{
  "executive_summary": {
    "badge": "Unsafe",
    "security_score": 45.0,
    "view": "composite",
    "aggregate_verdict_withheld": false,
    "aggregate_verdict_withheld_reason": null,
    "scanner_badges": {
      "agentshield": "Verified",
      "cisco-skill-scanner": "Caution",
      "agent-audit-kit": "Unsafe",
      "nerlo-behavioral": "unavailable",
      "nerlo-install-instruction": "Unsafe",
      "nerlo-multi-source": "unavailable",
      "trivy": "Unsafe",
      "osv-scanner": "Verified",
      "trivy_image": "unavailable"
    },
    "finding_counts": {
      "critical": 132,
      "high": 22,
      "medium": 21,
      "low": 24,
      "informational": 16
    },
    "recommendation": "apollo-mcp-server is NOT recommended for integration: the scan surfaced 132 critical and 22 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering."
  },
  "source_provenance": {
    "repository_url": "https://github.com/apollographql/apollo-mcp-server",
    "commit_sha_scanned": null,
    "license": null,
    "maintainer": null,
    "name": "apollo-mcp-server",
    "version": null
  },
  "per_scanner_detail": [
    {
      "scanner_name": "agentshield",
      "scanner_version": "1.4.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 1.4001762979969499,
      "status": "complete",
      "examined": null,
      "metadata": {
        "source": "npm",
        "source_url": "https://www.npmjs.com/package/ecc-agentshield",
        "install_command": "npm install -g ecc-agentshield@1.4.0",
        "scans_performed": [
          "claude_config"
        ],
        "score_breakdown": {
          "mcp": 100,
          "hooks": 100,
          "agents": 100,
          "secrets": 100,
          "permissions": 100
        }
      },
      "display_score": 100.0,
      "display_badge": "Verified"
    },
    {
      "scanner_name": "cisco-skill-scanner",
      "scanner_version": "2.0.11",
      "score": 60.0,
      "scanner_badge": "Caution",
      "findings": [
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/.agents/skills/mcp-apps-sync-docs/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/.claude/skills/review/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "policy_violation",
          "file_path": "/repo/.",
          "line_number": null,
          "rule_identifier": "EXCESSIVE_FILE_COUNT",
          "title": "Skill package contains many files",
          "description": "Skill package contains 258 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content.",
          "remediation": "Review file inventory and remove unnecessary files."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/mcp-apps-sync-docs/SKILL.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/mcp-apps-sync-docs/SKILL.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/SKILL.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/SKILL.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_01.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_01.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_02.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_02.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_03.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_03.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_04.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_04.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_05.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_05.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_06.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_06.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_07.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_07.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_08.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_08.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "obfuscation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_09.md",
          "line_number": null,
          "rule_identifier": "HIDDEN_DATA_FILE",
          "title": "Hidden data file detected",
          "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_09.md. Hidden files may contain concealed configuration or data that should be reviewed.",
          "remediation": "Move file to a visible location or document its purpose."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "social_engineering",
          "file_path": "/repo/SKILL.md",
          "line_number": null,
          "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
          "title": "Vague skill description",
          "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
          "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "command_injection",
          "file_path": "/repo/docs/source/guides/auth-auth0.mdx",
          "line_number": 2,
          "rule_identifier": "PIPELINE_TAINT_FLOW",
          "title": "Dangerous data flow in command pipeline",
          "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://rover.apollo.dev/nix/latest | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
          "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "command_injection",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 2,
          "rule_identifier": "PIPELINE_TAINT_FLOW",
          "title": "Dangerous data flow in command pipeline",
          "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://mcp.apollo.dev/download/nix/latest | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
          "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "command_injection",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 2,
          "rule_identifier": "PIPELINE_TAINT_FLOW",
          "title": "Dangerous data flow in command pipeline",
          "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://mcp.apollo.dev/download/nix/v1.17.0 | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
          "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "low",
          "category": "command_injection",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 2,
          "rule_identifier": "PIPELINE_TAINT_FLOW",
          "title": "Dangerous data flow in command pipeline",
          "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://mcp.apollo.dev/download/nix/v1.17.0-rc.1 | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
          "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "social_engineering",
          "file_path": "/repo/.claude/SKILL.md",
          "line_number": null,
          "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
          "title": "Vague skill description",
          "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
          "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/.claude/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_INVALID_NAME",
          "title": "Skill name does not follow agent skills naming rules",
          "description": "Skill name '.claude' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
          "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/.claude/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "social_engineering",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/SKILL.md",
          "line_number": null,
          "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
          "title": "Vague skill description",
          "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
          "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/.agents/skills/rust-best-practices/references/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "social_engineering",
          "file_path": "/repo/examples/weather/SKILL.md",
          "line_number": null,
          "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
          "title": "Vague skill description",
          "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
          "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/examples/weather/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "social_engineering",
          "file_path": "/repo/examples/TheSpaceDevs/SKILL.md",
          "line_number": null,
          "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
          "title": "Vague skill description",
          "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
          "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/examples/TheSpaceDevs/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_INVALID_NAME",
          "title": "Skill name does not follow agent skills naming rules",
          "description": "Skill name 'TheSpaceDevs' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
          "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/examples/TheSpaceDevs/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/examples/TheSpaceDevs/prompts/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_INVALID_NAME",
          "title": "Skill name does not follow agent skills naming rules",
          "description": "Skill name 'astronaut_bio' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
          "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
        },
        {
          "tool_name": "cisco-skill-scanner",
          "severity": "informational",
          "category": "policy_violation",
          "file_path": "/repo/examples/TheSpaceDevs/prompts/SKILL.md",
          "line_number": null,
          "rule_identifier": "MANIFEST_MISSING_LICENSE",
          "title": "Skill does not specify a license",
