{"data":{"skill":{"slug":"zl2023github-security-engineer","name":"security-engineer","icon":"📦","repo":"https://github.com/zl2023github/software-engineer-skills/tree/main/software-engineering/security-engineer","status":"approved","author":"zl2023github","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"1b63b331-672f-4521-8d90-d44ec7d0d2a7","skill_id":"6c00f9a3-a03e-4efa-904b-2312ed8ea0b9","version":4,"content_hash":"v3:88a8e9a07f4c54ab105c1c41b6267c287146b07b:a2b2ad42ce197e1fb9d7686e137c526fed7af39c3cded0eedaaccedae60e1481:995b2118c312bbead381edb2369e84034f4aded2f47e364079b75a1a37baf9dc:736b696c6c732f7a6c323032336769746875622f73656375726974792d656e67696e656572:66ddfb8daeb86700aef35428d714f31a","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most critical static alerts are false positives caused by defensive examples, public references, and Markdown syntax. Actionable scanning, sensitive-data inspection, destructive removal, and an unaudited hidden-path script remain confirmed risks. The broad post-exploitation workflow creates additional high dual-use risk despite its authorization reminder.","remediation":[{"issue":"The workflow includes exploitation, privilege escalation, lateral movement, and brute-force activity.","severity":"high","suggestion":"Require written scope, target allowlisting, and separate user confirmation before each active or post-exploitation action. Remove lateral movement and brute-force guidance from default workflows."},{"issue":"The ClamAV example recursively deletes detected files with --remove.","severity":"high","suggestion":"Replace deletion with quarantine and require review before any removal. State the affected path and backup status before execution."},{"issue":"The PDF guide executes a generator from an unaudited hidden home-directory path.","severity":"high","suggestion":"Package the generator with the skill, reference it by a package-relative path, and verify its integrity before execution."},{"issue":"Several scanner and forensic commands can affect targets or expose sensitive data.","severity":"medium","suggestion":"Add per-command impact notes, least-impact defaults, secret redaction, bounded paths, and explicit confirmation before execution."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/pdf-guide.md","line_end":31,"line_start":31},{"file":"references/pdf-guide.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":213,"line_start":213},{"file":"SKILL.md","line_end":308,"line_start":308}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":37,"line_start":35},{"file":"SKILL.md","line_end":40,"line_start":37},{"file":"SKILL.md","line_end":41,"line_start":40},{"file":"SKILL.md","line_end":42,"line_start":41},{"file":"SKILL.md","line_end":43,"line_start":42},{"file":"SKILL.md","line_end":44,"line_start":43},{"file":"SKILL.md","line_end":45,"line_start":44},{"file":"SKILL.md","line_end":51,"line_start":45},{"file":"SKILL.md","line_end":53,"line_start":51},{"file":"SKILL.md","line_end":61,"line_start":53},{"file":"SKILL.md","line_end":62,"line_start":61},{"file":"SKILL.md","line_end":63,"line_start":62},{"file":"SKILL.md","line_end":69,"line_start":63},{"file":"SKILL.md","line_end":71,"line_start":69},{"file":"SKILL.md","line_end":74,"line_start":71},{"file":"SKILL.md","line_end":75,"line_start":74},{"file":"SKILL.md","line_end":76,"line_start":75},{"file":"SKILL.md","line_end":77,"line_start":76},{"file":"SKILL.md","line_end":78,"line_start":77},{"file":"SKILL.md","line_end":90,"line_start":78},{"file":"SKILL.md","line_end":92,"line_start":90},{"file":"SKILL.md","line_end":95,"line_start":92},{"file":"SKILL.md","line_end":96,"line_start":95},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":102,"line_start":97},{"file":"SKILL.md","line_end":104,"line_start":102},{"file":"SKILL.md","line_end":107,"line_start":104},{"file":"SKILL.md","line_end":108,"line_start":107},{"file":"SKILL.md","line_end":109,"line_start":108},{"file":"SKILL.md","line_end":113,"line_start":109},{"file":"SKILL.md","line_end":117,"line_start":113},{"file":"SKILL.md","line_end":119,"line_start":117},{"file":"SKILL.md","line_end":122,"line_start":119},{"file":"SKILL.md","line_end":123,"line_start":122},{"file":"SKILL.md","line_end":129,"line_start":123},{"file":"SKILL.md","line_end":131,"line_start":129},{"file":"SKILL.md","line_end":135,"line_start":131},{"file":"SKILL.md","line_end":135,"line_start":135},{"file":"SKILL.md","line_end":137,"line_start":136},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":146,"line_start":144},{"file":"SKILL.md","line_end":150,"line_start":146},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":152,"line_start":151},{"file":"SKILL.md","line_end":152,"line_start":152},{"file":"SKILL.md","line_end":159,"line_start":157},{"file":"SKILL.md","line_end":162,"line_start":159},{"file":"SKILL.md","line_end":162,"line_start":162},{"file":"SKILL.md","line_end":165,"line_start":164},{"file":"SKILL.md","line_end":166,"line_start":165}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":209,"line_start":209},{"file":"SKILL.md","line_end":209,"line_start":209},{"file":"SKILL.md","line_end":372,"line_start":372},{"file":"SKILL.md","line_end":373,"line_start":373},{"file":"SKILL.md","line_end":374,"line_start":374},{"file":"SKILL.md","line_end":375,"line_start":375},{"file":"SKILL.md","line_end":376,"line_start":376},{"file":"SKILL.md","line_end":377,"line_start":377},{"file":"SKILL.md","line_end":209,"line_start":209}]}],"critical_findings":[],"high_findings":[{"title":"Hidden