{"data":{"skill":{"slug":"vercel-next-cache-components-optimizer","name":"next-cache-components-optimizer","icon":"📦","repo":"https://github.com/vercel/next.js/tree/988a6ab72735d5c61f906d6ea0484930aa496713/skills/next-cache-components-optimizer","status":"approved","author":"vercel","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"d70fc7a6-588e-465d-a2d0-6b69143cf8e3","skill_id":"91086049-8ec4-4769-8622-5f48a576a290","version":1,"content_hash":"v3:bdb71a4bc34515f37772ae85fd5501f9c2ff33b0:9b538b7f58241f8d6d808a35967bd8b0624f3ae97f7904ab51b294b05e533210:6437f3d9fe208c2d5df428cb1a9d1a141affc6f08fef6252dcbcac400186936c:736b696c6c732f76657263656c2f6e6578742d63616368652d636f6d706f6e656e74732d6f7074696d697a6572:4b0975ec91595b749b6222e5b9238de1","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 158 static alerts are false positives caused by Markdown formatting, fixed relative paths, non-secret deployment flags, and official documentation links. No prompt injection, secret collection, arbitrary process execution, path traversal, or data-exfiltration intent was found. The skill provides legitimate Next.js optimization guidance and explicitly keeps its testing API out of production.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"reference/patterns.md","line_end":349,"line_start":349},{"file":"reference/patterns.md","line_end":343,"line_start":341},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":112,"line_start":112},{"file":"SKILL.md","line_end":113,"line_start":113},{"file":"SKILL.md","line_end":130,"line_start":117},{"file":"SKILL.md","line_end":140,"line_start":130},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":143,"line_start":143},{"file":"SKILL.md","line_end":146,"line_start":145},{"file":"SKILL.md","line_end":148,"line_start":146},{"file":"SKILL.md","line_end":149,"line_start":148},{"file":"SKILL.md","line_end":151,"line_start":149},{"file":"SKILL.md","line_end":153,"line_start":151},{"file":"SKILL.md","line_end":156,"line_start":153},{"file":"SKILL.md","line_end":169,"line_start":156},{"file":"SKILL.md","line_end":172,"line_start":169},{"file":"SKILL.md","line_end":175,"line_start":172},{"file":"SKILL.md","line_end":175,"line_start":175},{"file":"SKILL.md","line_end":183,"line_start":180},{"file":"SKILL.md","line_end":184,"line_start":183},{"file":"SKILL.md","line_end":186,"line_start":184},{"file":"SKILL.md","line_end":188,"line_start":186},{"file":"SKILL.md","line_end":191,"line_start":188},{"file":"SKILL.md","line_end":192,"line_start":191},{"file":"SKILL.md","line_end":195,"line_start":192},{"file":"SKILL.md","line_end":204,"line_start":195},{"file":"SKILL.md","line_end":207,"line_start":204},{"file":"SKILL.md","line_end":209,"line_start":207},{"file":"SKILL.md","line_end":212,"line_start":209},{"file":"SKILL.md","line_end":213,"line_start":212},{"file":"SKILL.md","line_end":214,"line_start":213},{"file":"SKILL.md","line_end":218,"line_start":214},{"file":"SKILL.md","line_end":219,"line_start":218},{"file":"SKILL.md","line_end":225,"line_start":219}]},{"factor":"filesystem","evidence":[{"file":"reference/real-app-patterns.md","line_end":79,"line_start":79},{"file":"reference/red-test-robustness.md","line_end":142,"line_start":142},{"file":"test-template.md","line_end":13,"line_start":13},{"file":"test-template.md","line_end":28,"line_start":28}]},{"factor":"env_access","evidence":[{"file":"rig-template.md","line_end":40,"line_start":40},{"file":"rig-template.md","line_end":41,"line_start":41},{"file":"rig-template.md","line_end":98,"line_start":98},{"file":"rig-template.md","line_end":103,"line_start":103},{"file":"rig-template.md","line_end":40,"line_start":40},{"file":"rig-template.md","line_end":41,"line_start":41},{"file":"rig-template.md","line_end":98,"line_start":98},{"file":"rig-template.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":199,"line_start":199},{"file":"SKILL.md","line_end":200,"line_start":200},{"file":"SKILL.md","line_end":202,"line_start":202},{"file":"SKILL.md","line_end":199,"line_start":199},{"file":"SKILL.md","line_end":200,"line_start":200},{"file":"SKILL.md","line_end":202,"line_start":202}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":156,"line_start":156},{"file":"SKILL.md","line_end":301,"line_start":301},{"file":"SKILL.md","line_end":348,"line_start":348},{"file":"SKILL.md","line_end":349,"line_start":349},{"file":"SKILL.md","line_end":375,"line_start":375},{"file":"SKILL.md","line_end":472,"line_start":472}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":6,"total_lines":1356,"audit_model":"codex","audited_at":"2026-08-20T08:36:40.305+00:00","created_at":"2026-08-20T09:52:59.505739+00:00","static_findings":[{"id":"external_commands:reference/patterns.md:349:process-spawn","file":"reference/patterns.md","pattern":"Process spawn","snippet":"- **The full prefetch is mandatory.** With App Shells enabled an auto/PPR prefetch bails before the ","category":"external_commands","line_end":349,"severity":"high","line_start":349},{"id":"external_commands:reference/patterns.md:341:ruby-shell-backtick-execution","file":"reference/patterns.md","pattern":"Ruby/shell backtick execution","snippet":"// 3. The URL-dependent content is behind `use cache`, keyed by the resolved","category":"external_commands","line_end":343,"severity":"medium","line_start":341},{"id":"blocker:reference/patterns.md:54:system-reconnaissance","file":"reference/patterns.md","pattern":"System reconnaissance","snippet":"<ProductGrid category={category} />","category":"blocker","line_end":54,"severity":"low","line_start":54},{"id":"filesystem:reference/real-app-patterns.md:79:path-traversal-sequence","file":"reference/real-app-patterns.md","pattern":"Path traversal sequence","snippet":"The `../test-template.md` specs drive a `<Link>` click for soft navigations and `page.goto()` for