{"data":{"skill":{"slug":"zhanlincui-vercel-react-best-practices","name":"vercel-react-best-practices","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/vercel-react-best-practices","status":"approved","author":"ZhanlinCui","authorVersion":"1.0.0","skillstoreRevision":1},"audit":{"id":"e7f5044d-f7e5-4bb9-978b-e6fa05a4c3ab","skill_id":"47e118a1-ac6c-40f5-846e-5364454ccd3e","version":4,"content_hash":"v3:88a205c7f635a966e31156313b590d59007c5caa:81bad0edc74bc4969ea6abf75b0f84dd99a0557fb0d52a2f74c06cf0567833e1:9a5d6fdd43f029f5e6f2d4fdf826416f52a9f4717feac20b43eba66f12cac1f7:736b696c6c732f7a68616e6c696e6375692f76657263656c2d72656163742d626573742d707261637469636573:28f52787cf04e1cf65df09d55f544193","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 172 static findings were adjudicated as false positives from Markdown documentation, code examples, inline backticks, or public reference links. No prompt injection, credential handling, command execution, or unauthorized network intent was found. One medium content-trust issue remains because a community source uses official Vercel attribution that should be clarified before publication.","remediation":[{"issue":"Unverified official Vercel affiliation claims","severity":"medium","suggestion":"Remove or qualify official maintainer wording unless affiliation is verified. State that this is a community-packaged guide and cite upstream sources clearly."}],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"AGENTS.md","line_end":428,"line_start":428},{"file":"AGENTS.md","line_end":470,"line_start":470},{"file":"AGENTS.md","line_end":508,"line_start":508},{"file":"AGENTS.md","line_end":529,"line_start":529},{"file":"AGENTS.md","line_end":551,"line_start":551},{"file":"AGENTS.md","line_end":2309,"line_start":2309},{"file":"rules/bundle-conditional.md","line_end":20,"line_start":20},{"file":"rules/bundle-defer-third-party.md","line_end":35,"line_start":35},{"file":"rules/bundle-dynamic-imports.md","line_end":28,"line_start":28},{"file":"rules/bundle-preload.md","line_end":18,"line_start":18},{"file":"rules/bundle-preload.md","line_end":40,"line_start":40},{"file":"rules/js-tosorted-immutable.md","line_end":57,"line_start":57}]},{"factor":"external_commands","evidence":[{"file":"AGENTS.md","line_end":1064,"line_start":1056},{"file":"AGENTS.md","line_end":1082,"line_start":1064},{"file":"AGENTS.md","line_end":1642,"line_start":1636},{"file":"AGENTS.md","line_end":1760,"line_start":1758},{"file":"AGENTS.md","line_end":2129,"line_start":2125},{"file":"AGENTS.md","line_end":2144,"line_start":2138},{"file":"README.md","line_end":89,"line_start":88},{"file":"README.md","line_end":89,"line_start":89},{"file":"README.md","line_end":97,"line_start":96},{"file":"README.md","line_end":98,"line_start":97},{"file":"README.md","line_end":99,"line_start":98},{"file":"README.md","line_end":100,"line_start":99},{"file":"README.md","line_end":101,"line_start":100},{"file":"README.md","line_end":105,"line_start":101},{"file":"README.md","line_end":106,"line_start":105},{"file":"README.md","line_end":107,"line_start":106},{"file":"README.md","line_end":108,"line_start":107},{"file":"README.md","line_end":115,"line_start":108},{"file":"README.md","line_end":118,"line_start":115},{"file":"rules/client-localstorage-schema.md","line_end":35,"line_start":27},{"file":"rules/client-localstorage-schema.md","line_end":53,"line_start":35},{"file":"rules/js-hoist-regexp.md","line_end":20,"line_start":16},{"file":"rules/js-hoist-regexp.md","line_end":35,"line_start":29},{"file":"rules/rendering-hydration-no-flicker.md","line_end":78,"line_start":72},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":91,"line_start":91},{"file":"SKILL.md","line_end":92,"line_start":92},{"file":"SKILL.md","line_end":93,"line_start":93},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":105,"line_start":105},{"file":"SKILL.md","line_end":115,"line_start":111},{"file":"SKILL.md","line_end":125,"line_start":115}]},{"factor":"network","evidence":[{"file":"AGENTS.md","line_end":995,"line_start":995},{"file":"AGENTS.md","line_end":612,"line_start":612},{"file":"AGENTS.md","line_end":867,"line_start":867},{"file":"metadata.json","line_end":7,"line_start":7},{"file":"metadata.json","line_end":8,"line_start":8},{"file":"metadata.json","line_end":9,"line_start":9},{"file":"metadata.json","line_end":10,"line_start":10},{"file":"metadata.json","line_end":11,"line_start":11},{"file":"metadata.json","line_end":12,"line_start":12},{"file":"metadata.json","line_end":13,"line_start":13},{"file":"README.md","line_end":84,"line_start":84},{"file":"README.md","line_end":123,"line_start":123},{"file":"rules/_sections.md","line_end":26,"line_start":26},{"file":"rules/client-swr-dedup.md","line_end":18,"line_start":18},{"file":"rules/server-serialization.md","line_end":10,"line_start":10}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Unverified Official Affiliation Claim","locations":[{"file":"SKILL.md","line_end":12,"line_start":3},{"file":"AGENTS.md","line_end":10,"line_start":3},{"file":"metadata.json","line_end":3,"line_start":3}],"confidence":0.82,"description":"The community-sourced skill presents itself with official Vercel attribution, including Vercel Engineering, author vercel, and maintained by Vercel language. This can mislead users about provenance and review authority.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The report source type is community, but multiple files state or imply official Vercel ownership. This is a provenance and marketplace trust issue rather than executable malware."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":53,"total_lines":5215,"audit_model":"codex","audited_at":"2026-07-08T16:30:39.367+00:00","created_at":"2026-07-16T11:02:03.666743+00:00","static_findings":[{"id":"scripts:AGENTS.md:428:dynamic-import-expression","file":"AGENTS.md","pattern":"Dynamic import() expression","snippet":"import('./animation-frames.js')","category":"scripts","line_end":428,"severity":"medium","line_start":428},{"id":"scripts:AGENTS.md:470:dynamic-import-expression","file":"AGENTS.md","pattern":"Dynamic import() expression","snippet":"() => import('@vercel/analytics/react').then(m => m.Analytics),","category":"scripts","line_end":470,"severity":"medium","line_start":470},{"id":"scripts:AGENTS.md:508:dynamic-import-expression","file":"AGENTS.md","pattern":"Dynamic import() expression","snippet":"() => import('./monaco-editor').then(m => m.MonacoEditor),","category":"scripts","line_end":508,"severity":"medium","line_start":508},{"id":"scripts:AGENTS.md:529:dynamic-import-expression","file":"AGENTS.md","pattern":"Dynamic import() expression","snippet":"void import('./monaco-editor')","category":"scripts","line_end":529,"severity":"medium","line_start":529},{"id":"scripts:AGENTS.md:551:dynamic-import-expression","file":"AGENTS.md","pattern":"Dynamic import() expression","snippet":"void import('./monaco-editor').then(mod => mod.init())","category":"scripts","line_end":551,"severity":"medium","line_start":551},{"id":"scripts:AGENTS.md:2309:with-statement-deprecated-scope-confusion","file":"AGENTS.md","pattern":"with statement (deprecated, scope confusion)","snippet":"- `.with()` - immutable element