          "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
          "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
        }
      ],
      "execution_duration_seconds": 16.648979959994904,
      "status": "complete",
      "examined": {
        "unit": "skills",
        "count": 9
      },
      "metadata": {
        "source": "pypi",
        "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
        "report_type": "cisco-skill-sast",
        "analyzers_used": [
          "bytecode",
          "pipeline",
          "static_analyzer"
        ],
        "skills_scanned": [
          "mcp-apps-sync-docs",
          "rust-best-practices",
          "review",
          "repo",
          ".claude",
          "references",
          "weather",
          "TheSpaceDevs",
          "astronaut_bio"
        ],
        "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
        "severity_counts": {
          "low": 16,
          "high": 0,
          "medium": 0,
          "critical": 0,
          "informational": 16
        },
        "artifact_type_policy": "mcp_server",
        "downweighted_findings": 5
      },
      "display_score": 60.0,
      "display_badge": "Caution"
    },
    {
      "scanner_name": "agent-audit-kit",
      "scanner_version": "0.3.26",
      "score": 0.0,
      "scanner_badge": "Unsafe",
      "findings": [
        {
          "tool_name": "agent-audit-kit",
          "severity": "low",
          "category": "supply-chain",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "AAK-SUPPLY-005",
          "title": "Dependency count exceeds threshold",
          "description": "More than 200 direct + transitive dependencies in lockfile. Each dependency is a trust decision.",
          "remediation": "Audit and remove unused dependencies. Consider lighter alternatives."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 44,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 44,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 45,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 50,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 51,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 51,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 51,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 52,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 57,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 57,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 57,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 67,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 68,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 69,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 73,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 75,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 77,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 79,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 79,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 86,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 86,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 90,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "AGENTS.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 44,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 44,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 45,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 50,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 51,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 51,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 51,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 52,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 57,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 57,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 57,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 67,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 68,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 69,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 73,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 75,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 77,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 79,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 79,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 86,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 86,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 90,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": 49,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "critical",
          "category": "agent-config",
          "file_path": "CLAUDE.md",
          "line_number": null,
          "rule_identifier": "AAK-AGENT-001",
          "title": "Agent instruction file contains shell command directives",
          "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
          "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/release-container.yml",
          "line_number": 36,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/release-container.yml",
          "line_number": 75,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/release-container.yml",
          "line_number": 92,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/claude-code-review.yml",
          "line_number": 69,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/prep-release.yml",
          "line_number": 22,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/ci.yml",
          "line_number": 20,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/ci.yml",
          "line_number": 80,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/ci.yml",
          "line_number": 84,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/release-bins.yml",
          "line_number": 39,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/release-bins.yml",
          "line_number": 89,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/notify-skills.yml",
          "line_number": 20,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/claude-code.yml",
          "line_number": 25,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        },
        {
          "tool_name": "agent-audit-kit",
          "severity": "medium",
          "category": "supply-chain",
          "file_path": ".github/workflows/release-experimental.yml",
          "line_number": 49,
          "rule_identifier": "AAK-GHA-IMMUTABLE-001",
          "title": "Third-party GitHub Action not pinned by full commit SHA",
          "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
          "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
        }
      ],
      "execution_duration_seconds": 11.024274966999656,
      "status": "complete",
      "examined": {
        "unit": "files",
        "count": 192
      },
      "metadata": {
        "source": "pypi",
        "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
        "report_type": "agent-audit-kit-sast",
        "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
        "rules_evaluated": 211,
        "severity_counts": {
          "low": 1,
          "high": 0,
          "medium": 13,
          "critical": 132,
          "informational": 0
        }
      },
      "display_score": 0.0,
      "display_badge": "Unsafe"
    },
    {
      "scanner_name": "nerlo-behavioral",
      "scanner_version": "0.1.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 33.76540187500359,
      "status": "not_applicable",
      "examined": {
        "unit": "files",
        "count": 0
      },
      "metadata": {
        "source": "nerlo-original",
        "source_url": "https://github.com/nerlo-ai/nerlo",
        "report_type": "nerlo-behavioral",
        "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
        "ruleset_paths": [
          "/opt/nerlo-rules/exfiltration.yaml",
          "/opt/nerlo-rules/clipboard_exfiltration.yaml",
          "/opt/nerlo-rules/rce_endpoint.yaml",
          "/opt/nerlo-rules/taint_egress.yaml"
        ],
        "install_command": "pip install 'semgrep==1.97.0'",
        "merged_invocation": true
      },
      "display_score": null,
      "display_badge": "unavailable"
    },
    {
      "scanner_name": "nerlo-install-instruction",
      "scanner_version": "0.1.0",
      "score": 0.0,
      "scanner_badge": "Unsafe",
      "findings": [
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "medium",
          "category": "install-instruction-run",
          "file_path": "/repo/CHANGELOG.md",
          "line_number": 1189,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
          "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
          "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "medium",
          "category": "install-instruction-run",
          "file_path": "/repo/CHANGELOG.md",
          "line_number": 1199,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
          "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
          "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "high",
          "category": "install-instruction-exec",
          "file_path": "/repo/docs/source/guides/auth-auth0.mdx",
          "line_number": 22,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "high",
          "category": "install-instruction-exec",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 36,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "high",
          "category": "install-instruction-exec",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 44,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "high",
