# Security Audit Report — accessibility

- **Report ID:** `3bfb2953-40b5-464d-91e4-7ee86390538a`
- **Generated:** 2026-08-12T07:44:18.318733+00:00
- **Signature:** unsigned (cosign keyless signing runs in CI; Req 22.4)

## 1. Executive Summary

**Badge:** Unsafe (composite)  
**Security score:** n/a

| Scanner | Badge |
| --- | --- |
| agent-audit-kit | Unsafe |
| agentshield | Caution |
| bearer | Unsafe |
| capslock | not_applicable |
| cisco-skill-scanner | Unsafe |
| nerlo-behavioral | Unsafe |
| nerlo-install-instruction | Unsafe |

| Severity | Findings |
| --- | --- |
| critical | 170 |
| high | 406 |
| medium | 719 |
| low | 1636 |
| informational | 402 |

accessibility is NOT recommended for integration: the scan surfaced 170 critical and 406 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering.

## 2. Source Provenance

- **Repository:** https://github.com/brendadeeznuts1111/tier-1380-omega
- **Commit scanned:** `unknown`
- **License:** unknown
- **Maintainer:** unknown
- **Version:** unknown

## 3. Per-Scanner Detail

### agentshield (v1.4.0) — Caution / 84.0

- **[high] Skill tampering or unsigned skill loading instruction** — Found "Skip verification" — Instructs agent to skip skill verification — allows tampered skills to execute. Reference: OpenClaw skill verification gate (vgzotta PR \#14893). (agents/cloudflare-debug.md:None)
- **[high] Skill tampering or unsigned skill loading instruction** — Found "Skip verification" — Instructs agent to skip skill verification — allows tampered skills to execute. Reference: OpenClaw skill verification gate (vgzotta PR \#14893). (agents/cloudflare-deploy.md:None)
- **[high] Skill tampering or unsigned skill loading instruction** — Found "Skip verification" — Instructs agent to skip skill verification — allows tampered skills to execute. Reference: OpenClaw skill verification gate (vgzotta PR \#14893). (agents/d1-migration.md:None)
- **[high] Destructive tool usage instruction detected** — Found "Drop tables" — Contains destructive SQL/database operations — drop tables, truncate, mass delete. From openclaw-security-guard tool manipulation patterns. (agents/d1-migration.md:None)
- **[medium] Agent definition effective size is 5580 characters (>5000 threshold)** — The agent definition at agents/a11y-auditor.md has an effective size of 5580 characters after discounting fenced code blocks and markdown tables. Unusually large agent definitions may contain hidden malicious instructions buried in legitimate-looking text. Review the full content carefully, especially any instructions near the end of the file. (agents/a11y-auditor.md:None)
- **[medium] Agent definition effective size is 5564 characters (>5000 threshold)** — The agent definition at agents/code-example-validator.md has an effective size of 5564 characters after discounting fenced code blocks and markdown tables. Unusually large agent definitions may contain hidden malicious instructions buried in legitimate-looking text. Review the full content carefully, especially any instructions near the end of the file. (agents/code-example-validator.md:None)
- **[medium] Agent definition effective size is 7700 characters (>5000 threshold)** — The agent definition at agents/content-accuracy-auditor.md has an effective size of 7700 characters after discounting fenced code blocks and markdown tables. Unusually large agent definitions may contain hidden malicious instructions buried in legitimate-looking text. Review the full content carefully, especially any instructions near the end of the file. (agents/content-accuracy-auditor.md:None)