replacement","category":"scripts","line_end":2309,"severity":"medium","line_start":2309},{"id":"external_commands:AGENTS.md:1056:ruby-shell-backtick-execution","file":"AGENTS.md","pattern":"Ruby/shell backtick execution","snippet":"localStorage.setItem(`userConfig:${VERSION}`, JSON.stringify(config))","category":"external_commands","line_end":1064,"severity":"medium","line_start":1056},{"id":"external_commands:AGENTS.md:1064:ruby-shell-backtick-execution","file":"AGENTS.md","pattern":"Ruby/shell backtick execution","snippet":"const data = localStorage.getItem(`userConfig:${VERSION}`)","category":"external_commands","line_end":1082,"severity":"medium","line_start":1064},{"id":"external_commands:AGENTS.md:1636:ruby-shell-backtick-execution","file":"AGENTS.md","pattern":"Ruby/shell backtick execution","snippet":"`,","category":"external_commands","line_end":1642,"severity":"medium","line_start":1636},{"id":"external_commands:AGENTS.md:1758:ruby-shell-backtick-execution","file":"AGENTS.md","pattern":"Ruby/shell backtick execution","snippet":"`","category":"external_commands","line_end":1760,"severity":"medium","line_start":1758},{"id":"external_commands:AGENTS.md:2125:ruby-shell-backtick-execution","file":"AGENTS.md","pattern":"Ruby/shell backtick execution","snippet":"const regex = new RegExp(`(${query})`, 'gi')","category":"external_commands","line_end":2129,"severity":"medium","line_start":2125},{"id":"external_commands:AGENTS.md:2138:ruby-shell-backtick-execution","file":"AGENTS.md","pattern":"Ruby/shell backtick execution","snippet":"() => new RegExp(`(${escapeRegex(query)})`, 'gi'),","category":"external_commands","line_end":2144,"severity":"medium","line_start":2138},{"id":"network:AGENTS.md:995:fetch-api-call","file":"AGENTS.md","pattern":"Fetch API call","snippet":"fetch('/api/users')","category":"network","line_end":995,"severity":"low","line_start":995},{"id":"network:AGENTS.md:612:python-http-libraries","file":"AGENTS.md","pattern":"Python HTTP libraries","snippet":"The React Server/Client boundary serializes all object properties into strings and embeds them in th","category":"network","line_end":612,"severity":"low","line_start":612},{"id":"network:AGENTS.md:867:python-http-libraries","file":"AGENTS.md","pattern":"Python HTTP libraries","snippet":"Automatic deduplication and efficient data fetching patterns reduce redundant network requests.","category":"network","line_end":867,"severity":"low","line_start":867},{"id":"sensitive:AGENTS.md:881:certificate-key-files","file":"AGENTS.md","pattern":"Certificate/key files","snippet":"if (e.metaKey && e.key === key) {","category":"sensitive","line_end":881,"severity":"high","line_start":881},{"id":"sensitive:AGENTS.md:922:certificate-key-files","file":"AGENTS.md","pattern":"Certificate/key files","snippet":"if (e.metaKey && keyCallbacks.has(e.key)) {","category":"sensitive","line_end":922,"severity":"high","line_start":922},{"id":"sensitive:AGENTS.md:923:certificate-key-files","file":"AGENTS.md","pattern":"Certificate/key files","snippet":"keyCallbacks.get(e.key)!.forEach(cb => cb())","category":"sensitive","line_end":923,"severity":"high","line_start":923},{"id":"sensitive:AGENTS.md:1980:certificate-key-files","file":"AGENTS.md","pattern":"Certificate/key files","snippet":"if (e.key) storageCache.delete(e.key)","category":"sensitive","line_end":1980,"severity":"high","line_start":1980},{"id":"blocker:AGENTS.md:30:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"- 2.1 [Avoid Barrel File Imports](#21-avoid-barrel-file-imports)","category":"blocker","line_end":30,"severity":"low","line_start":30},{"id":"blocker:AGENTS.md:91:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"Move `await` operations into the branches where they're actually used to avoid blocking code paths t","category":"blocker","line_end":91,"severity":"low","line_start":91},{"id":"blocker:AGENTS.md:347:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"- When you want to avoid layout shift (loading → content jump)","category":"blocker","line_end":347,"severity":"low","line_start":347},{"id":"blocker:AGENTS.md:359:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"### 2.1 Avoid Barrel File Imports","category":"blocker","line_end":359,"severity":"low","line_start":359},{"id":"blocker:AGENTS.md:363:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"Import directly from source files instead of barrel files to avoid loading thousands of unused modul","category":"blocker","line_end":363,"severity":"low","line_start":363},{"id":"blocker:AGENTS.md:526:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"function EditorButton({ onClick }: { onClick: () => void }) {","category":"blocker","line_end":526,"severity":"low","line_start":526},{"id":"blocker:AGENTS.md:529:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"void import('./monaco-editor')","category":"blocker","line_end":529,"severity":"low","line_start":529},{"id":"blocker:AGENTS.md:551:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"void import('./monaco-editor').then(mod => mod.init())","category":"blocker","line_end":551,"severity":"low","line_start":551},{"id":"blocker:AGENTS.md:591:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"const user = await db.user.findUnique({ where: { id } })","category":"blocker","line_end":591,"severity":"low","line_start":591},{"id":"blocker:AGENTS.md:602:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"**With Vercel's [Fluid Compute](https://vercel.com/docs/fluid-compute):** LRU caching is especially ","category":"blocker","line_end":602,"severity":"low","line_start":602},{"id":"blocker:AGENTS.md:736:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"where: { id: session.user.id }","category":"blocker","line_end":736,"severity":"low","line_start":736},{"id":"blocker:AGENTS.md:743:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"**Avoid inline objects as arguments:**","category":"blocker","line_end":743,"severity":"low","line_start":743},{"id":"blocker:AGENTS.md:751:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"return await db.user.findUnique({ where: { id: params.uid } })","category":"blocker","line_end":751,"severity":"low","line_start":751},{"id":"blocker:AGENTS.md:1156:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"const id = computeAvatarId(user)","category":"blocker","line_end":1156,"severity":"low","line_start":1156},{"id":"blocker:AGENTS.md:1169:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"const id = useMemo(() => computeAvatarId(user), [user])","category":"blocker","line_end":1169,"severity":"low","line_start":1169},{"id":"blocker:AGENTS.md:1199:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"**Correct: re-runs only when id changes**","category":"blocker","line_end":1199,"severity":"low","line_start":1199},{"id":"blocker:AGENTS.md:1270:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"setItems(items.filter(item => item.id !== id))","category":"blocker","line_end":1270,"severity":"low","line_start":1270},{"id":"blocker:AGENTS.md:1292:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"setItems(curr => curr.filter(item => item.id !