          "category": "install-instruction-exec",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 58,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "high",
          "category": "install-instruction-exec",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 67,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "high",
          "category": "install-instruction-exec",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 81,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "high",
          "category": "install-instruction-exec",
          "file_path": "/repo/docs/source/run.mdx",
          "line_number": 90,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
          "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
          "remediation": null
        },
        {
          "tool_name": "nerlo-install-instruction",
          "severity": "medium",
          "category": "install-instruction-run",
          "file_path": "/repo/scripts/windows/install.ps1",
          "line_number": 31,
          "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
          "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
          "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
          "remediation": null
        }
      ],
      "execution_duration_seconds": 33.767548199000885,
      "status": "complete",
      "examined": {
        "unit": "files",
        "count": 53
      },
      "metadata": {
        "source": "nerlo-original",
        "source_url": "https://github.com/nerlo-ai/nerlo",
        "report_type": "nerlo-install-instruction",
        "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
        "ruleset_paths": [
          "/opt/nerlo-rules/install_instructions.yaml",
          "/opt/nerlo-rules/cursor_rules.yaml"
        ],
        "install_command": "pip install 'semgrep==1.97.0'",
        "severity_counts": {
          "low": 0,
          "high": 7,
          "medium": 3,
          "critical": 0,
          "informational": 0
        },
        "merged_invocation": true
      },
      "display_score": 0.0,
      "display_badge": "Unsafe"
    },
    {
      "scanner_name": "nerlo-multi-source",
      "scanner_version": "0.1.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 16.95486114900268,
      "status": "not_applicable",
      "examined": null,
      "metadata": {
        "source": "nerlo-original",
        "per_source": [],
        "report_type": "nerlo-multi-source",
        "diverged_sources": [],
        "published_surfaces_scanned": 0
      },
      "display_score": null,
      "display_badge": "unavailable"
    },
    {
      "scanner_name": "trivy",
      "scanner_version": "0.71.0",
      "score": 0.0,
      "scanner_badge": "Unsafe",
      "findings": [
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-394x-vwmw-crm3",
          "title": "AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN",
          "description": "### Summary\n\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\n\nA logic error in CN (Common Name) validation allows certificates with wildcard or raw UTF-8 Unicode CN values to bypass name constraints enforcement. The `cn2dnsid` function does not recognize these CN patterns as valid DNS identifiers, causing `NAME_CONSTRAINTS_check_CN` to skip validation. However, `X509_check_host` accepts these CN values when no dNSName SAN is present, allowing certificates to bypass n",
          "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.39.0 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-65p9-r9h6-22vj",
          "title": "AWS-LC has Timing Side-Channel in AES-CCM Tag Verification",
          "description": "### Summary\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\nObservable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis.\n\nThe impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm.\n\nCustomers of AWS services do not need to take action. aws-lc-sys and aws-lc-fips-sys contain code from AWS-LC. Applications us",
          "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.38.0 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-9f94-5g5w-gf6r",
          "title": "CRL Distribution Point Scope Check Logic Error in AWS-LC",
          "description": "### Summary\n\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact \n\nA logic error in CRL distribution point matching in AWS-LC allows a revoked certificate to bypass revocation checks during certificate validation, when the application enables CRL checking and uses partitioned CRLs with Issuing Distribution Point (IDP) extensions.\n\nCustomers of AWS services do not need to take action. aws-lc-sys and aws-lc-fips-sys contain code from AWS-LC. Applications using aws-lc-sys o",
          "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.39.0 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-hfpc-8r3f-gw53",
          "title": "AWS-LC has PKCS7_verify Signature Validation Bypass",
          "description": "### Summary\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\nImproper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.\n\nCustomers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.\n\n#### Impacted versions: \naws-lc-sys versions: >",
          "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.38.0 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-vw5v-4f2q-w9xf",
          "title": "AWS-LC has PKCS7_verify Certificate Chain Validation Bypass",
          "description": "### Summary\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\nImproper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.\n\nCustomers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.\n\n#### Impacted versio",
          "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.38.0 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-rhfx-m35p-ff5j",
          "title": "`IterMut` violates Stacked Borrows by invalidating internal pointer",
          "description": "Affected versions of this crate contain a soundness issue in the `IterMut` iterator implementation. The `IterMut::next` and `IterMut::next_back` methods temporarily create an exclusive reference to the key when dereferencing the internal node pointer.\n\nThis invalidates the shared pointer held by the internal `HashMap`, violating Stacked Borrows rules.",
          "remediation": "Upgrade lru from 0.12.5 to 0.16.3 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-32829",
          "title": "lz4_flex: lz4_flex's decompression can leak information from uninitialized memory or reused output buffer",
          "description": "lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0,  decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly validate offset values during LZ4 \"match copy operations,\" allowing out-of-bounds reads from the output buffer. The block-based API functions (`decompress_into`, `decompress_into_with_dict`, and others when `safe-decode` is",
          "remediation": "Upgrade lz4_flex from 0.11.5 to 0.11.6, 0.12.1 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-41676",
          "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x provi",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-41678",
          "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From  to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function wil",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-41681",
          "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-41898",
          "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-42327",
          "title": "rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant \u2014 resul",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.79 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-44662",
          "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-i",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.79 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-45784",
          "title": "rust-openssl: rust-openssl: Heap Corruption from Incorrect Buffer Sizing",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fix",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.80 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-41677",
          "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
          "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.",
          "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-48504",
          "title": "opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation",
          "description": "OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-reques",
          "remediation": "Upgrade opentelemetry_sdk from 0.30.0 to 0.32.1 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-48504",
          "title": "opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation",
          "description": "OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-reques",
          "remediation": "Upgrade opentelemetry_sdk from 0.32.0 to 0.32.1 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-31812",
          "title": "quinn-proto: quinn-proto: Denial of Service via crafted QUIC Initial packet",
          "description": "Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a s",
          "remediation": "Upgrade quinn-proto from 0.11.13 to 0.11.14 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-4w2j-m93h-cj5j",