file in home directory","locations":[{"file":"references/pdf-guide.md","line_end":31,"line_start":31}],"confidence":0.96,"description":"python3 ~/.hermes/skills/software-engineering/security-engineer/scripts/generate_pdf.py","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The guide instructs execution of a Python script from a hidden home-directory path, but that script is absent from the audited package. This can execute unverified code outside the package boundary."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":41,"line_start":40}],"confidence":0.97,"description":"- `nmap -sV -sC -O <target>` — 端口扫描+服务指纹+OS检测","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":62,"line_start":61}],"confidence":0.97,"description":"- **SQLMap**:`sqlmap -u <url> --data=<data> --batch --level=3 --risk=2`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":63,"line_start":62}],"confidence":0.97,"description":"- **OWASP ZAP**:`zap-cli quick-scan --self-contained <url>`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":69,"line_start":63}],"confidence":0.97,"description":"- **Nikto**:`nikto -h <target> -ssl -Format html -o report.html`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":96,"line_start":95}],"confidence":0.97,"description":"- **Nessus / OpenVAS**:`openvas-start && gvm-cli --gmp-username admin --gmp-password <pass> socket -","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The command starts OpenVAS and passes a scanner password on the command line. It changes service state and can expose the supplied password through shell history or process inspection."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":102,"line_start":97}],"confidence":0.97,"description":"- **Nuclei**:`nuclei -u <target> -severity critical,high -o results.txt`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":150,"line_start":150}],"confidence":0.94,"description":"- **Wazuh**:`/var/ossec/bin/wazuh-control status` → 告警查看 `cat /var/ossec/logs/alerts/alerts.json`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":162,"line_start":162}],"confidence":0.94,"description":"- **Volatility**:`volatility -f memory.dump --profile=<profile> pslist` / `netscan`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":166,"line_start":165}],"confidence":0.94,"description":"- **Strings**:`strings <binary> | grep -i 'password\\|secret\\|key\\|http'`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":175,"line_start":168}],"confidence":0.98,"description":"- **ClamAV**:`clamscan -r <path> --remove`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill supplies an actionable recursive ClamAV command with --remove. Executing it can delete files without quarantine, review, or per-file confirmation."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":40,"line_start":40}],"confidence":0.99,"description":"- `nmap -sV -sC -O <target>` — 端口扫描+服务指纹+OS检测","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":272,"line_start":272}],"confidence":0.99,"description":"nmap -sV -sC -O -A -T4 <target> -oA scan_result","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":275,"line_start":275}],"confidence":0.99,"description":"nmap -p- --min-rate=1000 <target> -oG all_ports.txt","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":278,"line_start":278}],"confidence":0.99,"description":"nmap -sV -p <ports> <target>","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."},{"title":"Offensive Post-Exploitation Workflow","locations":[{"file":"SKILL.md","line_end":60,"line_start":49}],"confidence":0.98,"description":"The Web testing workflow explicitly progresses through exploitation, privilege escalation, and lateral movement, while also recommending parameter and dictionary brute forcing.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The offensive progression and brute-force guidance are explicit in the workflow. A general authorization reminder exists, but no per-action approval or technical scope control is defined."}],"medium_findings":[{"title":"Hidden file access","locations":[{"file":"references/pdf-guide.md","line_end":31,"line_start":31}],"confidence":0.96,"description":"python3 ~/.hermes/skills/software-engineering/security-engineer/scripts/generate_pdf.py","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The regeneration command accesses and executes a script under ~/.hermes rather than a package-relative audited file. The external hidden path creates an integrity and provenance risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":75,"line_start":74}],"confidence":0.92,"description":"- **Semgrep**:`semgrep --config=auto --config=p/r2c-security-audit <path>`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":76,"line_start":75}],"confidence":0.92,"description":"- **SonarQube**:`sonar-scanner -Dsonar.projectKey=<key> -Dsonar.sources=.