== id))","category":"blocker","line_end":1292,"severity":"low","line_start":1292},{"id":"blocker:AGENTS.md:1508:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"Extract static JSX outside components to avoid re-creation.","category":"blocker","line_end":1508,"severity":"low","line_start":1508},{"id":"blocker:AGENTS.md:1574:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"When rendering content that depends on client-side storage (localStorage, cookies), avoid both SSR b","category":"blocker","line_end":1574,"severity":"low","line_start":1574},{"id":"blocker:AGENTS.md:1718:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"Avoid changing styles one property at a time. Group multiple CSS changes together via classes or `cs","category":"blocker","line_end":1718,"severity":"low","line_start":1718},{"id":"blocker:AGENTS.md:1728:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"element.style.border = '1px solid black'","category":"blocker","line_end":1728,"severity":"low","line_start":1728},{"id":"blocker:AGENTS.md:1740:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"border: 1px solid black;","category":"blocker","line_end":1740,"severity":"low","line_start":1740},{"id":"blocker:AGENTS.md:1757:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"border: 1px solid black;","category":"blocker","line_end":1757,"severity":"low","line_start":1757},{"id":"blocker:AGENTS.md:1804:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"user: users.find(u => u.id === order.userId)","category":"blocker","line_end":1804,"severity":"low","line_start":1804},{"id":"blocker:AGENTS.md:1852:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"**Impact: MEDIUM (avoid redundant computation)**","category":"blocker","line_end":1852,"severity":"low","line_start":1852},{"id":"blocker:AGENTS.md:2376:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"function SearchInput({ onSearch }: { onSearch: (q: string) => void }) {","category":"blocker","line_end":2376,"severity":"low","line_start":2376},{"id":"blocker:AGENTS.md:2389:system-reconnaissance","file":"AGENTS.md","pattern":"System reconnaissance","snippet":"function SearchInput({ onSearch }: { onSearch: (q: string) => void }) {","category":"blocker","line_end":2389,"severity":"low","line_start":2389},{"id":"blocker:AGENTS.md:1732:network-reconnaissance","file":"AGENTS.md","pattern":"Network reconnaissance","snippet":"**Correct: add class - single reflow**","category":"blocker","line_end":1732,"severity":"low","line_start":1732},{"id":"network:metadata.json:7:hardcoded-url","file":"metadata.json","pattern":"Hardcoded URL","snippet":"\"https://react.dev\",","category":"network","line_end":7,"severity":"low","line_start":7},{"id":"network:metadata.json:8:hardcoded-url","file":"metadata.json","pattern":"Hardcoded URL","snippet":"\"https://nextjs.org\",","category":"network","line_end":8,"severity":"low","line_start":8},{"id":"network:metadata.json:9:hardcoded-url","file":"metadata.json","pattern":"Hardcoded URL","snippet":"\"https://swr.vercel.app\",","category":"network","line_end":9,"severity":"low","line_start":9},{"id":"network:metadata.json:10:hardcoded-url","file":"metadata.json","pattern":"Hardcoded URL","snippet":"\"https://github.com/shuding/better-all\",","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:metadata.json:11:hardcoded-url","file":"metadata.json","pattern":"Hardcoded URL","snippet":"\"https://github.com/isaacs/node-lru-cache\",","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:metadata.json:12:hardcoded-url","file":"metadata.json","pattern":"Hardcoded URL","snippet":"\"https://vercel.com/blog/how-we-optimized-package-imports-in-next-js\",","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:metadata.json:13:hardcoded-url","file":"metadata.json","pattern":"Hardcoded URL","snippet":"\"https://vercel.com/blog/how-we-made-the-vercel-dashboard-twice-as-fast\"","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"external_commands:README.md:88:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- Files starting with `_` are special (excluded from build)","category":"external_commands","line_end":89,"severity":"medium","line_start":88},{"id":"external_commands:README.md:89:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- Rule files: `area-description.md` (e.g., `async-parallel.md`)","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:README.md:96:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `CRITICAL` - Highest priority, major performance gains","category":"external_commands","line_end":97,"severity":"medium","line_start":96},{"id":"external_commands:README.md:97:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `HIGH` - Significant performance improvements","category":"external_commands","line_end":98,"severity":"medium","line_start":97},{"id":"external_commands:README.md:98:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `MEDIUM-HIGH` - Moderate-high gains","category":"external_commands","line_end":99,"severity":"medium","line_start":98},{"id":"external_commands:README.md:99:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `MEDIUM` - Moderate performance improvements","category":"external_commands","line_end":100,"severity":"medium","line_start":99},{"id":"external_commands:README.md:100:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `LOW-MEDIUM` - Low-medium gains","category":"external_commands","line_end":101,"severity":"medium","line_start":100},{"id":"external_commands:README.md:101:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `LOW` - Incremental improvements","category":"external_commands","line_end":105,"severity":"medium","line_start":101},{"id":"external_commands:README.md:105:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `pnpm build` - Compile rules into AGENTS.md","category":"external_commands","line_end":106,"severity":"medium","line_start":105},{"id":"external_commands:README.md:106:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `pnpm validate` - Validate all rule files","category":"external_commands","line_end":107,"severity":"medium","line_start":106},{"id":"external_commands:README.md:107:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `pnpm extract-tests` - Extract test cases for LLM evaluation","category":"external_commands","line_end":108,"severity":"medium","line_start":107},{"id":"external_commands:README.md:108:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"- `pnpm dev` - Build and validate","category":"external_commands","line_end":115,"severity":"medium","line_start":108},{"id":"external_commands:README.md:115:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"2. Follow the `_template.md` structure","category":"external_commands","line_end":118,"severity":"medium","line_start":115},{"id":"network:README.md:84:hardcoded-url","file":"README.md","pattern":"Hardcoded URL","snippet":"Reference: [Link](https://example.com)","category":"network","line_end":84,"severity":"low","line_start":84},{"id":"network:README.md:123:hardcoded-url","file":"README.md","pattern":"Hardcoded URL","snippet":"Originally created by [@shuding](https://x.com/shuding) at [Vercel](https://vercel.com).","category":"network","line_end":123,"severity":"low","line_start":123},{"id":"network:rules/_sections.md:26:python-http-libraries","file":"rules/_sections.md","pattern":"Python HTTP libraries","snippet":"**Description:** Automatic deduplication and efficient data fetching patterns reduce redundant