          "title": "Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly",
          "description": "## Summary\n\nThe `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buf",
          "remediation": "Upgrade quinn-proto from 0.11.13 to 0.11.15 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-cq8v-f236-94qc",
          "title": "Rand is unsound with a custom logger using rand::rng()",
          "description": "It has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)",
          "remediation": "Upgrade rand from 0.10.0 to 0.9.3, 0.10.1, 0.8.6 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-cq8v-f236-94qc",
          "title": "Rand is unsound with a custom logger using rand::rng()",
          "description": "It has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)",
          "remediation": "Upgrade rand from 0.8.5 to 0.9.3, 0.10.1, 0.8.6 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-cq8v-f236-94qc",
          "title": "Rand is unsound with a custom logger using rand::rng()",
          "description": "It has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)",
          "remediation": "Upgrade rand from 0.9.2 to 0.9.3, 0.10.1, 0.8.6 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-82j2-j2ch-gfr8",
          "title": "rustls-webpki: Denial of service via panic on malformed CRL BIT STRING",
          "description": "### Summary\n\n`bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the `issuingDistributionPoint` CRL extension.\n\n**Precondition**: CRL checking is opt-in in rustls-webpki. This vulnerability affects only applications that explicitly pass `RevocationOptions` to `verify_for_usage()` and loa",
          "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.13, 0.104.0-alpha.7 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "medium",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-pwjx-qhcg-rvj4",
          "title": "webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic",
          "description": "If a certificate had more than one `distributionPoint`, then only the first `distributionPoint` would be considered against each CRL's `IssuingDistributionPoint` `distributionPoint`, and then the certificate's subsequent `distributionPoint`s would be ignored.\n\nThe impact was that correct provided CRLs would not be consulted to check revocation. With `UnknownStatusPolicy::Deny` (the default) this would lead to incorrect but safe `Error::UnknownRevocationStatus`. With `UnknownStatusPolicy::Allow` ",
          "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.10, 0.104.0-alpha.5 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-965h-392x-2mh5",
          "title": "webpki: Name constraints for URI names were incorrectly accepted",
          "description": "Name constraints for URI names were ignored and therefore accepted.\n\nNote this library does not provide an API for asserting URI names, and URI name constraints are otherwise not implemented.  URI name constraints are now rejected unconditionally.\n\nSince name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.",
          "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.12, 0.104.0-alpha.6 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "low",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "GHSA-xgp8-3hg3-c2mh",
          "title": "webpki: Name constraints were accepted for certificates asserting a wildcard name",
          "description": "Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name.\n\nThis was incorrect because, given a name constraint of `accept.example.com`, `*.example.com` could feasibly allow a name of `reject.example.com` which is outside the constraint.\nThis is very similar to [CVE-2025-61727](https://go.dev/issue/76442).\n\nSince name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and ",
          "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.12, 0.104.0-alpha.6 or later"
        },
        {
          "tool_name": "trivy",
          "severity": "high",
          "category": "cargo",
          "file_path": "Cargo.lock",
          "line_number": null,
          "rule_identifier": "CVE-2026-6654",
          "title": "thin-vec: mozilla/thin-vec: Memory corruption vulnerability via Double-Free/Use-After-Free",
          "description": "Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.",
          "remediation": "Upgrade thin-vec from 0.2.14 to 0.2.16 or later"
        }
      ],
      "execution_duration_seconds": 1.7396986349995132,
      "status": "complete",
      "examined": {
        "unit": "manifests",
        "count": 1
      },
      "metadata": {
        "source": "github-releases",
        "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
        "report_type": "filesystem-vulnerability",
        "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
        "severity_counts": {
          "low": 7,
          "high": 15,
          "medium": 5,
          "critical": 0,
          "informational": 0
        },
        "manifests_scanned": [
          "Cargo.lock"
        ]
      },
      "display_score": 0.0,
      "display_badge": "Unsafe"
    },
    {
      "scanner_name": "osv-scanner",
      "scanner_version": "2.3.8",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 0.5873383509970154,
      "status": "complete",
      "examined": null,
      "metadata": {
        "source": "github-releases",
        "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
        "report_type": "osv-vulnerability",
        "ecosystems_seen": [],
        "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
        "manifests_scanned": [],
        "finding_id_aliases": {},
        "cross_scanner_correlation": {
          "only_osv": [],
          "only_trivy": [
            "CVE-2026-31812",
            "CVE-2026-32829",
            "CVE-2026-41676",
            "CVE-2026-41677",
            "CVE-2026-41678",
            "CVE-2026-41681",
            "CVE-2026-41898",
            "CVE-2026-42327",
            "CVE-2026-44662",
            "CVE-2026-45784",
            "CVE-2026-48504",
            "CVE-2026-6654",
            "GHSA-394x-vwmw-crm3",
            "GHSA-4w2j-m93h-cj5j",
            "GHSA-65p9-r9h6-22vj",
            "GHSA-82j2-j2ch-gfr8",
            "GHSA-965h-392x-2mh5",
            "GHSA-9f94-5g5w-gf6r",
            "GHSA-cq8v-f236-94qc",
            "GHSA-hfpc-8r3f-gw53",
            "GHSA-pwjx-qhcg-rvj4",
            "GHSA-rhfx-m35p-ff5j",
            "GHSA-vw5v-4f2q-w9xf",
            "GHSA-xgp8-3hg3-c2mh"
          ],
          "intersection_ids": []
        }
      },
      "display_score": 100.0,
      "display_badge": "Verified"
    },
    {
      "scanner_name": "trivy_image",
      "scanner_version": "0.71.0",
      "score": 100.0,
      "scanner_badge": "Verified",
      "findings": [],
      "execution_duration_seconds": 0.5104940509991138,
      "status": "incomplete",
      "examined": null,
      "metadata": {
        "source": "github-releases",
        "image_ref": "ghcr.io/apollographql/apollo-mcp-server:v1.17.0",
        "os_family": null,
        "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
        "report_type": "container-image-vulnerability",
        "image_digest": "sha256:260319382cd828817627834c8986014f54735dd8323f024bd334cfb426516373",
        "image_layers": 20,
        "error_message": "trivy image exit code 1",
        "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
        "targets_scanned": [],
        "image_size_bytes": 27502080,
        "go_binaries_found": 0
      },
      "display_score": null,
      "display_badge": "unavailable"
    }
  ],
  "threat_model": "Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.",
  "audit_chain": {
    "scan_job_id": "a03ee0cf-a500-4acc-9879-e5827322246c",
    "scan_completed_at": "2026-07-31T06:48:12.489914+00:00",
    "scanner_versions": {
      "agentshield": "1.4.0",
      "cisco-skill-scanner": "2.0.11",
      "agent-audit-kit": "0.3.26",
      "nerlo-behavioral": "0.1.0",
      "nerlo-install-instruction": "0.1.0",
      "nerlo-multi-source": "0.1.0",
      "trivy": "0.71.0",
      "osv-scanner": "2.3.8",
      "trivy_image": "0.71.0"
    },
    "scanner_base_image": "us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:04d4ebff19b52711a0fc06336d25964d24b9072474ff98811e5b82af008f1b8d",
    "ai_decision_log_ids": [
      "2ffd2807-44a6-40f6-85bc-828cd545fe1e",
      "2deb2c37-8116-44b9-a30f-2d1819677e3d"
    ],
    "self_attestation_url": "http://localhost:8000/api/v1/registry/self-attestation"
  },
  "appendix": {
    "raw_scanner_reports": [
      {
        "scanner_name": "agentshield",
        "scanner_version": "1.4.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 1.4001762979969499,
        "status": "complete",
        "examined": null,
        "metadata": {
          "source": "npm",
          "source_url": "https://www.npmjs.com/package/ecc-agentshield",
          "install_command": "npm install -g ecc-agentshield@1.4.0",
          "scans_performed": [
            "claude_config"
          ],
          "score_breakdown": {
            "mcp": 100,
            "hooks": 100,
            "agents": 100,
            "secrets": 100,
            "permissions": 100
          }
        },
        "display_score": 100.0,
        "display_badge": "Verified"
      },
      {
        "scanner_name": "cisco-skill-scanner",
        "scanner_version": "2.0.11",
        "score": 60.0,
