include it","category":"blocker","line_end":670,"severity":"low","line_start":670},{"id":"blocker:security-rules.md:672:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"userId: currentUser.uid,  // Matches auth.uid","category":"blocker","line_end":673,"severity":"low","line_start":672},{"id":"blocker:security-rules.md:675:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// _openid is automatically populated by SDK based on authenticated user","category":"blocker","line_end":675,"severity":"low","line_start":675},{"id":"blocker:security-rules.md:679:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// Written data has userId that doesn't match current user's uid","category":"blocker","line_end":680,"severity":"low","line_start":679},{"id":"blocker:security-rules.md:681:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"userId: \"other-user-id\",  // Does not match auth.uid","category":"blocker","line_end":682,"severity":"low","line_start":681},{"id":"blocker:security-rules.md:686:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"// Also wrong: Cannot manually set _openid","category":"blocker","line_end":687,"severity":"low","line_start":686},{"id":"blocker:security-rules.md:689:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"_openid: \"some-id\",  // ERROR: Cannot manually set _openid","category":"blocker","line_end":690,"severity":"low","line_start":689},{"id":"blocker:security-rules.md:696:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"In query conditions, if the key is `_openid` and the value is `{openid}`, or if the key is `uid` and","category":"blocker","line_end":696,"severity":"low","line_start":696},{"id":"blocker:security-rules.md:698:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"**Important:** Under basic permission control, query conditions don't need to pass `_openid`, but se","category":"blocker","line_end":698,"severity":"low","line_start":698},{"id":"blocker:security-rules.md:718:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"doc._openid == auth.openid\"","category":"blocker","line_end":718,"severity":"low","line_start":718},{"id":"blocker:security-rules.md:738:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"_openid: '{openid}'  // Auto-replaced with current user's openid","category":"blocker","line_end":739,"severity":"low","line_start":738},{"id":"blocker:security-rules.md:746:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"uid: '{uid}'  // Auto-replaced with current user's uid","category":"blocker","line_end":747,"severity":"low","line_start":746},{"id":"blocker:security-rules.md:761:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"doc._openid == auth.openid\"","category":"blocker","line_end":761,"severity":"low","line_start":761},{"id":"blocker:security-rules.md:769:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"doc._openid == auth.uid\"","category":"blocker","line_end":769,"severity":"low","line_start":769},{"id":"blocker:security-rules.md:778:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"doc._openid == auth.openid\",","category":"blocker","line_end":778,"severity":"low","line_start":778},{"id":"blocker:security-rules.md:779:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"doc._openid == auth.openid\"","category":"blocker","line_end":779,"severity":"low","line_start":779},{"id":"blocker:security-rules.md:786:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"doc._openid == auth.uid\",","category":"blocker","line_end":786,"severity":"low","line_start":786},{"id":"blocker:security-rules.md:787:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"doc._openid == auth.uid\"","category":"blocker","line_end":787,"severity":"low","line_start":787},{"id":"blocker:security-rules.md:820:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"update\": \"auth.uid == doc.owner_id\",","category":"blocker","line_end":820,"severity":"low","line_start":820},{"id":"blocker:security-rules.md:821:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"delete\": \"auth.uid == doc.owner_id\"","category":"blocker","line_end":821,"severity":"low","line_start":821},{"id":"blocker:security-rules.md:843:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"delete\": \"doc.author == auth.uid && doc.published == false\"","category":"blocker","line_end":843,"severity":"low","line_start":843},{"id":"blocker:security-rules.md:850:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"auth.uid in doc.readers || auth.uid in doc.editors || doc.owner == auth.uid\",","category":"blocker","line_end":850,"severity":"low","line_start":850},{"id":"blocker:security-rules.md:851:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"auth.uid in doc.editors || doc.owner == auth.uid\"","category":"blocker","line_end":851,"severity":"low","line_start":851},{"id":"blocker:security-rules.md:861:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"doc.owner == auth.uid && now <= doc.endTime\"","category":"blocker","line_end":861,"severity":"low","line_start":861},{"id":"blocker:security-rules.md:868:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"read\": \"doc._openid == auth.openid\",","category":"blocker","line_end":868,"severity":"low","line_start":868},{"id":"blocker:security-rules.md:869:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"write\": \"doc._openid == auth.openid\"","category":"blocker","line_end":869,"severity":"low","line_start":869},{"id":"blocker:security-rules.md:888:system-reconnaissance","file":"security-rules.md","pattern":"System reconnaissance","snippet":"\"update\": \"doc.author == auth.uid && doc.status != 'locked'\"","category":"blocker","line_end":888,"severity":"low","line_start":888},{"id":"blocker:security-rules.md:32:network-reconnaissance","file":"security-rules.md","pattern":"Network reconnaissance","snippet":"- The system performs **rule matching** before any database access","category":"blocker","line_end":33,"severity":"low","line_start":32},{"id":"blocker:security-rules.md:525:network-reconnaissance","file":"security-rules.md","pattern":"Network reconnaissance","snippet":"- **get() function**: Each `get()` produces additional data access","category":"blocker","line_end":526,"severity":"low","line_start":525},{"id":"blocker:security-rules.md:526:network-reconnaissance","file":"security-rules.md","pattern":"Network reconnaissance","snippet":"- **Document ID queries for all write operations**: All write operations for document ID queries pro","category":"blocker","line_end":527,"severity":"low","line_start":526},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If this environment only installed the current skill, start from the CloudBase main entry and use th","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Keep local `references/...` paths for files that ship with the current skill directory. When this fi","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- A browser or Web app must read or write CloudBase document database data through `@cloudbase/js-sd","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The request mentions `app.database()`, `db.collection()`, `.where()`, `.watch()`, pagination, aggr","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Mini Program code using `wx.cloud.database()`.","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **NEW business tables that the task explicitly asks to put in CloudBase PostgreSQL (CloudBase PG).","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The task mentions specific SDK methods like `db.collection().add()`, `.get()`, `.update()`","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The context shows an existing Web project with SDK initialization (e.g., `index.js` already has `c","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The task mentions tools like `writeNoSqlDatabaseContent`, `managePermissions`, etc.","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Using `wx.cloud.database()` or Node SDK patterns in browser code.","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Expecting a `CUSTOM` security rule to take effect immediately after you call `managePermissions(","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Misreading the return shape of `db.collection(...).add(...)