`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":77,"line_start":76}],"confidence":0.92,"description":"- **Trivy**:`trivy fs --scanners vuln,secret,misconfig <path>`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":78,"line_start":77}],"confidence":0.92,"description":"- **Bandit**(Python):`bandit -r <path> -f json -o report.json`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":90,"line_start":78}],"confidence":0.92,"description":"- **Safety**(Python依赖):`safety check -r requirements.txt`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":96,"line_start":96}],"confidence":0.92,"description":"- **Trivy**:`trivy image <image>` / `trivy fs --scanners vuln,secret,misconfig <path>`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":108,"line_start":107}],"confidence":0.92,"description":"- **ELK Stack**:`curl -XGET 'localhost:9200/_search'` 查询日志","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":109,"line_start":108}],"confidence":0.92,"description":"- **Wazuh**:`/var/ossec/bin/wazuh-control status` 检查状态","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":113,"line_start":109}],"confidence":0.92,"description":"- **Grep/awk/sed**:日志快速过滤 `grep -E 'Failed password|Invalid user' /var/log/auth.log`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":117,"line_start":113}],"confidence":0.92,"description":"- **YARA**:`yara -r <rules.yar> <path>` 恶意文件扫描","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":123,"line_start":122}],"confidence":0.92,"description":"- **OpenSCAP**:`oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_<profile> --results ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":129,"line_start":123}],"confidence":0.92,"description":"- **Lynis**:`lynis audit system --quick`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":152,"line_start":151}],"confidence":0.92,"description":"- **Osquery**:`osqueryi \"SELECT * FROM processes WHERE name LIKE '%malware%';\"`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":152,"line_start":152}],"confidence":0.92,"description":"- **Auditd**:`ausearch -m avc -ts today` / `aureport --summary`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":165,"line_start":164}],"confidence":0.92,"description":"- **YARA**:`yara -r <rules.yar> <path>`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":168,"line_start":166}],"confidence":0.92,"description":"- **Lsof**:`lsof -i -P -n` 查看网络连接","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval."}],"low_findings":[],"dangerous_patterns":[{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":40,"line_start":40}],"confidence":0.99,"description":"- `nmap -sV -sC -O <target>` — 端口扫描+服务指纹+OS检测","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":272,"line_start":272}],"confidence":0.99,"description":"nmap -sV -sC -O -A -T4 <target> -oA scan_result","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":275,"line_start":275}],"confidence":0.99,"description":"nmap -p- --min-rate=1000 <target> -oG all_ports.txt","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."},{"title":"Network scanning tools","locations":[{"file":"SKILL.md","line_end":278,"line_start":278}],"confidence":0.99,"description":"nmap -sV -p <ports> <target>","review_kind":"security","source_category":"blocker","source_severity":"high","confidence_reasoning":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets."}],"files_scanned":2,"total_lines":416,"audit_model":"codex","audited_at":"2026-07-24T00:04:01.986+00:00","created_at":"2026-07-26T17:17:44.999329+00:00","static_findings":[{"id":"filesystem:references/pdf-guide.md:31:hidden-file-in-home-directory","file":"references/pdf-guide.md","pattern":"Hidden file in home directory","snippet":"python3 ~/.hermes/skills/software-engineering/security-engineer/scripts/generate_pdf.py","category":"filesystem","line_end":31,"severity":"high","line_start":31},{"id":"filesystem:references/pdf-guide.md:31:hidden-file-access","file":"references/pdf-guide.md","pattern":"Hidden file access","snippet":"python3 ~/.hermes/skills/software-engineering/security-engineer/scripts/generate_pdf.py","category":"filesystem","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":37,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":40,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nmap -sV -sC -O <target>` — 端口扫描+服务指纹+OS检测","category":"external_commands","line_end":41,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `subfinder / amass / sublist3r` — 子域名枚举","category":"external_commands","line_end":42,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `httpx / httprobe` — HTTP服务存活探测","category":"external_commands","line_end":43,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `whatweb / wappalyzer` — Web技术栈指纹识别","category":"external_commands","line_end":44,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `theHarvester` — 邮箱/子域/主机信息收集","category":"external_commands","line_end":45,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `dnsrecon / dig` — DNS枚举与区域传输检测","category":"external_commands","line_end":51,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":61,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **SQLMap**:`sqlmap -u <url> --data=<data> --batch --level=3 --risk=2`","category":"external_commands","line_end":62,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **OWASP ZAP**:`zap-cli quick-scan --self-contained <url>`","category":"external_commands","line_end":63,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Nikto**:`nikto -h <target> -ssl -Format html -o report.html`","category":"external_commands","line_end":69,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":74,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Semgrep**:`semgrep --config=auto --config=p/r2c-security-audit <path>`","category":"external_commands","line_end":75,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **SonarQube**:`sonar-scanner -Dsonar.projectKey=<key> -Dsonar.sources=.`","category":"external_commands","line_end":76,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Trivy**:`trivy fs --scanners vuln,secret,misconfig <path>`","category":"external_commands","line_end":77,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Bandit**(Python):`bandit -r <path> -f json -o report.json`","category":"external_commands","line_end":78,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Safety**(Python依赖):`safety check -r requirements.txt`","category":"external_commands","line_end":90,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":92,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":95,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Nessus / OpenVAS**:`openvas-start && gvm-cli --gmp-username admin --gmp-password <pass> socket -","category":"external_commands","line_end":96,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Trivy**:`trivy image <image>` / `trivy fs --scanners vuln,secret,misconfig <path>`","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Nuclei**:`nuclei -u <target> -severity critical,high -o results.txt`","category":"external_commands","line_end":102,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":104,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":107,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **ELK Stack**:`curl -XGET 'localhost:9200/_search'` 查询日志","category":"external_commands","line_end":108,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Wazuh**:`/var/ossec/bin/wazuh-control status` 检查状态","category":"external_commands","line_end":109,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Grep/awk/sed**:日志快速过滤 `grep -E 'Failed password|Invalid user' /var/log/auth.log`","category":"external_commands","line_end":113,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **YARA**:`yara -r <rules.yar> <path>` 恶意文件扫描","category":"external_commands","line_end":117,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":119,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":122,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **OpenSCAP**:`oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_<profile> --results ","category":"external_commands","line_end":123,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Lynis**:`lynis audit system --quick`","category":"external_commands","line_end":129,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":131,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":135,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- 防火墙:`ufw`/`iptables`/`nftables` 最小开放原则","category":"external_commands","line_end":135,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- 内核参数:`sysctl` 配置(net.ipv4.tcp_syncookies, kernel.randomize_va_space等)","category":"external_commands","line_end":137,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- 文件权限:`chmod`/`chown` 最小权限","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":146,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":150,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Wazuh**:`/var/ossec/bin/wazuh-control status` → 告警查看 `cat /var/ossec/logs/alerts/alerts.json`","category":"external_commands","line_end":150,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Osquery**:`osqueryi \"SELECT * FROM processes WHERE name LIKE '%malware%';\"`","category":"external_commands","line_end":152,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Auditd**:`ausearch -m avc -ts today` / `aureport --summary`","category":"external_commands","line_end":152,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":159,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":162,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Volatility**:`volatility -f memory.dump --profile=<profile> pslist` / `netscan`","category":"external_commands","line_end":162,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **YARA**:`yara -r <rules.yar> <path>`","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Strings**:`strings <binary> | grep -i 'password\\|secret\\|key\\|http'`","category":"external_commands","line_end":166,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Lsof**:`lsof -i -P -n` 查看网络连接","category":"external_commands","line_end":168,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **ClamAV**:`clamscan -r <path> --remove`","category":"external_commands","line_end":175,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":200,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":206,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| SQL注入 | `' OR 1=1 --` / SQLMap | 参数化查询/ORM/输入白名单 |","category":"external_commands","line_end":207,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| XSS | `<script>alert(1)</script>` | 输出编码/CSP/HttpOnly Cookie |","category":"external_commands","line_end":209,"severity":"medium","line_start":207},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| SSRF | `?url=http://169.254.169.254/` | URL白名单/内网DNS解析限制 |","category":"external_commands","line_end":210,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| XXE | `<!ENTITY xxe SYSTEM \"file:///etc/passwd\">` | 禁用外部实体解析 |","category":"external_commands","line_end":212,"severity":"medium","line_start":210},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 命令注入 | `;id` / `|id` / `$(id)` | 输入白名单/不使用shell执行 |","category":"external_commands","line_end":212,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 路径遍历 | `../../../etc/passwd` | 路径规范化/白名单 |","category":"external_commands","line_end":215,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| JWT安全问题 | `alg:none` / 弱密钥 / 未验证签名 | 使用强算法+验证签名+短过期时间 |","category":"external_commands","line_end":216,"severity":"medium","line_start":215},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| SSTI | `{{7*7}}` / `${7*7}` | 模板引擎沙箱/不拼接用户输入 |","category":"external_commands","line_end":216,"severity":"medium","line_start":216},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 不安全的反序列化 | `O:8:\"stdClass\":0:{}` | 使用安全序列化格式/签名验证 |","category":"external_commands","line_end":270,"severity":"medium","line_start":217},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":327,"severity":"medium","line_start":270},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":333,"severity":"medium","line_start":327},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":382,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"完整技能内容(含所有工作流、命令、表格、检查清单)已输出为 PDF 指南(16页),文件位置:**`~/security_engineer_agent_guide.pdf`**。见 `referenc","category":"external_commands","line_end":382,"severity":"medium","line_start":382},{"id":"external_commands:SKILL.md:212:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"| 命令注入 | `;id` / `|id` / `$(id)` | 输入白名单/不使用shell执行 |","category":"external_commands","line_end":212,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:212:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"| 命令注入 | `;id` / `|id` / `$(id)` | 输入白名单/不使用shell执行 |","category":"external_commands","line_end":212,"severity":"medium","line_start":212},{"id":"network:SKILL.md:209:aws-azure-metadata-endpoint","file":"SKILL.md","pattern":"AWS/Azure metadata endpoint","snippet":"| SSRF | `?url=http://169.254.169.254/` | URL白名单/内网DNS解析限制 |","category":"network","line_end":209,"severity":"critical","line_start":209},{"id":"network:SKILL.md:209:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| SSRF | `?url=http://169.254.169.254/` | URL白名单/内网DNS解析限制 |","category":"network","line_end":209,"severity":"low","line_start":209},{"id":"network:SKILL.md:372:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **OWASP Top 10**:https://owasp.org/www-project-top-ten/","category":"network","line_end":372,"severity":"low","line_start":372},{"id":"network:SKILL.md:373:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **CVE数据库**:https://cve.mitre.org / https://nvd.nist.gov","category":"network","line_end":373,"severity":"low","line_start":373},{"id":"network:SKILL.md:374:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Exploit-DB**:https://www.exploit-db.com","category":"network","line_end":374,"severity":"low","line_start":374},{"id":"network:SKILL.md:375:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **MITRE ATT&CK**:https://attack.mitre.org","category":"network","line_end":375,"severity":"low","line_start":375},{"id":"network:SKILL.md:376:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **CIS Benchmarks**:https://www.cisecurity.org/cis-benchmarks","category":"network","line_end":376,"severity":"low","line_start":376},{"id":"network:SKILL.md:377:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **HackerOne Hacktivity**:https://hackerone.com/hacktivity","category":"network","line_end":377,"severity":"low","line_start":377},{"id":"network:SKILL.md:209:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"| SSRF | `?url=http://169.254.169.254/` | URL白名单/内网DNS解析限制 |","category":"network","line_end":209,"severity":"medium","line_start":209},{"id":"filesystem:SKILL.md:213:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| 路径遍历 | `../../../etc/passwd` | 路径规范化/白名单 |","category":"filesystem","line_end":213,"severity":"high","line_start":213},{"id":"filesystem:SKILL.md:308:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"find / -perm -4000 -type f 2>/dev/null","category":"filesystem","line_end":308,"severity":"low","line_start":308},{"id":"blocker:SKILL.md:17:metasploit-framework","file":"SKILL.md","pattern":"Metasploit framework","snippet":"- 安全工具使用(Burp Suite, Nmap, Metasploit等)","category":"blocker","line_end":17,"severity":"critical","line_start":17},{"id":"blocker:SKILL.md:167:malware-type-keywords","file":"SKILL.md","pattern":"Malware type keywords","snippet":"- **Chkrootkit / Rkhunter**:Rootkit检测","category":"blocker","line_end":167,"severity":"high","line_start":167},{"id":"blocker:SKILL.md:210:system-password-file-access","file":"SKILL.md","pattern":"System password file access","snippet":"| XXE | `<!ENTITY xxe SYSTEM \"file:///etc/passwd\">` | 禁用外部实体解析 |","category":"blocker","line_end":210,"severity":"critical","line_start":210},{"id":"blocker:SKILL.md:213:system-password-file-access","file":"SKILL.md","pattern":"System password file access","snippet":"| 路径遍历 | `../../../etc/passwd` | 路径规范化/白名单 |","category":"blocker","line_end":213,"severity":"critical","line_start":213},{"id":"blocker:SKILL.md:305:system-password-file-access","file":"SKILL.md","pattern":"System password file access","snippet":"awk -F: '($3 == 0) {print}' /etc/passwd","category":"blocker","line_end":305,"severity":"critical","line_start":305},{"id":"blocker:SKILL.md:109:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Grep/awk/sed**:日志快速过滤 `grep -E 'Failed password|Invalid user' /var/log/auth.log`","category":"blocker","line_end":109,"severity":"low","line_start":109},{"id":"blocker:SKILL.md:110:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- **lsof/netstat/ss**:检查网络连接和监听端口","category":"blocker","line_end":110,"severity":"low","line_start":110},{"id":"blocker:SKILL.md:299:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"ss -tlnp","category":"blocker","line_end":299,"severity":"low","line_start":299},{"id":"blocker:SKILL.md:318:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"ss -tlnp","category":"blocker","line_end":318,"severity":"low","line_start":318},{"id":"blocker:SKILL.md:17:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"- 安全工具使用(Burp Suite, Nmap, Metasploit等)","category":"blocker","line_end":17,"severity":"high","line_start":17},{"id":"blocker:SKILL.md:40:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"- `nmap -sV -sC -O <target>` — 端口扫描+服务指纹+OS检测","category":"blocker","line_end":40,"severity":"high","line_start":40},{"id":"blocker:SKILL.md:271:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"# Nmap全面扫描","category":"blocker","line_end":271,"severity":"high","line_start":271},{"id":"blocker:SKILL.md:272:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"nmap -sV -sC -O -A -T4 <target> -oA scan_result","category":"blocker","line_end":272,"severity":"high","line_start":272},{"id":"blocker:SKILL.md:275:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"nmap -p- --min-rate=1000 <target> -oG all_ports.txt","category":"blocker","line_end":275,"severity":"high","line_start":275},{"id":"blocker:SKILL.md:278:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"nmap -sV -p <ports> <target>","category":"blocker","line_end":278,"severity":"high","line_start":278},{"id":"obfuscation:references/pdf-guide.md:1:heuristic-high-file-entropy-6-56-bits-possible-b","file":"references/pdf-guide.md","pattern":"[HEURISTIC] High file entropy (6.56 bits) - possible binary/encrypted content","snippet":"File: references/pdf-guide.md","category":"obfuscation","line_end":1,"severity":"high","line_start":1},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-6-84-bits-possible-b","file":"SKILL.md","pattern":"[HEURISTIC] High file entropy (6.84 bits) - possible binary/encrypted content","snippet":"File: SKILL.md","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"filesystem:references/pdf-guide.md:31:hidden-file-in-home-directory","reason":"The guide instructs execution of a Python script from a hidden home-directory path, but that script is absent from the audited package. This can execute unverified code outside the package boundary.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"filesystem:references/pdf-guide.md:31:hidden-file-access","reason":"The regeneration command accesses and executes a script under ~/.hermes rather than a package-relative audited file. The external hidden path creates an integrity and provenance risk.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"The command starts OpenVAS and passes a scanner password on the command line. It changes service state and can expose the supplied password through shell history or process inspection.