        "scanner_badge": "Caution",
        "findings": [
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/.agents/skills/mcp-apps-sync-docs/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/.claude/skills/review/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "policy_violation",
            "file_path": "/repo/.",
            "line_number": null,
            "rule_identifier": "EXCESSIVE_FILE_COUNT",
            "title": "Skill package contains many files",
            "description": "Skill package contains 258 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content.",
            "remediation": "Review file inventory and remove unnecessary files."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/mcp-apps-sync-docs/SKILL.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/mcp-apps-sync-docs/SKILL.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/SKILL.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/SKILL.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_01.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_01.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_02.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_02.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_03.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_03.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_04.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_04.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_05.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_05.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_06.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_06.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_07.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_07.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_08.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_08.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "obfuscation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/chapter_09.md",
            "line_number": null,
            "rule_identifier": "HIDDEN_DATA_FILE",
            "title": "Hidden data file detected",
            "description": "Hidden file found: .agents/skills/rust-best-practices/references/chapter_09.md. Hidden files may contain concealed configuration or data that should be reviewed.",
            "remediation": "Move file to a visible location or document its purpose."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "social_engineering",
            "file_path": "/repo/SKILL.md",
            "line_number": null,
            "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
            "title": "Vague skill description",
            "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
            "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "command_injection",
            "file_path": "/repo/docs/source/guides/auth-auth0.mdx",
            "line_number": 2,
            "rule_identifier": "PIPELINE_TAINT_FLOW",
            "title": "Dangerous data flow in command pipeline",
            "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://rover.apollo.dev/nix/latest | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
            "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "command_injection",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 2,
            "rule_identifier": "PIPELINE_TAINT_FLOW",
            "title": "Dangerous data flow in command pipeline",
            "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://mcp.apollo.dev/download/nix/latest | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
            "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "command_injection",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 2,
            "rule_identifier": "PIPELINE_TAINT_FLOW",
            "title": "Dangerous data flow in command pipeline",
            "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://mcp.apollo.dev/download/nix/v1.17.0 | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
            "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "low",
            "category": "command_injection",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 2,
            "rule_identifier": "PIPELINE_TAINT_FLOW",
            "title": "Dangerous data flow in command pipeline",
            "description": "Pipeline downloads data from the network and executes it: `curl -sSL https://mcp.apollo.dev/download/nix/v1.17.0-rc.1 | sh`. This is a remote code execution pattern. (Note: found in documentation file - may be instructional rather than executable.)",
            "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "social_engineering",
            "file_path": "/repo/.claude/SKILL.md",
            "line_number": null,
            "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
            "title": "Vague skill description",
            "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
            "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/.claude/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_INVALID_NAME",
            "title": "Skill name does not follow agent skills naming rules",
            "description": "Skill name '.claude' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
            "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/.claude/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "social_engineering",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/SKILL.md",
            "line_number": null,
            "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
            "title": "Vague skill description",
            "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
            "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/.agents/skills/rust-best-practices/references/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "social_engineering",
            "file_path": "/repo/examples/weather/SKILL.md",
            "line_number": null,
            "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
            "title": "Vague skill description",
            "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
            "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/examples/weather/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "social_engineering",
            "file_path": "/repo/examples/TheSpaceDevs/SKILL.md",
            "line_number": null,
            "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
            "title": "Vague skill description",
            "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
            "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/examples/TheSpaceDevs/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_INVALID_NAME",
            "title": "Skill name does not follow agent skills naming rules",
            "description": "Skill name 'TheSpaceDevs' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
            "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/examples/TheSpaceDevs/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/examples/TheSpaceDevs/prompts/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_INVALID_NAME",
            "title": "Skill name does not follow agent skills naming rules",
            "description": "Skill name 'astronaut_bio' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
            "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
          },
          {
            "tool_name": "cisco-skill-scanner",
            "severity": "informational",
            "category": "policy_violation",
            "file_path": "/repo/examples/TheSpaceDevs/prompts/SKILL.md",
            "line_number": null,
            "rule_identifier": "MANIFEST_MISSING_LICENSE",
            "title": "Skill does not specify a license",
            "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
            "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
          }
        ],
        "execution_duration_seconds": 16.648979959994904,
        "status": "complete",
        "examined": {
          "unit": "skills",
          "count": 9
        },
        "metadata": {
          "source": "pypi",
          "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
          "report_type": "cisco-skill-sast",
          "analyzers_used": [
            "bytecode",
            "pipeline",
            "static_analyzer"
          ],
          "skills_scanned": [
            "mcp-apps-sync-docs",
            "rust-best-practices",
            "review",
            "repo",
            ".claude",
            "references",
            "weather",
            "TheSpaceDevs",
            "astronaut_bio"
          ],
          "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
          "severity_counts": {
            "low": 16,
            "high": 0,
            "medium": 0,
            "critical": 0,
            "informational": 16
          },
          "artifact_type_policy": "mcp_server",
          "downweighted_findings": 5
        },
        "display_score": 60.0,
        "display_badge": "Caution"
      },
      {
        "scanner_name": "agent-audit-kit",
        "scanner_version": "0.3.26",
        "score": 0.0,
        "scanner_badge": "Unsafe",
        "findings": [
          {
            "tool_name": "agent-audit-kit",
            "severity": "low",
            "category": "supply-chain",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "AAK-SUPPLY-005",