in","category":"filesystem","line_end":79,"severity":"high","line_start":79},{"id":"filesystem:reference/red-test-robustness.md:142:path-traversal-sequence","file":"reference/red-test-robustness.md","pattern":"Path traversal sequence","snippet":"(`../test-template.md`, self-validating variant). If the lock did not engage, the content is","category":"filesystem","line_end":142,"severity":"high","line_start":142},{"id":"blocker:reference/red-test-robustness.md:66:system-reconnaissance","file":"reference/red-test-robustness.md","pattern":"System reconnaissance","snippet":"| **Hidden / off-screen**      | the testid is on a hover-overlay or off-screen list item           ","category":"blocker","line_end":66,"severity":"low","line_start":66},{"id":"blocker:reference/red-test-robustness.md:78:system-reconnaissance","file":"reference/red-test-robustness.md","pattern":"System reconnaissance","snippet":"- **Hidden marker**: the testid sat first on a `hidden sm:block` hover-overlay link, then on an","category":"blocker","line_end":78,"severity":"low","line_start":78},{"id":"blocker:reference/red-test-robustness.md:142:system-reconnaissance","file":"reference/red-test-robustness.md","pattern":"System reconnaissance","snippet":"(`../test-template.md`, self-validating variant). If the lock did not engage, the content is","category":"blocker","line_end":142,"severity":"low","line_start":142},{"id":"env_access:rig-template.md:40:environment-variable-access-dot-notation","file":"rig-template.md","pattern":"Environment variable access (dot notation)","snippet":"`EXPOSE_TESTING_API=1` for local production builds; `process.env.DEPLOY_ENV","category":"env_access","line_end":40,"severity":"low","line_start":40},{"id":"env_access:rig-template.md:41:environment-variable-access-dot-notation","file":"rig-template.md","pattern":"Environment variable access (dot notation)","snippet":"=== 'staging'` for a generic CI/staging env var; `process.env.VERCEL_ENV ===","category":"env_access","line_end":41,"severity":"low","line_start":41},{"id":"env_access:rig-template.md:98:environment-variable-access-dot-notation","file":"rig-template.md","pattern":"Environment variable access (dot notation)","snippet":"to a staging namespace. EXPOSE: `process.env.DEPLOY_ENV === 'staging'`. RUN: a","category":"env_access","line_end":98,"severity":"low","line_start":98},{"id":"env_access:rig-template.md:103:environment-variable-access-dot-notation","file":"rig-template.md","pattern":"Environment variable access (dot notation)","snippet":"`process.env.VERCEL_ENV === 'preview'`. RUN: `playwright test` with","category":"env_access","line_end":103,"severity":"low","line_start":103},{"id":"env_access:rig-template.md:40:environment-variable-object","file":"rig-template.md","pattern":"Environment variable object","snippet":"`EXPOSE_TESTING_API=1` for local production builds; `process.env.DEPLOY_ENV","category":"env_access","line_end":40,"severity":"low","line_start":40},{"id":"env_access:rig-template.md:41:environment-variable-object","file":"rig-template.md","pattern":"Environment variable object","snippet":"=== 'staging'` for a generic CI/staging env var; `process.env.VERCEL_ENV ===","category":"env_access","line_end":41,"severity":"low","line_start":41},{"id":"env_access:rig-template.md:98:environment-variable-object","file":"rig-template.md","pattern":"Environment variable object","snippet":"to a staging namespace. EXPOSE: `process.env.DEPLOY_ENV === 'staging'`. RUN: a","category":"env_access","line_end":98,"severity":"low","line_start":98},{"id":"env_access:rig-template.md:103:environment-variable-object","file":"rig-template.md","pattern":"Environment variable object","snippet":"`process.env.VERCEL_ENV === 'preview'`. RUN: `playwright test` with","category":"env_access","line_end":103,"severity":"low","line_start":103},{"id":"sensitive:rig-template.md:40:environment-file-access","file":"rig-template.md","pattern":"Environment file access","snippet":"`EXPOSE_TESTING_API=1` for local production builds; `process.env.DEPLOY_ENV","category":"sensitive","line_end":40,"severity":"high","line_start":40},{"id":"sensitive:rig-template.md:41:environment-file-access","file":"rig-template.md","pattern":"Environment file access","snippet":"=== 'staging'` for a generic CI/staging env var; `process.env.VERCEL_ENV ===","category":"sensitive","line_end":41,"severity":"high","line_start":41},{"id":"sensitive:rig-template.md:98:environment-file-access","file":"rig-template.md","pattern":"Environment file access","snippet":"to a staging namespace. EXPOSE: `process.env.DEPLOY_ENV === 'staging'`. RUN: a","category":"sensitive","line_end":98,"severity":"high","line_start":98},{"id":"sensitive:rig-template.md:103:environment-file-access","file":"rig-template.md","pattern":"Environment file access","snippet":"`process.env.VERCEL_ENV === 'preview'`. RUN: `playwright test` with","category":"sensitive","line_end":103,"severity":"high","line_start":103},{"id":"blocker:rig-template.md:77:llm-role-tokens-injection","file":"rig-template.md","pattern":"LLM role tokens injection","snippet":"- TEST USER: <account> via <login mechanism>; flags/plan/role/data: <...>","category":"blocker","line_end":77,"severity":"high","line_start":77},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"goal as a failing `@next/playwright` `instant()` test, work it to green, and","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"references — `reference/patterns.md` (before→after for each blocker type) and","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`reference/real-app-patterns.md` (parallel routes, auth gates, the empty-shell","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **The mechanism: `@next/playwright` `instant()`.