netwo","category":"network","line_end":26,"severity":"low","line_start":26},{"id":"blocker:rules/advanced-use-latest.md:27:system-reconnaissance","file":"rules/advanced-use-latest.md","pattern":"System reconnaissance","snippet":"function SearchInput({ onSearch }: { onSearch: (q: string) => void }) {","category":"blocker","line_end":27,"severity":"low","line_start":27},{"id":"blocker:rules/advanced-use-latest.md:40:system-reconnaissance","file":"rules/advanced-use-latest.md","pattern":"System reconnaissance","snippet":"function SearchInput({ onSearch }: { onSearch: (q: string) => void }) {","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"blocker:rules/async-defer-await.md:10:system-reconnaissance","file":"rules/async-defer-await.md","pattern":"System reconnaissance","snippet":"Move `await` operations into the branches where they're actually used to avoid blocking code paths t","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:rules/async-suspense-boundaries.md:97:system-reconnaissance","file":"rules/async-suspense-boundaries.md","pattern":"System reconnaissance","snippet":"- When you want to avoid layout shift (loading → content jump)","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:rules/bundle-barrel-imports.md:2:system-reconnaissance","file":"rules/bundle-barrel-imports.md","pattern":"System reconnaissance","snippet":"title: Avoid Barrel File Imports","category":"blocker","line_end":2,"severity":"low","line_start":2},{"id":"blocker:rules/bundle-barrel-imports.md:8:system-reconnaissance","file":"rules/bundle-barrel-imports.md","pattern":"System reconnaissance","snippet":"## Avoid Barrel File Imports","category":"blocker","line_end":8,"severity":"low","line_start":8},{"id":"blocker:rules/bundle-barrel-imports.md:10:system-reconnaissance","file":"rules/bundle-barrel-imports.md","pattern":"System reconnaissance","snippet":"Import directly from source files instead of barrel files to avoid loading thousands of unused modul","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"scripts:rules/bundle-conditional.md:20:dynamic-import-expression","file":"rules/bundle-conditional.md","pattern":"Dynamic import() expression","snippet":"import('./animation-frames.js')","category":"scripts","line_end":20,"severity":"medium","line_start":20},{"id":"scripts:rules/bundle-defer-third-party.md:35:dynamic-import-expression","file":"rules/bundle-defer-third-party.md","pattern":"Dynamic import() expression","snippet":"() => import('@vercel/analytics/react').then(m => m.Analytics),","category":"scripts","line_end":35,"severity":"medium","line_start":35},{"id":"scripts:rules/bundle-dynamic-imports.md:28:dynamic-import-expression","file":"rules/bundle-dynamic-imports.md","pattern":"Dynamic import() expression","snippet":"() => import('./monaco-editor').then(m => m.MonacoEditor),","category":"scripts","line_end":28,"severity":"medium","line_start":28},{"id":"scripts:rules/bundle-preload.md:18:dynamic-import-expression","file":"rules/bundle-preload.md","pattern":"Dynamic import() expression","snippet":"void import('./monaco-editor')","category":"scripts","line_end":18,"severity":"medium","line_start":18},{"id":"scripts:rules/bundle-preload.md:40:dynamic-import-expression","file":"rules/bundle-preload.md","pattern":"Dynamic import() expression","snippet":"void import('./monaco-editor').then(mod => mod.init())","category":"scripts","line_end":40,"severity":"medium","line_start":40},{"id":"blocker:rules/bundle-preload.md:15:system-reconnaissance","file":"rules/bundle-preload.md","pattern":"System reconnaissance","snippet":"function EditorButton({ onClick }: { onClick: () => void }) {","category":"blocker","line_end":15,"severity":"low","line_start":15},{"id":"blocker:rules/bundle-preload.md:18:system-reconnaissance","file":"rules/bundle-preload.md","pattern":"System reconnaissance","snippet":"void import('./monaco-editor')","category":"blocker","line_end":18,"severity":"low","line_start":18},{"id":"blocker:rules/bundle-preload.md:40:system-reconnaissance","file":"rules/bundle-preload.md","pattern":"System reconnaissance","snippet":"void import('./monaco-editor').then(mod => mod.init())","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"sensitive:rules/client-event-listeners.md:18:certificate-key-files","file":"rules/client-event-listeners.md","pattern":"Certificate/key files","snippet":"if (e.metaKey && e.key === key) {","category":"sensitive","line_end":18,"severity":"high","line_start":18},{"id":"sensitive:rules/client-event-listeners.md:59:certificate-key-files","file":"rules/client-event-listeners.md","pattern":"Certificate/key files","snippet":"if (e.metaKey && keyCallbacks.has(e.key)) {","category":"sensitive","line_end":59,"severity":"high","line_start":59},{"id":"sensitive:rules/client-event-listeners.md:60:certificate-key-files","file":"rules/client-event-listeners.md","pattern":"Certificate/key files","snippet":"keyCallbacks.get(e.key)!.forEach(cb => cb())","category":"sensitive","line_end":60,"severity":"high","line_start":60},{"id":"external_commands:rules/client-localstorage-schema.md:27:ruby-shell-backtick-execution","file":"rules/client-localstorage-schema.md","pattern":"Ruby/shell backtick execution","snippet":"localStorage.setItem(`userConfig:${VERSION}`, JSON.stringify(config))","category":"external_commands","line_end":35,"severity":"medium","line_start":27},{"id":"external_commands:rules/client-localstorage-schema.md:35:ruby-shell-backtick-execution","file":"rules/client-localstorage-schema.md","pattern":"Ruby/shell backtick execution","snippet":"const data = localStorage.getItem(`userConfig:${VERSION}`)","category":"external_commands","line_end":53,"severity":"medium","line_start":35},{"id":"network:rules/client-swr-dedup.md:18:fetch-api-call","file":"rules/client-swr-dedup.md","pattern":"Fetch API call","snippet":"fetch('/api/users')","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"blocker:rules/js-batch-dom-css.md:10:system-reconnaissance","file":"rules/js-batch-dom-css.md","pattern":"System reconnaissance","snippet":"Avoid interleaving style writes with layout reads. When you read a layout property (like `offsetWidt","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:rules/js-batch-dom-css.md:31:system-reconnaissance","file":"rules/js-batch-dom-css.md","pattern":"System reconnaissance","snippet":"element.style.border = '1px solid black'","category":"blocker","line_end":31,"severity":"low","line_start":31},{"id":"blocker:rules/js-batch-dom-css.md:45:system-reconnaissance","file":"rules/js-batch-dom-css.md","pattern":"System reconnaissance","snippet":"border: 1px solid black;","category":"blocker","line_end":45,"severity":"low","line_start":45},{"id":"blocker:rules/js-cache-function-results.md:4:system-reconnaissance","file":"rules/js-cache-function-results.md","pattern":"System reconnaissance","snippet":"impactDescription: avoid redundant computation","category":"blocker","line_end":4,"severity":"low","line_start":4},{"id":"sensitive:rules/js-cache-storage.md:62:certificate-key-files","file":"rules/js-cache-storage.md","pattern":"Certificate/key files","snippet":"if (e.key) storageCache.delete(e.key)","category":"sensitive","line_end":62,"severity":"high","line_start":62},{"id":"external_commands:rules/js-hoist-regexp.md:16:ruby-shell-backtick-execution","file":"rules/js-hoist-regexp.md","pattern":"Ruby/shell backtick execution","snippet":"const