            "title": "Dependency count exceeds threshold",
            "description": "More than 200 direct + transitive dependencies in lockfile. Each dependency is a trust decision.",
            "remediation": "Audit and remove unused dependencies. Consider lighter alternatives."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 44,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 44,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 45,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 50,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 51,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 51,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 51,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 52,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 57,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 57,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 57,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 67,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 68,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 69,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 73,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 75,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 77,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 79,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 79,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 86,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 86,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 90,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "AGENTS.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 44,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 44,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 45,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 50,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 51,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 51,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 51,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 52,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 57,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 57,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 57,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 67,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 68,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 69,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 73,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 75,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 77,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 79,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 79,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 86,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 86,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 90,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": 49,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "critical",
            "category": "agent-config",
            "file_path": "CLAUDE.md",
            "line_number": null,
            "rule_identifier": "AAK-AGENT-001",
            "title": "Agent instruction file contains shell command directives",
            "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
            "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/release-container.yml",
            "line_number": 36,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/release-container.yml",
            "line_number": 75,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/release-container.yml",
            "line_number": 92,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/claude-code-review.yml",
            "line_number": 69,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/prep-release.yml",
            "line_number": 22,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/ci.yml",
            "line_number": 20,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/ci.yml",
            "line_number": 80,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/ci.yml",
            "line_number": 84,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/release-bins.yml",
            "line_number": 39,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/release-bins.yml",
            "line_number": 89,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/notify-skills.yml",
            "line_number": 20,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/claude-code.yml",
            "line_number": 25,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          },
          {
            "tool_name": "agent-audit-kit",
            "severity": "medium",
            "category": "supply-chain",
            "file_path": ".github/workflows/release-experimental.yml",
            "line_number": 49,
            "rule_identifier": "AAK-GHA-IMMUTABLE-001",
            "title": "Third-party GitHub Action not pinned by full commit SHA",
            "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
            "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
          }
        ],
        "execution_duration_seconds": 11.024274966999656,
        "status": "complete",
        "examined": {
          "unit": "files",
          "count": 192
        },
        "metadata": {
          "source": "pypi",
          "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
          "report_type": "agent-audit-kit-sast",
          "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
          "rules_evaluated": 211,
          "severity_counts": {
            "low": 1,
            "high": 0,
            "medium": 13,
            "critical": 132,
            "informational": 0
          }
        },
        "display_score": 0.0,
        "display_badge": "Unsafe"
      },
      {
        "scanner_name": "nerlo-behavioral",
        "scanner_version": "0.1.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 33.76540187500359,
        "status": "not_applicable",
        "examined": {
          "unit": "files",
          "count": 0
        },
        "metadata": {
          "source": "nerlo-original",
          "source_url": "https://github.com/nerlo-ai/nerlo",
          "report_type": "nerlo-behavioral",
          "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
          "ruleset_paths": [
            "/opt/nerlo-rules/exfiltration.yaml",
            "/opt/nerlo-rules/clipboard_exfiltration.yaml",
            "/opt/nerlo-rules/rce_endpoint.yaml",
            "/opt/nerlo-rules/taint_egress.yaml"
          ],
          "install_command": "pip install 'semgrep==1.97.0'",
          "merged_invocation": true
        },
        "display_score": null,
        "display_badge": "unavailable"
      },
      {
        "scanner_name": "nerlo-install-instruction",
        "scanner_version": "0.1.0",
        "score": 0.0,
        "scanner_badge": "Unsafe",
        "findings": [
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "medium",
            "category": "install-instruction-run",
            "file_path": "/repo/CHANGELOG.md",
            "line_number": 1189,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
            "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
            "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "medium",
            "category": "install-instruction-run",
            "file_path": "/repo/CHANGELOG.md",
            "line_number": 1199,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
            "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
            "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "high",
            "category": "install-instruction-exec",
            "file_path": "/repo/docs/source/guides/auth-auth0.mdx",
            "line_number": 22,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "high",
            "category": "install-instruction-exec",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 36,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "high",
            "category": "install-instruction-exec",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 44,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "high",
            "category": "install-instruction-exec",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 58,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "high",
            "category": "install-instruction-exec",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 67,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "high",
            "category": "install-instruction-exec",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 81,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "high",
            "category": "install-instruction-exec",
            "file_path": "/repo/docs/source/run.mdx",
            "line_number": 90,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
            "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
            "remediation": null
          },
          {
            "tool_name": "nerlo-install-instruction",
            "severity": "medium",
            "category": "install-instruction-run",
            "file_path": "/repo/scripts/windows/install.ps1",
            "line_number": 31,
            "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
            "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
            "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