** This skill uses","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[`instant()`](https://nextjs.org/docs/app/guides/instant-navigation#prevent-regressions-with-e2e-tes","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`@next/playwright` (installed alongside `@playwright/test`, on the same","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"release line as `next`), so it isn't tied to any host. Keep it. Timing a","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`next build && next start`, a CI/staging container, and a per-push preview","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"fallbacks, `loading.tsx`).","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"prefetched App Shell — the `<Link>` default under Partial Prefetching —","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`reference/real-app-patterns.md`).","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"judgment (D1/D2/E), because an `instant()` pass alone is satisfied by a blank","category":"external_commands","line_end":77,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`fallback={null}` shell (the empty-shell failure mode,","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`reference/real-app-patterns.md`).","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`instant()` is a ruler, not a stopwatch: assert that the shell appears under","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"defer the read behind `<Suspense>` (always fresh, still instant) rather than","category":"external_commands","line_end":112,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"guess a `cacheLife`.","category":"external_commands","line_end":113,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":130,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":140,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Next.js 16.3+ with `cacheComponents: true`** in `next.config.ts`. Without","category":"external_commands","line_end":140,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **`@next/playwright`** on the same release line as the project's `next`; it","category":"external_commands","line_end":142,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"provides `instant()`. Verify with `npm ls next @next/playwright` (or the","category":"external_commands","line_end":143,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"testing API is in the `next` runtime, gated by the","category":"external_commands","line_end":146,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`experimental.exposeTestingApiInProductionBuild` config flag (phase A).","category":"external_commands","line_end":148,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the project does not meet these, upgrade first (`npx @next/codemod upgrade`","category":"external_commands","line_end":149,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"automates most of it), then enable Cache Components in `next.config.ts`:","category":"external_commands","line_end":151,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```ts","category":"external_commands","line_end":153,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":156,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[`next-cache-components-adoption`](https://github.com/vercel/next.js/tree/canary/skills/next-cache-c","category":"external_commands","line_end":169,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`instant-nav.rig.md`. Every later run reads that file instead of","category":"external_commands","line_end":172,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"container, preview deploy) are in **`rig-template.md`**.","category":"external_commands","line_end":175,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`@next/playwright`, a config with `baseURL`, one authenticated path) is part","category":"external_commands","line_end":175,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Stand up the rig described by `instant-nav.rig.md`. Two invariants hold on","category":"external_commands","line_end":183,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Never measure on `next dev`.** It does not prefetch, and its lock is","category":"external_commands","line_end":184,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"unreliable for blocking routes, so a dev `instant()` result is not a valid","category":"external_commands","line_end":186,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **The measured build must expose the testing API.** Otherwise `instant()`","category":"external_commands","line_end":188,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`reference/red-test-robustness.md`). The lock-engagement proof is the phase-C","category":"external_commands","line_end":191,"severity":"medium","line_start":188},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"self-validating variant in `test-template.md` is the in-band guarantee. Wire","category":"external_commands","line_end":192,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`experimental.exposeTestingApiInProductionBuild` to a condition that is","category":"external_commands","line_end":195,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```ts","category":"external_commands","line_end":204,"severity":"medium","line_start":195},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":207,"severity":"medium","line_start":204},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`next build && next start`, a CI/staging container, and a preview deploy are","category":"external_commands","line_end":209,"severity":"medium","line_start":207},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`rig-template.md` for filled examples.","category":"external_commands","line_end":212,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"artifact contains `HEAD` before trusting a verdict (a stale deploy reads as a","category":"external_commands","line_end":213,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"false RED or GREEN); a local `next build && next start` needs none. The probe","category":"external_commands","line_end":214,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"mechanism