`. In the CloudBase Web SDK, the create","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For CMS-style collections that need **app-level admin users** to edit/delete all records while edi","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Initialize CloudBase once and reuse the same `app` / `db` instance.","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"This skill covers **browser-side document database usage** via `@cloudbase/js-sdk`.","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- realtime listeners with `watch()`","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":102,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":112,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CRUD -> `./crud-operations.md`","category":"external_commands","line_end":113,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complex queries -> `./complex-queries.md`","category":"external_commands","line_end":114,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Pagination -> `./pagination.md`","category":"external_commands","line_end":115,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Aggregation -> `./aggregation.md`","category":"external_commands","line_end":116,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Realtime listeners -> `./realtime.md`","category":"external_commands","line_end":117,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Geolocation -> `./geolocation.md`","category":"external_commands","line_end":118,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Security rules -> `./security-rules.md`","category":"external_commands","line_end":126,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `app.database()` and collection references.","category":"external_commands","line_end":131,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the requirement is simple owner-only write access, `READONLY` can be enough.","category":"external_commands","line_end":132,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the requirement is “app-level admin can edit/delete all, editor only own”, use a `CUSTOM` rule.","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For that CMS pattern, frontend writes can stay on `.doc(id).update()` / `.doc(id).remove()`.","category":"external_commands","line_end":133,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Reuse whichever role collection already exists and can be addressed by `_id == auth.uid`. In this ","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For writes, do not treat a resolved promise as success by default. Check write result fields such ","category":"external_commands","line_end":139,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For Web SDK `.add(...)`, the newly created document ID is `result._id`.","category":"external_commands","line_end":142,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Do not look for the ID under `result.id`, `result.data`, or other driver-specific fields.","category":"external_commands","line_end":143,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":153,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":157,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":165,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":169,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":175,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":179,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":183,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":196,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":203,"severity":"medium","line_start":196},{"id":"network:SKILL.md:12:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:33:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te","category":"network","line_end":33,"severity":"low","line_start":33},{"id":"network:SKILL.md:34:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:SKILL.md:35:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co","category":"network","line_end":35,"severity":"low","line_start":35},{"id":"filesystem:SKILL.md:33:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Web login and caller identity -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/te","category":"filesystem","line_end":33,"severity":"high","line_start":33},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- General Web app structure -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool","category":"filesystem","line_end":34,"severity":"high","line_start":34},{"id":"filesystem:SKILL.md:35:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Mini Program database code -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.co","category":"filesystem","line_end":35,"severity":"high","line_start":35},{"id":"blocker:SKILL.md:134:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Reuse whichever role collection already exists and can be addressed by `_id == auth.uid`. In this ","category":"blocker","line_end":134,"severity":"low","line_start":134}],"finding_verdicts":[{"id":"blocker:aggregation.md:212:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:aggregation.md:313:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:complex-queries.md:96:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:crud-operations.md:482:sqlite-database-file","reason":"The matched text appears only in documentation examples and does not provide an executable security-sensitive behavior.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:13:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:20:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:117:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:123:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:141:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:183:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:188:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:198:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:199:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:200:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:201:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:211:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:212:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:216:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:242:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:588:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:641:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:645:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:648:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:crud-operations.md:652:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:geolocation.md:314:ruby-shell-backtick-execution","reason":"This is a JavaScript console.log template literal inside a documentation example. It does not invoke Ruby, a shell, or an operating-system command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:pagination.md:140:ruby-shell-backtick-execution","reason":"This is a JavaScript console.log template literal inside a documentation example. It does not invoke Ruby, a shell, or an operating-system command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:pagination.md:141:ruby-shell-backtick-execution","reason":"This is a JavaScript console.log template literal inside a documentation example. It does not invoke Ruby, a shell, or an operating-system command.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:pagination.md:67:certificate-key-files","reason":"The matched text appears only in documentation examples and does not provide an executable security-sensitive behavior.