            "remediation": null
          }
        ],
        "execution_duration_seconds": 33.767548199000885,
        "status": "complete",
        "examined": {
          "unit": "files",
          "count": 53
        },
        "metadata": {
          "source": "nerlo-original",
          "source_url": "https://github.com/nerlo-ai/nerlo",
          "report_type": "nerlo-install-instruction",
          "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
          "ruleset_paths": [
            "/opt/nerlo-rules/install_instructions.yaml",
            "/opt/nerlo-rules/cursor_rules.yaml"
          ],
          "install_command": "pip install 'semgrep==1.97.0'",
          "severity_counts": {
            "low": 0,
            "high": 7,
            "medium": 3,
            "critical": 0,
            "informational": 0
          },
          "merged_invocation": true
        },
        "display_score": 0.0,
        "display_badge": "Unsafe"
      },
      {
        "scanner_name": "nerlo-multi-source",
        "scanner_version": "0.1.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 16.95486114900268,
        "status": "not_applicable",
        "examined": null,
        "metadata": {
          "source": "nerlo-original",
          "per_source": [],
          "report_type": "nerlo-multi-source",
          "diverged_sources": [],
          "published_surfaces_scanned": 0
        },
        "display_score": null,
        "display_badge": "unavailable"
      },
      {
        "scanner_name": "trivy",
        "scanner_version": "0.71.0",
        "score": 0.0,
        "scanner_badge": "Unsafe",
        "findings": [
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-394x-vwmw-crm3",
            "title": "AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN",
            "description": "### Summary\n\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\n\nA logic error in CN (Common Name) validation allows certificates with wildcard or raw UTF-8 Unicode CN values to bypass name constraints enforcement. The `cn2dnsid` function does not recognize these CN patterns as valid DNS identifiers, causing `NAME_CONSTRAINTS_check_CN` to skip validation. However, `X509_check_host` accepts these CN values when no dNSName SAN is present, allowing certificates to bypass n",
            "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.39.0 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-65p9-r9h6-22vj",
            "title": "AWS-LC has Timing Side-Channel in AES-CCM Tag Verification",
            "description": "### Summary\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\nObservable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis.\n\nThe impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm.\n\nCustomers of AWS services do not need to take action. aws-lc-sys and aws-lc-fips-sys contain code from AWS-LC. Applications us",
            "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.38.0 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-9f94-5g5w-gf6r",
            "title": "CRL Distribution Point Scope Check Logic Error in AWS-LC",
            "description": "### Summary\n\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact \n\nA logic error in CRL distribution point matching in AWS-LC allows a revoked certificate to bypass revocation checks during certificate validation, when the application enables CRL checking and uses partitioned CRLs with Issuing Distribution Point (IDP) extensions.\n\nCustomers of AWS services do not need to take action. aws-lc-sys and aws-lc-fips-sys contain code from AWS-LC. Applications using aws-lc-sys o",
            "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.39.0 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-hfpc-8r3f-gw53",
            "title": "AWS-LC has PKCS7_verify Signature Validation Bypass",
            "description": "### Summary\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\nImproper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.\n\nCustomers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.\n\n#### Impacted versions: \naws-lc-sys versions: >",
            "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.38.0 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-vw5v-4f2q-w9xf",
            "title": "AWS-LC has PKCS7_verify Certificate Chain Validation Bypass",
            "description": "### Summary\nAWS-LC is an open-source, general-purpose cryptographic library.\n\n### Impact\nImproper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.\n\nCustomers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.\n\n#### Impacted versio",
            "remediation": "Upgrade aws-lc-sys from 0.37.1 to 0.38.0 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-rhfx-m35p-ff5j",
            "title": "`IterMut` violates Stacked Borrows by invalidating internal pointer",
            "description": "Affected versions of this crate contain a soundness issue in the `IterMut` iterator implementation. The `IterMut::next` and `IterMut::next_back` methods temporarily create an exclusive reference to the key when dereferencing the internal node pointer.\n\nThis invalidates the shared pointer held by the internal `HashMap`, violating Stacked Borrows rules.",
            "remediation": "Upgrade lru from 0.12.5 to 0.16.3 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-32829",
            "title": "lz4_flex: lz4_flex's decompression can leak information from uninitialized memory or reused output buffer",
            "description": "lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0,  decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly validate offset values during LZ4 \"match copy operations,\" allowing out-of-bounds reads from the output buffer. The block-based API functions (`decompress_into`, `decompress_into_with_dict`, and others when `safe-decode` is",
            "remediation": "Upgrade lz4_flex from 0.11.5 to 0.11.6, 0.12.1 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-41676",
            "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out length to EVP_PKEY_derive, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming *keylen, unconditionally writing the full shared secret (32/56/prime-size bytes). A caller passing a short slice gets a heap/stack overflow from safe code. OpenSSL 3.x provi",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-41678",
            "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From  to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but this condition is reversed. The intended invariant is out.len() >= in_.len() - 8, ensuring the output buffer is large enough. Because of the inverted check, the function only accepts buffers at or below the minimum required size and rejects larger ones. If a smaller buffer is provided the function wil",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-41681",
            "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller than that, MdCtxRef::digest_final() writes past its end, usually corrupting the stack. This is reachable from safe Rust. This vulnerability is fixed in 0.10.78.",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-41898",
            "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the user closure's returned usize directly to OpenSSL without checking it against the &mut [u8] that was handed to the closure. This can lead to buffer overflows and other unintended consequences. This vulnerability is fixed in",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-42327",
            "title": "rust-openssl: rust-openssl: Arbitrary code execution via specially crafted certificate",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_responders returns OCSP responder URLs from a certificate's AIA extension as OpensslString, whose Deref<Target = str> wraps the raw bytes with str::from_utf8_unchecked. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a &str that violates the UTF-8 invariant \u2014 resul",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.79 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-44662",
            "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-i",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.79 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-45784",
            "title": "rust-openssl: rust-openssl: Heap Corruption from Incorrect Buffer Sizing",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fix",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.80 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-41677",
            "title": "rust-openssl provides OpenSSL bindings for the Rust programming langua ...",
            "description": "rust-openssl provides OpenSSL bindings for the Rust programming language.  From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.",
            "remediation": "Upgrade openssl from 0.10.75 to 0.10.78 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-48504",
            "title": "opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation",
            "description": "OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-reques",
            "remediation": "Upgrade opentelemetry_sdk from 0.30.0 to 0.32.1 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-48504",
            "title": "opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation",