is in `rig-template.md` (question 6).","category":"external_commands","line_end":218,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Drive the real navigation with no `instant()` lock and assert that the","category":"external_commands","line_end":219,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"destination's `SHELL_MARKER` renders **as the test user**: the account the","category":"external_commands","line_end":225,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"untrustworthy REDs. Scaffold and run command: **`test-template.md`**.","category":"external_commands","line_end":230,"severity":"medium","line_start":225},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Wrap the same navigation in `instant()`; assert the shell commits under the","category":"external_commands","line_end":232,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`test-template.md`).","category":"external_commands","line_end":236,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"RED recipes in `reference/red-test-robustness.md`.","category":"external_commands","line_end":242,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The question that settles it: **does `SHELL_MARKER` render without the lock,","category":"external_commands","line_end":247,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**`reference/red-test-robustness.md`**. Read it now.","category":"external_commands","line_end":253,"severity":"medium","line_start":247},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**The anti-pattern: one coarse boundary.** A single `<Suspense>` high in the","category":"external_commands","line_end":271,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### The most common blocker: a top-level `await` in a layout on a fallback route","category":"external_commands","line_end":273,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":276,"severity":"medium","line_start":273},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":278,"severity":"medium","line_start":276},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When any dynamic segment in the route lacks `generateStaticParams`, the route","category":"external_commands","line_end":280,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"enumerated ones. A top-level `await` in a layout (`await params`, a","category":"external_commands","line_end":280,"severity":"medium","line_start":280},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"dynamic-segment route with one segment lacking `generateStaticParams`, plus a","category":"external_commands","line_end":284,"severity":"medium","line_start":283},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"top-level `await` in the layout above it.","category":"external_commands","line_end":288,"severity":"medium","line_start":284},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Render `children` unconditionally; move the top-level `await` into a","category":"external_commands","line_end":288,"severity":"medium","line_start":288},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`<Suspense fallback={null}>`-wrapped child. Mechanism and before→after:","category":"external_commands","line_end":290,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`reference/real-app-patterns.md`, \"Deferring an auth gate\".","category":"external_commands","line_end":293,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"top-level `await` (commonly `await params`) blocks the same way the layout's","category":"external_commands","line_end":293,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`<Suspense>`-wrapped leaf as well. `fallback={null}` is correct only when a gate renders nothing on","category":"external_commands","line_end":295,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every other blocker shape — `cookies()`/`headers()`, uncached fetch or database","category":"external_commands","line_end":298,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"reads, `searchParams`, metadata, viewport, non-deterministic values (`Date.now()`,","category":"external_commands","line_end":299,"severity":"medium","line_start":299},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`Math.random()`, `crypto.randomUUID()`) — surfaces its own insight when you hit","category":"external_commands","line_end":300,"severity":"medium","line_start":300},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"it: the build prints a `https://nextjs.org/docs/messages/<slug>` link. The","category":"external_commands","line_end":303,"severity":"medium","line_start":301},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"add `--debug-prerender` for the full failing frame and to report every blocker","category":"external_commands","line_end":305,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`next build --debug-build-paths \"app/<route>/**\"` rather than rebuilding the app.","category":"external_commands","line_end":308,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The before→after recipe for each shape is in `reference/patterns.md`, which maps it to the insight","category":"external_commands","line_end":318,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **A green check isn't always instant.