regex = new RegExp(`(${query})`, 'gi')","category":"external_commands","line_end":20,"severity":"medium","line_start":16},{"id":"external_commands:rules/js-hoist-regexp.md:29:ruby-shell-backtick-execution","file":"rules/js-hoist-regexp.md","pattern":"Ruby/shell backtick execution","snippet":"() => new RegExp(`(${escapeRegex(query)})`, 'gi'),","category":"external_commands","line_end":35,"severity":"medium","line_start":29},{"id":"blocker:rules/js-index-maps.md:18:system-reconnaissance","file":"rules/js-index-maps.md","pattern":"System reconnaissance","snippet":"user: users.find(u => u.id === order.userId)","category":"blocker","line_end":18,"severity":"low","line_start":18},{"id":"scripts:rules/js-tosorted-immutable.md:57:with-statement-deprecated-scope-confusion","file":"rules/js-tosorted-immutable.md","pattern":"with statement (deprecated, scope confusion)","snippet":"- `.with()` - immutable element replacement","category":"scripts","line_end":57,"severity":"medium","line_start":57},{"id":"blocker:rules/rendering-hoist-jsx.md:10:system-reconnaissance","file":"rules/rendering-hoist-jsx.md","pattern":"System reconnaissance","snippet":"Extract static JSX outside components to avoid re-creation.","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"external_commands:rules/rendering-hydration-no-flicker.md:72:ruby-shell-backtick-execution","file":"rules/rendering-hydration-no-flicker.md","pattern":"Ruby/shell backtick execution","snippet":"`,","category":"external_commands","line_end":78,"severity":"medium","line_start":72},{"id":"blocker:rules/rendering-hydration-no-flicker.md:10:system-reconnaissance","file":"rules/rendering-hydration-no-flicker.md","pattern":"System reconnaissance","snippet":"When rendering content that depends on client-side storage (localStorage, cookies), avoid both SSR b","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:rules/rerender-dependencies.md:20:system-reconnaissance","file":"rules/rerender-dependencies.md","pattern":"System reconnaissance","snippet":"**Correct (re-runs only when id changes):**","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:rules/rerender-functional-setstate.md:25:system-reconnaissance","file":"rules/rerender-functional-setstate.md","pattern":"System reconnaissance","snippet":"setItems(items.filter(item => item.id !== id))","category":"blocker","line_end":25,"severity":"low","line_start":25},{"id":"blocker:rules/rerender-functional-setstate.md:47:system-reconnaissance","file":"rules/rerender-functional-setstate.md","pattern":"System reconnaissance","snippet":"setItems(curr => curr.filter(item => item.id !== id))","category":"blocker","line_end":47,"severity":"low","line_start":47},{"id":"blocker:rules/rerender-memo.md:17:system-reconnaissance","file":"rules/rerender-memo.md","pattern":"System reconnaissance","snippet":"const id = computeAvatarId(user)","category":"blocker","line_end":17,"severity":"low","line_start":17},{"id":"blocker:rules/rerender-memo.md:30:system-reconnaissance","file":"rules/rerender-memo.md","pattern":"System reconnaissance","snippet":"const id = useMemo(() => computeAvatarId(user), [user])","category":"blocker","line_end":30,"severity":"low","line_start":30},{"id":"blocker:rules/server-cache-lru.md:26:system-reconnaissance","file":"rules/server-cache-lru.md","pattern":"System reconnaissance","snippet":"const user = await db.user.findUnique({ where: { id } })","category":"blocker","line_end":26,"severity":"low","line_start":26},{"id":"blocker:rules/server-cache-lru.md:37:system-reconnaissance","file":"rules/server-cache-lru.md","pattern":"System reconnaissance","snippet":"**With Vercel's [Fluid Compute](https://vercel.com/docs/fluid-compute):** LRU caching is especially ","category":"blocker","line_end":37,"severity":"low","line_start":37},{"id":"blocker:rules/server-cache-react.md:21:system-reconnaissance","file":"rules/server-cache-react.md","pattern":"System reconnaissance","snippet":"where: { id: session.user.id }","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"blocker:rules/server-cache-react.md:28:system-reconnaissance","file":"rules/server-cache-react.md","pattern":"System reconnaissance","snippet":"**Avoid inline objects as arguments:**","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"blocker:rules/server-cache-react.md:36:system-reconnaissance","file":"rules/server-cache-react.md","pattern":"System reconnaissance","snippet":"return await db.user.findUnique({ where: { id: params.uid } })","category":"blocker","line_end":36,"severity":"low","line_start":36},{"id":"blocker:rules/server-cache-react.md:48:system-reconnaissance","file":"rules/server-cache-react.md","pattern":"System reconnaissance","snippet":"return await db.user.findUnique({ where: { id: uid } })","category":"blocker","line_end":48,"severity":"low","line_start":48},{"id":"network:rules/server-serialization.md:10:python-http-libraries","file":"rules/server-serialization.md","pattern":"Python HTTP libraries","snippet":"The React Server/Client boundary serializes all object properties into strings and embeds them in th","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 1 | Eliminating Waterfalls | CRITICAL | `async-` |","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 2 | Bundle Size Optimization | CRITICAL | `bundle-` |","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 3 | Server-Side Performance | HIGH | `server-` |","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 4 | Client-Side Data Fetching | MEDIUM-HIGH | `client-` |","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 5 | Re-render Optimization | MEDIUM | `rerender-` |","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 6 | Rendering Performance | MEDIUM | `rendering-` |","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 7 | JavaScript Performance | LOW-MEDIUM | `js-` |","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 8 | Advanced Patterns | LOW | `advanced-` |","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `async-defer-await` - Move await into branches where actually used","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `async-parallel` - Use Promise.all() for independent operations","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `async-dependencies` - Use better-all for partial dependencies","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `async-api-routes` - Start promises early, await late in API routes","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `async-suspense-boundaries` - Use Suspense to stream content","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bundle-barrel-imports` - Import directly, avoid barrel files","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bundle-dynamic-imports` - Use next/dynamic for heavy components","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bundle-defer-third-party` - Load analytics/logging after hydration","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bundle-conditional` - Load modules only when feature is activated","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bundle-preload` - Preload on hover/focus for perceived speed","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `server-cache-react` - Use React.cache() for per-request deduplication","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `server-cache-lru` - Use