            "description": "OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound baggage header, so a large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries later discarded by the SDK's baggage storage limits. Services that accept untrusted inbound propagation headers may experience increased per-reques",
            "remediation": "Upgrade opentelemetry_sdk from 0.32.0 to 0.32.1 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-31812",
            "title": "quinn-proto: quinn-proto: Denial of Service via crafted QUIC Initial packet",
            "description": "Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a s",
            "remediation": "Upgrade quinn-proto from 0.11.13 to 0.11.14 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-4w2j-m93h-cj5j",
            "title": "Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly",
            "description": "## Summary\n\nThe `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buf",
            "remediation": "Upgrade quinn-proto from 0.11.13 to 0.11.15 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-cq8v-f236-94qc",
            "title": "Rand is unsound with a custom logger using rand::rng()",
            "description": "It has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)",
            "remediation": "Upgrade rand from 0.10.0 to 0.9.3, 0.10.1, 0.8.6 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-cq8v-f236-94qc",
            "title": "Rand is unsound with a custom logger using rand::rng()",
            "description": "It has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)",
            "remediation": "Upgrade rand from 0.8.5 to 0.9.3, 0.10.1, 0.8.6 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-cq8v-f236-94qc",
            "title": "Rand is unsound with a custom logger using rand::rng()",
            "description": "It has been reported (by @lopopolo) that the `rand` library is [unsound](https://rust-lang.github.io/unsafe-code-guidelines/glossary.html#soundness-of-code--of-a-library) (i.e. that safe code using the public API can cause Undefined Behaviour) when all the following conditions are met:\n\n- The `log` and `thread_rng` features are enabled\n- A [custom logger](https://docs.rs/log/latest/log/#implementing-a-logger) is defined\n- The custom logger accesses `rand::rng()` (previously `rand::thread_rng()`)",
            "remediation": "Upgrade rand from 0.9.2 to 0.9.3, 0.10.1, 0.8.6 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-82j2-j2ch-gfr8",
            "title": "rustls-webpki: Denial of service via panic on malformed CRL BIT STRING",
            "description": "### Summary\n\n`bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the `issuingDistributionPoint` CRL extension.\n\n**Precondition**: CRL checking is opt-in in rustls-webpki. This vulnerability affects only applications that explicitly pass `RevocationOptions` to `verify_for_usage()` and loa",
            "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.13, 0.104.0-alpha.7 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "medium",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-pwjx-qhcg-rvj4",
            "title": "webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic",
            "description": "If a certificate had more than one `distributionPoint`, then only the first `distributionPoint` would be considered against each CRL's `IssuingDistributionPoint` `distributionPoint`, and then the certificate's subsequent `distributionPoint`s would be ignored.\n\nThe impact was that correct provided CRLs would not be consulted to check revocation. With `UnknownStatusPolicy::Deny` (the default) this would lead to incorrect but safe `Error::UnknownRevocationStatus`. With `UnknownStatusPolicy::Allow` ",
            "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.10, 0.104.0-alpha.5 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-965h-392x-2mh5",
            "title": "webpki: Name constraints for URI names were incorrectly accepted",
            "description": "Name constraints for URI names were ignored and therefore accepted.\n\nNote this library does not provide an API for asserting URI names, and URI name constraints are otherwise not implemented.  URI name constraints are now rejected unconditionally.\n\nSince name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and requires misissuance to exploit.",
            "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.12, 0.104.0-alpha.6 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "low",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "GHSA-xgp8-3hg3-c2mh",
            "title": "webpki: Name constraints were accepted for certificates asserting a wildcard name",
            "description": "Permitted subtree name constraints for DNS names were accepted for certificates asserting a wildcard name.\n\nThis was incorrect because, given a name constraint of `accept.example.com`, `*.example.com` could feasibly allow a name of `reject.example.com` which is outside the constraint.\nThis is very similar to [CVE-2025-61727](https://go.dev/issue/76442).\n\nSince name constraints are restrictions on otherwise properly-issued certificates, this bug is reachable only after signature verification and ",
            "remediation": "Upgrade rustls-webpki from 0.103.9 to 0.103.12, 0.104.0-alpha.6 or later"
          },
          {
            "tool_name": "trivy",
            "severity": "high",
            "category": "cargo",
            "file_path": "Cargo.lock",
            "line_number": null,
            "rule_identifier": "CVE-2026-6654",
            "title": "thin-vec: mozilla/thin-vec: Memory corruption vulnerability via Double-Free/Use-After-Free",
            "description": "Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.",
            "remediation": "Upgrade thin-vec from 0.2.14 to 0.2.16 or later"
          }
        ],
        "execution_duration_seconds": 1.7396986349995132,
        "status": "complete",
        "examined": {
          "unit": "manifests",
          "count": 1
        },
        "metadata": {
          "source": "github-releases",
          "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
          "report_type": "filesystem-vulnerability",
          "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
          "severity_counts": {
            "low": 7,
            "high": 15,
            "medium": 5,
            "critical": 0,
            "informational": 0
          },
          "manifests_scanned": [
            "Cargo.lock"
          ]
        },
        "display_score": 0.0,
        "display_badge": "Unsafe"
      },
      {
        "scanner_name": "osv-scanner",
        "scanner_version": "2.3.8",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 0.5873383509970154,
        "status": "complete",
        "examined": null,
        "metadata": {
          "source": "github-releases",
          "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
          "report_type": "osv-vulnerability",
          "ecosystems_seen": [],
          "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
          "manifests_scanned": [],
          "finding_id_aliases": {},
          "cross_scanner_correlation": {
            "only_osv": [],
            "only_trivy": [
              "CVE-2026-31812",
              "CVE-2026-32829",
              "CVE-2026-41676",
              "CVE-2026-41677",
              "CVE-2026-41678",
              "CVE-2026-41681",
              "CVE-2026-41898",
              "CVE-2026-42327",
              "CVE-2026-44662",
              "CVE-2026-45784",
              "CVE-2026-48504",
              "CVE-2026-6654",
              "GHSA-394x-vwmw-crm3",
              "GHSA-4w2j-m93h-cj5j",
              "GHSA-65p9-r9h6-22vj",
              "GHSA-82j2-j2ch-gfr8",
              "GHSA-965h-392x-2mh5",
              "GHSA-9f94-5g5w-gf6r",
              "GHSA-cq8v-f236-94qc",
              "GHSA-hfpc-8r3f-gw53",
              "GHSA-pwjx-qhcg-rvj4",
              "GHSA-rhfx-m35p-ff5j",
              "GHSA-vw5v-4f2q-w9xf",
              "GHSA-xgp8-3hg3-c2mh"
            ],
            "intersection_ids": []
          }
        },
        "display_score": 100.0,
        "display_badge": "Verified"
      },
      {
        "scanner_name": "trivy_image",
        "scanner_version": "0.71.0",
        "score": 100.0,
        "scanner_badge": "Verified",
        "findings": [],
        "execution_duration_seconds": 0.5104940509991138,
        "status": "incomplete",
        "examined": null,
        "metadata": {
          "source": "github-releases",
          "image_ref": "ghcr.io/apollographql/apollo-mcp-server:v1.17.0",
          "os_family": null,
          "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
          "report_type": "container-image-vulnerability",
          "image_digest": "sha256:260319382cd828817627834c8986014f54735dd8323f024bd334cfb426516373",
          "image_layers": 20,
          "error_message": "trivy image exit code 1",
          "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
          "targets_scanned": [],
          "image_size_bytes": 27502080,
          "go_binaries_found": 0
        },
        "display_score": null,
        "display_badge": "unavailable"
      }
    ]
  },
  "report": {
    "report_id": "37242e1a-e184-4a6a-af6c-8e5e25140e07",
    "format": "json",
    "generated_at": "2026-07-31T13:56:00.673211+00:00",
    "scanner_filter": null,
    "signature": null
  }
}