** `export const instant = false` opts","category":"external_commands","line_end":320,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`<Suspense>` above the document `<body>` prerenders an empty shell — neither","category":"external_commands","line_end":320,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. the route's `loading.tsx`;","category":"external_commands","line_end":329,"severity":"medium","line_start":328},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. an exported `*Skeleton` colocated with the component;","category":"external_commands","line_end":330,"severity":"medium","line_start":329},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. the fallback already inside the component's own `<Suspense>`.","category":"external_commands","line_end":335,"severity":"medium","line_start":330},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"shared boundary.) A `loading.tsx` above the divergence point fills only","category":"external_commands","line_end":337,"severity":"medium","line_start":335},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`loading.tsx` at the destination segment is itself the in-tree boundary for a","category":"external_commands","line_end":340,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`loading.tsx` and colocated skeletons are interchangeable for that purpose.","category":"external_commands","line_end":351,"severity":"medium","line_start":340},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Exception: if the deferred component renders `null` for some users (for","category":"external_commands","line_end":352,"severity":"medium","line_start":351},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"example, a flag-gated control), `fallback={null}` is correct, since a skeleton","category":"external_commands","line_end":361,"severity":"medium","line_start":352},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`await page.setViewportSize({ width: 1280, height: 800 })`, then","category":"external_commands","line_end":362,"severity":"medium","line_start":361},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`{ width: 390, height: 844 }`), or by adding a mobile Playwright project, so","category":"external_commands","line_end":364,"severity":"medium","line_start":362},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`reference/real-app-patterns.md`.","category":"external_commands","line_end":371,"severity":"medium","line_start":364},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`params`, `searchParams`, or the full URL), there may be no meaningful static","category":"external_commands","line_end":371,"severity":"medium","line_start":371},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Prefetching, a `<Link prefetch={true}>`, and cached URL-dependent content. See","category":"external_commands","line_end":376,"severity":"medium","line_start":374},{"id":"external_commands:SKILL.md:376:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and pattern 10 in `reference/patterns.md` for the requirements, cost trade-offs,","category":"external_commands","line_end":377,"severity":"medium","line_start":376},{"id":"external_commands:SKILL.md:377:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"manual prefetch caveat, and `instant()` test gotchas.","category":"external_commands","line_end":386,"severity":"medium","line_start":377},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Same render output.** The moved `await`s compute and return the same","category":"external_commands","line_end":389,"severity":"medium","line_start":386},{"id":"external_commands:SKILL.md:389:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Side effects still fire.** A deferred `redirect()` or `notFound()` still","category":"external_commands","line_end":389,"severity":"medium","line_start":389},{"id":"external_commands:SKILL.md:405:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`reference/red-test-robustness.md`). On a deployed rig, confirm each run is live","category":"external_commands","line_end":412,"severity":"medium","line_start":405},{"id":"external_commands:SKILL.md:412:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`reference/red-test-robustness.md`); confirm them, then require these","category":"external_commands","line_end":427,"severity":"medium","line_start":412},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Soft navigation** → drive a real `<Link>` click. **Initial load** → use","category":"external_commands","line_end":428,"severity":"medium","line_start":427},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`page.goto()` inside `instant()` with the `baseURL` option. Do not substitute","category":"external_commands","line_end":428,"severity":"medium","line_start":428},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`goto` for a soft-nav verdict; the two shells can differ","category":"external_commands","line_end":430,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`test-template.md`, `reference/real-app-patterns.md`).","category":"external_commands","line_end":430,"severity":"medium","line_start":430},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`reference/real-app-patterns.md`).","category":"external_commands","line_end":438,"severity":"medium","line_start":434},{"id":"external_commands:SKILL.md:438:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rig-template.md`: phase 0, the six-question rig discovery, the","category":"external_commands","line_end":439,"severity":"medium","line_start":438},{"id":"external_commands:SKILL.md:439:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`instant-nav.rig.md` template, and filled examples (local-only, generic CI,","category":"external_commands","line_end":441,"severity":"medium","line_start":439},{"id":"external_commands:SKILL.md:441:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `test-template.md`: the shipped `instant()` specs for both navigation","category":"external_commands","line_end":441,"severity":"medium","line_start":441},{"id":"external_commands:SKILL.md:443:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `reference/red-test-robustness.md`: the C-gate and phase F. The taxonomy of","category":"external_commands","line_end":446,"severity":"medium","line_start":443},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `reference/real-app-patterns.md`: parallel routes, deferring an auth gate,","category":"external_commands","line_end":453,"severity":"medium","line_start":446},{"id":"external_commands:SKILL.md:453:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Partial