LRU cache for cross-request caching","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `server-serialization` - Minimize data passed to client components","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `server-parallel-fetching` - Restructure components to parallelize fetches","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `server-after-nonblocking` - Use after() for non-blocking operations","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `client-swr-dedup` - Use SWR for automatic request deduplication","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `client-event-listeners` - Deduplicate global event listeners","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rerender-defer-reads` - Don't subscribe to state only used in callbacks","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rerender-memo` - Extract expensive work into memoized components","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rerender-dependencies` - Use primitive dependencies in effects","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rerender-derived-state` - Subscribe to derived booleans, not raw values","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rerender-functional-setstate` - Use functional setState for stable callbacks","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rerender-lazy-state-init` - Pass function to useState for expensive values","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rerender-transitions` - Use startTransition for non-urgent updates","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rendering-animate-svg-wrapper` - Animate div wrapper, not SVG element","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rendering-content-visibility` - Use content-visibility for long lists","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rendering-hoist-jsx` - Extract static JSX outside components","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rendering-svg-precision` - Reduce SVG coordinate precision","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rendering-hydration-no-flicker` - Use inline script for client-only data","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rendering-activity` - Use Activity component for show/hide","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `rendering-conditional-render` - Use ternary, not && for conditionals","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-batch-dom-css` - Group CSS changes via classes or cssText","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-index-maps` - Build Map for repeated lookups","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-cache-property-access` - Cache object properties in loops","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-cache-function-results` - Cache function results in module-level Map","category":"external_commands","line_end":92,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-cache-storage` - Cache localStorage/sessionStorage reads","category":"external_commands","line_end":93,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-combine-iterations` - Combine multiple filter/map into one loop","category":"external_commands","line_end":94,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-length-check-first` - Check array length before expensive comparison","category":"external_commands","line_end":95,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-early-exit` - Return early from functions","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-hoist-regexp` - Hoist RegExp creation outside loops","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-min-max-loop` - Use loop for min/max instead of sort","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-set-map-lookups` - Use Set/Map for O(1) lookups","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `js-tosorted-immutable` - Use toSorted() for immutability","category":"external_commands","line_end":100,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `advanced-event-handler-refs` - Store event handlers in refs","category":"external_commands","line_end":104,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `advanced-use-latest` - useLatest for stable callback refs","category":"external_commands","line_end":105,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":115,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":125,"severity":"medium","line_start":115},{"id":"blocker:SKILL.md:48:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- `bundle-barrel-imports` - Import directly, avoid barrel files","category":"blocker","line_end":48,"severity":"low","line_start":48}],"finding_verdicts":[{"id":"scripts:AGENTS.md:428:dynamic-import-expression","reason":"The import() match is in AGENTS.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:AGENTS.md:470:dynamic-import-expression","reason":"The import() match is in AGENTS.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:AGENTS.md:508:dynamic-import-expression","reason":"The import() match is in AGENTS.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:AGENTS.md:529:dynamic-import-expression","reason":"The import() match is in AGENTS.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:AGENTS.md:551:dynamic-import-expression","reason":"The import() match is in AGENTS.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:AGENTS.md:2309:with-statement-deprecated-scope-confusion","reason":"The match in AGENTS.md is documentation for the Array .with() method, not a JavaScript with statement. No deprecated scope-confusing construct is executed by the skill.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:AGENTS.md:1056:ruby-shell-backtick-execution","reason":"The match in AGENTS.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:AGENTS.md:1064:ruby-shell-backtick-execution","reason":"The match in AGENTS.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:AGENTS.md:1636:ruby-shell-backtick-execution","reason":"The match in AGENTS.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:AGENTS.md:1758:ruby-shell-backtick-execution","reason":"The match in AGENTS.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:AGENTS.md:2125:ruby-shell-backtick-execution","reason":"The match in AGENTS.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:AGENTS.md:2138:ruby-shell-backtick-execution","reason":"The match in AGENTS.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"network:AGENTS.md:995:fetch-api-call","reason":"The fetch call in AGENTS.md is a documented client-side example using a local API path. The skill repository does not execute this request or send marketplace user data.","verdict":"false_positive","confidence":0.95},{"id":"network:AGENTS.md:612:python-http-libraries","reason":"The match in AGENTS.md is prose about requests or data fetching, not a Python HTTP import or executable network client. No outbound request behavior is present.","verdict":"false_positive","confidence":0.96},{"id":"network:AGENTS.md:867:python-http-libraries","reason":"The match in AGENTS.md is prose about requests or data fetching, not a Python HTTP import or executable network client. No outbound request behavior is present.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:AGENTS.md:881:certificate-key-files","reason":"The snippet in AGENTS.