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"This is an actionable active-scanning or injection-testing command against a user-selected target. It can disrupt services or probe systems outside an authorized scope.","verdict":"confirmed","severity":"high","confidence":0.97},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The backticks format security tool or configuration names in Markdown. This line does not contain a complete command or a Ruby execution construct.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data.","verdict":"confirmed","severity":"high","confidence":0.94},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data.","verdict":"confirmed","severity":"high","confidence":0.94},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"This actionable forensic command reads security alerts, memory data, or strings associated with credentials and secrets. Its output can expose sensitive operational data.","verdict":"confirmed","severity":"high","confidence":0.94},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The skill presents a complete external command for execution against local files, services, logs, or images. Execution can read data or change local tool state and requires explicit approval.","verdict":"confirmed","severity":"medium","confidence":0.92},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The skill supplies an actionable recursive ClamAV command with --remove. Executing it can delete files without quarantine, review, or per-file confirmation.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The matched text is a Markdown code-fence delimiter, not Ruby backtick syntax or shell execution. This finding contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","reason":"The backticks format a PDF path and a reference filename. They do not invoke a shell or Ruby interpreter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:shell-command-substitution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:template-literal-with-command-substitution","reason":"The backticks delimit a vulnerability payload inside a reference table that also gives defensive mitigation. The text is not Ruby execution or an instruction to run the payload.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:209:aws-azure-metadata-endpoint","reason":"The metadata address appears only as an illustrative SSRF test in a vulnerability table, beside URL allowlisting and internal-DNS restrictions. No network request is performed.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:209:hardcoded-url","reason":"The metadata address appears only as an illustrative SSRF test in a vulnerability table, beside URL allowlisting and internal-DNS restrictions. No network request is performed.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:372:hardcoded-url","reason":"This is a public security reference link in documentation. The skill does not automatically contact the URL or transmit data to it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:373:hardcoded-url","reason":"This is a public security reference link in documentation. The skill does not automatically contact the URL or transmit data to it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:374:hardcoded-url","reason":"This is a public security reference link in documentation. The skill does not automatically contact the URL or transmit data to it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:375:hardcoded-url","reason":"This is a public security reference link in documentation. The skill does not automatically contact the URL or transmit data to it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:376:hardcoded-url","reason":"This is a public security reference link in documentation. The skill does not automatically contact the URL or transmit data to it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:377:hardcoded-url","reason":"This is a public security reference link in documentation. The skill does not automatically contact the URL or transmit data to it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:209:hardcoded-ip-address","reason":"The metadata address appears only as an illustrative SSRF test in a vulnerability table, beside URL allowlisting and internal-DNS restrictions. No network request is performed.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:213:path-traversal-sequence","reason":"The traversal string is an illustrative payload in a vulnerability table and is paired with normalization and allowlisting guidance. It is not used for file access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:308:standard-device-file-access","reason":"The command redirects error output to /dev/null, the standard Unix discard device. It does not read a sensitive device or persist data.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:17:metasploit-framework","reason":"Metasploit is named only as an example security tool. No Metasploit command or payload is provided, and the skill separately requires legal authorization before testing.