Prefetching (`partialPrefetching: true`, or the relevant destination","category":"external_commands","line_end":454,"severity":"medium","line_start":453},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"still uses `prefetch = 'partial'` during an incremental rollout).","category":"external_commands","line_end":458,"severity":"medium","line_start":454},{"id":"external_commands:SKILL.md:458:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":460,"severity":"medium","line_start":458},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":462,"severity":"medium","line_start":460},{"id":"external_commands:SKILL.md:462:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If `partialPrefetching: true` is in config, the app is globally adopted. If only","category":"external_commands","line_end":463,"severity":"medium","line_start":462},{"id":"external_commands:SKILL.md:463:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`prefetch = 'partial'` matches, treat those destination segments as adopted","category":"external_commands","line_end":467,"severity":"medium","line_start":463},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"above, consider a targeted `<Link prefetch={true}>` on the links where having","category":"external_commands","line_end":472,"severity":"medium","line_start":467},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[`next-partial-prefetching-adoption`](https://github.com/vercel/next.js/tree/canary/skills/next-part","category":"external_commands","line_end":475,"severity":"medium","line_start":472},{"id":"network:SKILL.md:41:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"[`instant()`](https://nextjs.org/docs/app/guides/instant-navigation#prevent-regressions-with-e2e-tes","category":"network","line_end":41,"severity":"low","line_start":41},{"id":"network:SKILL.md:156:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"[`next-cache-components-adoption`](https://github.com/vercel/next.js/tree/canary/skills/next-cache-c","category":"network","line_end":156,"severity":"low","line_start":156},{"id":"network:SKILL.md:301:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"it: the build prints a `https://nextjs.org/docs/messages/<slug>` link. The","category":"network","line_end":301,"severity":"low","line_start":301},{"id":"network:SKILL.md:348:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"See: [Streaming](https://nextjs.org/docs/app/guides/streaming#push-dynamic-access-down)","category":"network","line_end":348,"severity":"low","line_start":348},{"id":"network:SKILL.md:349:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"and [loading states](https://nextjs.org/docs/app/guides/instant-navigation#iterate-on-loading-states","category":"network","line_end":349,"severity":"low","line_start":349},{"id":"network:SKILL.md:375:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"[Optimizing prefetching](https://nextjs.org/docs/app/guides/optimizing-prefetching)","category":"network","line_end":375,"severity":"low","line_start":375},{"id":"network:SKILL.md:472:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"[`next-partial-prefetching-adoption`](https://github.com/vercel/next.js/tree/canary/skills/next-part","category":"network","line_end":472,"severity":"low","line_start":472},{"id":"env_access:SKILL.md:199:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"//   generic CI:  process.env.DEPLOY_ENV === 'staging'","category":"env_access","line_end":199,"severity":"low","line_start":199},{"id":"env_access:SKILL.md:200:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"//   Vercel:      process.env.VERCEL_ENV === 'preview'","category":"env_access","line_end":200,"severity":"low","line_start":200},{"id":"env_access:SKILL.md:202:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"process.env.EXPOSE_TESTING_API === '1',","category":"env_access","line_end":202,"severity":"low","line_start":202},{"id":"env_access:SKILL.md:199:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"//   generic CI:  process.env.DEPLOY_ENV === 'staging'","category":"env_access","line_end":199,"severity":"low","line_start":199},{"id":"env_access:SKILL.md:200:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"//   Vercel:      process.env.VERCEL_ENV === 'preview'","category":"env_access","line_end":200,"severity":"low","line_start":200},{"id":"env_access:SKILL.md:202:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"process.env.EXPOSE_TESTING_API === '1',","category":"env_access","line_end":202,"severity":"low","line_start":202},{"id":"sensitive:SKILL.md:199:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"//   generic CI:  process.env.DEPLOY_ENV === 'staging'","category":"sensitive","line_end":199,"severity":"high","line_start":199},{"id":"sensitive:SKILL.md:200:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"//   Vercel:      process.env.VERCEL_ENV === 'preview'","category":"sensitive","line_end":200,"severity":"high","line_start":200},{"id":"sensitive:SKILL.md:202:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"process.env.EXPOSE_TESTING_API === '1',","category":"sensitive","line_end":202,"severity":"high","line_start":202},{"id":"blocker:SKILL.md:50:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"deploy are equally valid rigs; the verdict comes from the build, never the","category":"blocker","line_end":50,"severity":"low","line_start":50},{"id":"blocker:SKILL.md:103:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"means the fix did nothing — roll it back.","category":"blocker","line_end":103,"severity":"low","line_start":103},{"id":"blocker:SKILL.md:184:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"unreliable for blocking routes, so a dev `instant()` result is not a valid","category":"blocker","line_end":185,"severity":"low","line_start":184},{"id":"filesystem:test-template.md:13:path-traversal-sequence","file":"test-template.md","pattern":"Path