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:AGENTS.md:922:certificate-key-files","reason":"The snippet in AGENTS.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:AGENTS.md:923:certificate-key-files","reason":"The snippet in AGENTS.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:AGENTS.md:1980:certificate-key-files","reason":"The snippet in AGENTS.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"blocker:AGENTS.md:30:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:91:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:347:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:359:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:363:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:526:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:529:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:551:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:591:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:602:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:736:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:743:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:751:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1156:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1169:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1199:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1270:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1292:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1508:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1574:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1718:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1728:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1740:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1757:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1804:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1852:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:2376:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:2389:system-reconnaissance","reason":"The match in AGENTS.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:AGENTS.md:1732:network-reconnaissance","reason":"The match in AGENTS.md describes CSS reflow in documentation, not network scanning or endpoint discovery. No network reconnaissance behavior exists.","verdict":"false_positive","confidence":0.98},{"id":"network:metadata.json:7:hardcoded-url","reason":"The URL in metadata.json is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:metadata.json:8:hardcoded-url","reason":"The URL in metadata.json is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:metadata.json:9:hardcoded-url","reason":"The URL in metadata.json is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:metadata.json:10:hardcoded-url","reason":"The URL in metadata.json is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:metadata.json:11:hardcoded-url","reason":"The URL in metadata.json is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:metadata.json:12:hardcoded-url","reason":"The URL in metadata.json is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:metadata.json:13:hardcoded-url","reason":"The URL in metadata.json is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:README.md:88:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:89:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:96:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:97:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:98:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:99:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:100:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:101:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:105:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:106:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:107:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:108:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:README.md:115:ruby-shell-backtick-execution","reason":"The match in README.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"network:README.md:84:hardcoded-url","reason":"The URL in README.md is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:README.md:123:hardcoded-url","reason":"The URL in README.md is a public documentation or reference link. The skill does not automatically fetch it, exfiltrate data, or contact a suspicious endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:rules/_sections.md:26:python-http-libraries","reason":"The match in rules/_sections.md is prose about requests or data fetching, not a Python HTTP import or executable network client. No outbound request behavior is present.","verdict":"false_positive","confidence":0.96},{"id":"blocker:rules/advanced-use-latest.md:27:system-reconnaissance","reason":"The match in rules/advanced-use-latest.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/advanced-use-latest.md:40:system-reconnaissance","reason":"The match in rules/advanced-use-latest.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/async-defer-await.md:10:system-reconnaissance","reason":"The match in rules/async-defer-await.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/async-suspense-boundaries.md:97:system-reconnaissance","reason":"The match in rules/async-suspense-boundaries.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/bundle-barrel-imports.md:2:system-reconnaissance","reason":"The match in rules/bundle-barrel-imports.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/bundle-barrel-imports.md:8:system-reconnaissance","reason":"The match in rules/bundle-barrel-imports.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/bundle-barrel-imports.md:10:system-reconnaissance","reason":"The match in rules/bundle-barrel-imports.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"scripts:rules/bundle-conditional.md:20:dynamic-import-expression","reason":"The import() match is in rules/bundle-conditional.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:rules/bundle-defer-third-party.md:35:dynamic-import-expression","reason":"The import() match is in rules/bundle-defer-third-party.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:rules/bundle-dynamic-imports.md:28:dynamic-import-expression","reason":"The import() match is in rules/bundle-dynamic-imports.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:rules/bundle-preload.md:18:dynamic-import-expression","reason":"The import() match is in rules/bundle-preload.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"scripts:rules/bundle-preload.md:40:dynamic-import-expression","reason":"The import() match is in rules/bundle-preload.md, a Markdown documentation example about lazy loading hardcoded React modules. It is not executable skill code or untrusted dynamic module loading.","verdict":"false_positive","confidence":0.96},{"id":"blocker:rules/bundle-preload.md:15:system-reconnaissance","reason":"The match in rules/bundle-preload.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/bundle-preload.md:18:system-reconnaissance","reason":"The match in rules/bundle-preload.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/bundle-preload.md:40:system-reconnaissance","reason":"The match in rules/bundle-preload.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:rules/client-event-listeners.md:18:certificate-key-files","reason":"The snippet in rules/client-event-listeners.