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:167:malware-type-keywords","reason":"The rootkit term describes defensive detection tools used during incident response. It does not provide malware, persistence, or evasion instructions.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:210:system-password-file-access","reason":"The /etc/passwd path is an illustrative XXE or traversal payload in a defensive vulnerability table. No file read is performed.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:213:system-password-file-access","reason":"The /etc/passwd path is an illustrative XXE or traversal payload in a defensive vulnerability table. No file read is performed.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:305:system-password-file-access","reason":"The read-only awk command checks /etc/passwd for UID 0 accounts during a local audit. It does not access /etc/shadow, recover password hashes, or modify accounts.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:109:system-reconnaissance","reason":"The line describes authorized defensive filtering of authentication logs. It contains no persistence, concealment, credential theft, or data exfiltration behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:110:network-reconnaissance","reason":"The command inspects local listening sockets for defensive monitoring. It does not scan remote hosts or discover an external network.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:299:network-reconnaissance","reason":"The command inspects local listening sockets for defensive monitoring. It does not scan remote hosts or discover an external network.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:318:network-reconnaissance","reason":"The command inspects local listening sockets for defensive monitoring. It does not scan remote hosts or discover an external network.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:17:network-scanning-tools","reason":"The line only names common security tools and supplies no scan command. The skill requires authorization before penetration testing or scanning.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:40:network-scanning-tools","reason":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"blocker:SKILL.md:271:network-scanning-tools","reason":"This line is a descriptive heading for an Nmap example, not an executable command. The actionable scan commands are adjudicated separately.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:272:network-scanning-tools","reason":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"blocker:SKILL.md:275:network-scanning-tools","reason":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"blocker:SKILL.md:278:network-scanning-tools","reason":"The skill provides a ready-to-run Nmap command for service, operating-system, or broad port discovery. It enables active remote reconnaissance and can affect unauthorized targets.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"obfuscation:references/pdf-guide.md:1:heuristic-high-file-entropy-6-56-bits-possible-b","reason":"The file is readable Markdown with Chinese prose, tables, paths, and command examples. There is no encoded, encrypted, binary, or concealed instruction content.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-6-84-bits-possible-b","reason":"The file is readable Markdown with Chinese prose, tables, paths, and command examples. There is no encoded, encrypted, binary, or concealed instruction content.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Offensive Post-Exploitation Workflow","severity":"high","locations":[{"file":"SKILL.md","line_end":60,"line_start":49}],"confidence":0.98,"description":"The Web testing workflow explicitly progresses through exploitation, privilege escalation, and lateral movement, while also recommending parameter and dictionary brute forcing.","confidence_reasoning":"The offensive progression and brute-force guidance are explicit in the workflow. A general authorization reminder exists, but no per-action approval or technical scope control is defined."}],"subject_marketplace_commit_sha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","subject_content_hash":"a2b2ad42ce197e1fb9d7686e137c526fed7af39c3cded0eedaaccedae60e1481","subject_tree_hash":"995b2118c312bbead381edb2369e84034f4aded2f47e364079b75a1a37baf9dc","subject_plugin_path":"skills/zl2023github/security-engineer","audit_payload_hash":"66ddfb8daeb86700aef35428d714f31a","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","contentHash":"a2b2ad42ce197e1fb9d7686e137c526fed7af39c3cded0eedaaccedae60e1481","treeHash":"995b2118c312bbead381edb2369e84034f4aded2f47e364079b75a1a37baf9dc","pluginPath":"skills/zl2023github/security-engineer","auditPayloadHash":"66ddfb8daeb86700aef35428d714f31a"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/zl2023github-security-engineer/audits/4/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":5,"capabilityReviewCount":28,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}