traversal sequence","snippet":"All identifiers in angle brackets (`<b>`, `<Trigger>`) and the `../helpers` import are placeholders;","category":"filesystem","line_end":13,"severity":"high","line_start":13},{"id":"filesystem:test-template.md:28:path-traversal-sequence","file":"test-template.md","pattern":"Path traversal sequence","snippet":"import { logIntoTestAccount, testUrl } from '../helpers'","category":"filesystem","line_end":28,"severity":"high","line_start":28},{"id":"blocker:test-template.md:33:system-reconnaissance","file":"test-template.md","pattern":"System reconnaissance","snippet":"// data-testid on a known static node over a guessed role/name.","category":"blocker","line_end":33,"severity":"low","line_start":33},{"id":"blocker:test-template.md:97:system-reconnaissance","file":"test-template.md","pattern":"System reconnaissance","snippet":"makes a vacuous pass impossible: if the lock did not engage (testing API missing from the build),","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:test-template.md:117:system-reconnaissance","file":"test-template.md","pattern":"System reconnaissance","snippet":"cached. So the initial-load `toHaveCount(0)` gated half is as valid as the soft-nav one; it needs","category":"blocker","line_end":117,"severity":"low","line_start":117}],"finding_verdicts":[{"id":"external_commands:reference/patterns.md:349:process-spawn","reason":"The word \"spawn\" describes an internal Next.js prefetch stage in prose. The cited line does not launch a process or provide an executable process-spawn call.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:reference/patterns.md:341:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"blocker:reference/patterns.md:54:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:reference/real-app-patterns.md:79:path-traversal-sequence","reason":"The traversal sequence is a relative Markdown link to another file in this skill. It does not read or write a user-controlled filesystem path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:reference/red-test-robustness.md:142:path-traversal-sequence","reason":"The traversal sequence is a relative Markdown link to another file in this skill. It does not read or write a user-controlled filesystem path.","verdict":"false_positive","confidence":0.99},{"id":"blocker:reference/red-test-robustness.md:66:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:reference/red-test-robustness.md:78:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:reference/red-test-robustness.md:142:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:40:environment-variable-access-dot-notation","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:41:environment-variable-access-dot-notation","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:98:environment-variable-access-dot-notation","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:103:environment-variable-access-dot-notation","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:40:environment-variable-object","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:41:environment-variable-object","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:98:environment-variable-object","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:rig-template.md:103:environment-variable-object","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:rig-template.md:40:environment-file-access","reason":"The cited text checks named non-secret deployment flags through process.env. It does not open an environment file, collect credentials, or disclose environment contents.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:rig-template.md:41:environment-file-access","reason":"The cited text checks named non-secret deployment flags through process.env. It does not open an environment file, collect credentials, or disclose environment contents.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:rig-template.md:98:environment-file-access","reason":"The cited text checks named non-secret deployment flags through process.env. It does not open an environment file, collect credentials, or disclose environment contents.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:rig-template.md:103:environment-file-access","reason":"The cited text checks named non-secret deployment flags through process.env. It does not open an environment file, collect credentials, or disclose environment contents.","verdict":"false_positive","confidence":0.99},{"id":"blocker:rig-template.md:77:llm-role-tokens-injection","reason":"The word \"role\" is a field in a test-user account template alongside plan and data. It is not an LLM role token or an instruction that attempts to override the auditor.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:188:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:330:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:352:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:361:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:364:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:376:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:377:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:389:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:405:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:412:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:438:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:439:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:441:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:443:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:453:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:458:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter around a read-only ripgrep example. It is documentation, not Ruby backtick execution or an implicit command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:460:ruby-shell-backtick-execution","reason":"The match is a Markdown code-fence delimiter around a read-only ripgrep example. It is documentation, not Ruby backtick execution or an implicit command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:462:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:463:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:472:ruby-shell-backtick-execution","reason":"The match comes from Markdown backticks that format framework APIs, paths, configuration, or examples. No Ruby backtick operator or executable shell interpolation appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:41:hardcoded-url","reason":"The URL is a documentation link to nextjs.org or the Vercel Next.js repository. The skill does not issue a request, send data, or direct credentials to that URL.