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:rules/client-event-listeners.md:59:certificate-key-files","reason":"The snippet in rules/client-event-listeners.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:rules/client-event-listeners.md:60:certificate-key-files","reason":"The snippet in rules/client-event-listeners.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:rules/client-localstorage-schema.md:27:ruby-shell-backtick-execution","reason":"The match in rules/client-localstorage-schema.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:rules/client-localstorage-schema.md:35:ruby-shell-backtick-execution","reason":"The match in rules/client-localstorage-schema.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"network:rules/client-swr-dedup.md:18:fetch-api-call","reason":"The fetch call in rules/client-swr-dedup.md is a documented client-side example using a local API path. The skill repository does not execute this request or send marketplace user data.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/js-batch-dom-css.md:10:system-reconnaissance","reason":"The match in rules/js-batch-dom-css.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/js-batch-dom-css.md:31:system-reconnaissance","reason":"The match in rules/js-batch-dom-css.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/js-batch-dom-css.md:45:system-reconnaissance","reason":"The match in rules/js-batch-dom-css.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/js-cache-function-results.md:4:system-reconnaissance","reason":"The match in rules/js-cache-function-results.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:rules/js-cache-storage.md:62:certificate-key-files","reason":"The snippet in rules/js-cache-storage.md refers to KeyboardEvent or StorageEvent e.key in a React example. It is not certificate material, private key handling, or filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:rules/js-hoist-regexp.md:16:ruby-shell-backtick-execution","reason":"The match in rules/js-hoist-regexp.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:rules/js-hoist-regexp.md:29:ruby-shell-backtick-execution","reason":"The match in rules/js-hoist-regexp.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"blocker:rules/js-index-maps.md:18:system-reconnaissance","reason":"The match in rules/js-index-maps.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"scripts:rules/js-tosorted-immutable.md:57:with-statement-deprecated-scope-confusion","reason":"The match in rules/js-tosorted-immutable.md is documentation for the Array .with() method, not a JavaScript with statement. No deprecated scope-confusing construct is executed by the skill.","verdict":"false_positive","confidence":0.98},{"id":"blocker:rules/rendering-hoist-jsx.md:10:system-reconnaissance","reason":"The match in rules/rendering-hoist-jsx.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:rules/rendering-hydration-no-flicker.md:72:ruby-shell-backtick-execution","reason":"The match in rules/rendering-hydration-no-flicker.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"blocker:rules/rendering-hydration-no-flicker.md:10:system-reconnaissance","reason":"The match in rules/rendering-hydration-no-flicker.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/rerender-dependencies.md:20:system-reconnaissance","reason":"The match in rules/rerender-dependencies.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/rerender-functional-setstate.md:25:system-reconnaissance","reason":"The match in rules/rerender-functional-setstate.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/rerender-functional-setstate.md:47:system-reconnaissance","reason":"The match in rules/rerender-functional-setstate.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/rerender-memo.md:17:system-reconnaissance","reason":"The match in rules/rerender-memo.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/rerender-memo.md:30:system-reconnaissance","reason":"The match in rules/rerender-memo.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/server-cache-lru.md:26:system-reconnaissance","reason":"The match in rules/server-cache-lru.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/server-cache-lru.md:37:system-reconnaissance","reason":"The match in rules/server-cache-lru.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/server-cache-react.md:21:system-reconnaissance","reason":"The match in rules/server-cache-react.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/server-cache-react.md:28:system-reconnaissance","reason":"The match in rules/server-cache-react.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/server-cache-react.md:36:system-reconnaissance","reason":"The match in rules/server-cache-react.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"blocker:rules/server-cache-react.md:48:system-reconnaissance","reason":"The match in rules/server-cache-react.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95},{"id":"network:rules/server-serialization.md:10:python-http-libraries","reason":"The match in rules/server-serialization.md is prose about requests or data fetching, not a Python HTTP import or executable network client. No outbound request behavior is present.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The match in SKILL.md is Markdown backtick formatting or a TypeScript template literal inside an example. There is no Ruby code, shell execution, or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:48:system-reconnaissance","reason":"The match in SKILL.md is ordinary React, Next.js, or JavaScript performance documentation. It does not probe the host system, enumerate files, or collect environment details.","verdict":"false_positive","confidence":0.95}],"semantic_findings":[{"title":"Unverified Official Affiliation Claim","severity":"medium","locations":[{"file":"SKILL.md","line_end":12,"line_start":3},{"file":"AGENTS.md","line_end":10,"line_start":3},{"file":"metadata.json","line_end":3,"line_start":3}],"confidence":0.82,"description":"The community-sourced skill presents itself with official Vercel attribution, including Vercel Engineering, author vercel, and maintained by Vercel language. This can mislead users about provenance and review authority.","confidence_reasoning":"The report source type is community, but multiple files state or imply official Vercel ownership. This is a provenance and marketplace trust issue rather than executable malware."}],"subject_marketplace_commit_sha":"88a205c7f635a966e31156313b590d59007c5caa","subject_content_hash":"81bad0edc74bc4969ea6abf75b0f84dd99a0557fb0d52a2f74c06cf0567833e1","subject_tree_hash":"9a5d6fdd43f029f5e6f2d4fdf826416f52a9f4717feac20b43eba66f12cac1f7","subject_plugin_path":"skills/zhanlincui/vercel-react-best-practices","audit_payload_hash":"28f52787cf04e1cf65df09d55f544193","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"88a205c7f635a966e31156313b590d59007c5caa","contentHash":"81bad0edc74bc4969ea6abf75b0f84dd99a0557fb0d52a2f74c06cf0567833e1","treeHash":"9a5d6fdd43f029f5e6f2d4fdf826416f52a9f4717feac20b43eba66f12cac1f7","pluginPath":"skills/zhanlincui/vercel-react-best-practices","auditPayloadHash":"28f52787cf04e1cf65df09d55f544193"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}