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:pagination.md:107:certificate-key-files","reason":"The matched text appears only in documentation examples and does not provide an executable security-sensitive behavior.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:security-rules.md:972:ruby-shell-backtick-execution","reason":"This is a CloudBase security-rule string using JavaScript-style template literal syntax in documentation. No shell process or executable command is run.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:26:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:244:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:248:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:251:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:254:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:257:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:259:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:260:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:275:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:276:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:292:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:293:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:311:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:312:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:337:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:339:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:354:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:355:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:371:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:372:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:377:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:378:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:379:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:380:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:381:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:382:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:418:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:424:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:427:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:465:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:497:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:498:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:499:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:500:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:509:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:537:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:544:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:559:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:584:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:665:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:669:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:670:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:672:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:675:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:679:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:681:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:686:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:689:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:696:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:698:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:718:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:738:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:746:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:761:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:769:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:778:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:779:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:786:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:787:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:820:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:821:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:843:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:850:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:851:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:861:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:868:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:869:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:888:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:32:network-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:525:network-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"blocker:security-rules.md:526:network-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"This is Markdown or JavaScript documentation using backticks for inline code, code fences, or SDK examples. There is no Ruby shell execution or OS command invocation.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:12:hardcoded-url","reason":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:33:hardcoded-url","reason":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:34:hardcoded-url","reason":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:35:hardcoded-url","reason":"The skill embeds raw external fallback URLs for loading CloudBase skill instructions. That can make runtime behavior depend on mutable content outside the audited package.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"filesystem:SKILL.md:33:path-traversal-sequence","reason":"The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.","verdict":"confirmed","severity":"high","confidence":0.84},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","reason":"The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.","verdict":"confirmed","severity":"high","confidence":0.84},{"id":"filesystem:SKILL.md:35:path-traversal-sequence","reason":"The skill tells the agent to read a parent-directory sibling SKILL.md path with ../. That can escape the current skill boundary and expand the trusted instruction surface beyond this audit.","verdict":"confirmed","severity":"high","confidence":0.84},{"id":"blocker:SKILL.md:134:system-reconnaissance","reason":"The line is CloudBase SDK or security-rule documentation using identifiers such as _id, _openid, auth.uid, or doc fields. It does not perform host, OS, or environment reconnaissance.","verdict":"false_positive","confidence":0.94}],"semantic_findings":[{"title":"Mutable Remote Instruction Loading","severity":"high","locations":[{"file":"SKILL.md","line_end":15,"line_start":10},{"file":"SKILL.md","line_end":35,"line_start":33}],"confidence":0.9,"description":"SKILL.md directs agents to use published fallback URLs for sibling skills when local references are absent. This can load mutable external instructions outside the audited package.","confidence_reasoning":"The instructions explicitly point agents to raw remote SKILL.md files as fallback sources. This is not exfiltration, but it materially expands the instruction trust boundary."}],"subject_marketplace_commit_sha":"24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec","subject_content_hash":"0efc18c6ba16c5e5178d15902b0c7b2b89399ce8868d8122ddff4e4470818353","subject_tree_hash":"2231285a8902a966813579abc2cd0a7a0f79da6d909c716f5be30626e2188700","subject_plugin_path":"skills/tencentcloudbase/cloudbase-document-database-web-sdk","audit_payload_hash":"c144946d89b5c9121000ecb7d2ccd370","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec","contentHash":"0efc18c6ba16c5e5178d15902b0c7b2b89399ce8868d8122ddff4e4470818353","treeHash":"2231285a8902a966813579abc2cd0a7a0f79da6d909c716f5be30626e2188700","pluginPath":"skills/tencentcloudbase/cloudbase-document-database-web-sdk","auditPayloadHash":"c144946d89b5c9121000ecb7d2ccd370"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":8,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}