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:156:hardcoded-url","reason":"The URL is a documentation link to nextjs.org or the Vercel Next.js repository. The skill does not issue a request, send data, or direct credentials to that URL.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:301:hardcoded-url","reason":"The URL is a documentation link to nextjs.org or the Vercel Next.js repository. The skill does not issue a request, send data, or direct credentials to that URL.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:348:hardcoded-url","reason":"The URL is a documentation link to nextjs.org or the Vercel Next.js repository. The skill does not issue a request, send data, or direct credentials to that URL.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:349:hardcoded-url","reason":"The URL is a documentation link to nextjs.org or the Vercel Next.js repository. The skill does not issue a request, send data, or direct credentials to that URL.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:375:hardcoded-url","reason":"The URL is a documentation link to nextjs.org or the Vercel Next.js repository. The skill does not issue a request, send data, or direct credentials to that URL.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:472:hardcoded-url","reason":"The URL is a documentation link to nextjs.org or the Vercel Next.js repository. The skill does not issue a request, send data, or direct credentials to that URL.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:199:environment-variable-access-dot-notation","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:200:environment-variable-access-dot-notation","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:202:environment-variable-access-dot-notation","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:199:environment-variable-object","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:200:environment-variable-object","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:202:environment-variable-object","reason":"The example reads named deployment-state flags such as DEPLOY_ENV, VERCEL_ENV, or EXPOSE_TESTING_API. It neither enumerates the environment nor accesses or transmits secret values.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:199:environment-file-access","reason":"The cited text checks named non-secret deployment flags through process.env. It does not open an environment file, collect credentials, or disclose environment contents.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:200:environment-file-access","reason":"The cited text checks named non-secret deployment flags through process.env. It does not open an environment file, collect credentials, or disclose environment contents.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:202:environment-file-access","reason":"The cited text checks named non-secret deployment flags through process.env. It does not open an environment file, collect credentials, or disclose environment contents.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:50:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:103:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:184:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:test-template.md:13:path-traversal-sequence","reason":"The relative path is a documented placeholder import for a project test helper. It is fixed source text with no untrusted path input or filesystem traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:test-template.md:28:path-traversal-sequence","reason":"The relative path is a documented placeholder import for a project test helper. It is fixed source text with no untrusted path input or filesystem traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"blocker:test-template.md:33:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:test-template.md:97:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:test-template.md:117:system-reconnaissance","reason":"The cited text discusses UI visibility, test reliability, or build state. It contains no host reconnaissance command and does not collect system information.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"bdb71a4bc34515f37772ae85fd5501f9c2ff33b0","subject_content_hash":"9b538b7f58241f8d6d808a35967bd8b0624f3ae97f7904ab51b294b05e533210","subject_tree_hash":"6437f3d9fe208c2d5df428cb1a9d1a141affc6f08fef6252dcbcac400186936c","subject_plugin_path":"skills/vercel/next-cache-components-optimizer","audit_payload_hash":"4b0975ec91595b749b6222e5b9238de1","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bdb71a4bc34515f37772ae85fd5501f9c2ff33b0","contentHash":"9b538b7f58241f8d6d808a35967bd8b0624f3ae97f7904ab51b294b05e533210","treeHash":"6437f3d9fe208c2d5df428cb1a9d1a141affc6f08fef6252dcbcac400186936c","pluginPath":"skills/vercel/next-cache-components-optimizer","auditPayloadHash":"4b0975ec91595b749b6222e5b9238de1"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/vercel-next-cache-components-optimizer/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}