### cisco-skill-scanner (v2.0.11) — Unsafe / 0.0

- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-python-workers/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 58% of skill content could be analyzed. 8 of 18 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-browser-rendering:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-browser-rendering/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts:20)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/basic-screenshot.ts:11)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/pdf-generation.ts:26)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/screenshot-with-kv-cache.ts:12)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts:47)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/web-scraper-basic.ts:21)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/web-scraper-batch.ts:57)
- **[high] Critically low analyzability score** — Only 51% of skill content could be analyzed. 10 of 21 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/ai-sdk-ui:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/ai-sdk-ui/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 88% of skill content could be analyzed. 3 of 21 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/cloudflare-worker-base:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-worker-base/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:25)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:51)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/src/index.ts:77)
- **[high] Critically low analyzability score** — Only 61% of skill content could be analyzed. 8 of 22 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/react-hook-form-zod:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/react-hook-form-zod/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:26)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:195)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:241)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/basic-form.tsx:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/server-validation.ts:222)
- **[high] Critically low analyzability score** — Only 53% of skill content could be analyzed. 11 of 24 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/tinacms:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tinacms/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tinacms/templates/cloudflare-worker-backend/src/index.ts:51)
- **[medium] Moderate analyzability score** — Only 89% of skill content could be analyzed. 1 of 9 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/google-gemini-file-search:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-file-search/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 64% of skill content could be analyzed. 7 of 20 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/openai-assistants:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-assistants/SKILL.md:None)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:40)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:43)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:106)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:66)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:67)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:71)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:76)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/vector-store-setup.ts:101)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/vector-store-setup.ts:110)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/skill-review/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/sveltia-cms/SKILL.md:None)
- **[high] find command with -exec flag can execute arbitrary commands on discovered files** — Pattern detected: find content -name "*.md" -exec  (/repo/skills/sveltia-cms/SKILL.md:504)
- **[high] find command with -exec flag can execute arbitrary commands on discovered files** — Pattern detected: find content -name "*.md" -exec  (/repo/skills/sveltia-cms/SKILL.md:521)
- **[medium] Moderate analyzability score** — Only 77% of skill content could be analyzed. 2 of 8 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/tanstack-router:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name 'TanStack Router' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/skills/tanstack-router/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-router/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 58% of skill content could be analyzed. 9 of 22 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/openai-responses:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-responses/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:13)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:74)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:108)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:122)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:146)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:163)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:200)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:227)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:249)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:297)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:20)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:61)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:66)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:71)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:95)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:128)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:155)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:185)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:190)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:195)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:200)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/image-generation.ts:132)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-responses/templates/image-generation.ts:137)
- **[medium] File extension does not match actual content type** — File 'web-search.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/openai-responses/templates/web-search.ts:None)
- **[high] Critically low analyzability score** — Only 51% of skill content could be analyzed. 4 of 8 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/firebase-auth:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firebase-auth/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/skill-creator/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/docs-workflow/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 78% of skill content could be analyzed. 2 of 9 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/firecrawl-scraper:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firecrawl-scraper/SKILL.md:None)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFile( (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:102)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:94)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:126)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:150)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:166)
- **[high] Critically low analyzability score** — Only 58% of skill content could be analyzed. 6 of 15 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/nextjs:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/nextjs/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:327)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/nextjs/templates/route-handler-api.ts:102)
- **[medium] Moderate analyzability score** — Only 79% of skill content could be analyzed. 1 of 5 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/google-workspace:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-workspace/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:37)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:79)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:99)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:127)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:165)
- **[medium] Moderate analyzability score** — Only 82% of skill content could be analyzed. 1 of 6 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/mcp-cli-scripts:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/mcp-cli-scripts/SKILL.md:None)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/mcp-cli-scripts/templates/script-template.ts:144)
- **[high] Critically low analyzability score** — Only 54% of skill content could be analyzed. 14 of 31 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/google-gemini-api:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-api/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:91)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:148)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:218)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:230)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-image.ts:29)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-image.ts:56)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:28)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:55)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:22)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:31)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:134)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch ( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:5)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:22)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:25)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:99)
- **[high] Critically low analyzability score** — Only 55% of skill content could be analyzed. 5 of 12 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/google-chat-api:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-chat-api/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/bearer-token-verify.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/interactive-bot.ts:31)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/webhook-handler.ts:17)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/webhook-handler.ts:30)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/wordpress-plugin-core/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 15% of skill content could be analyzed. 16 of 19 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/ts-agent-sdk:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/ts-agent-sdk/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/ts-agent-sdk/templates/api/base.ts:32)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/ts-agent-sdk/templates/client.ts:92)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: from 'child_process' (/repo/skills/ts-agent-sdk/templates/db/client.ts:8)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: execSync( (/repo/skills/ts-agent-sdk/templates/db/client.ts:175)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/ts-agent-sdk/templates/db/client.ts:210)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-planning/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 88% of skill content could be analyzed. 1 of 9 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/cloudflare-d1:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-d1/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 63% of skill content could be analyzed. 3 of 10 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/vercel-blob:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/vercel-blob/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-blob/templates/drag-drop-upload.tsx:115)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-blob/templates/file-list-manager.tsx:30)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-blob/templates/file-list-manager.tsx:66)
- **[high] Critically low analyzability score** — Only 56% of skill content could be analyzed. 6 of 13 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/playwright-local:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/playwright-local/SKILL.md:None)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFile( (/repo/skills/playwright-local/templates/authenticated-session.ts:27)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFile( (/repo/skills/playwright-local/templates/authenticated-session.ts:33)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/playwright-local/templates/basic-scrape.ts:29)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/playwright-local/templates/basic-scrape.ts:35)
- **[medium] Moderate analyzability score** — Only 71% of skill content could be analyzed. 7 of 22 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/cloudflare-hyperdrive:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-hyperdrive/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/drizzle-mysql.ts:30)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/drizzle-postgres.ts:30)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts:6)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts:17)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts:30)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/postgres-basic.ts:15)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/postgres-js.ts:17)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/postgres-pool.ts:15)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/prisma-postgres.ts:57)
- **[high] Critically low analyzability score** — Only 65% of skill content could be analyzed. 5 of 14 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-queues:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-queues/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:76)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:107)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:68)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/react-native-expo/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 48% of skill content could be analyzed. 8 of 15 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/email-gateway:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:110)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:153)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:196)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:265)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:225)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/resend-basic.ts:48)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/resend-basic.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/resend-react-email.tsx:152)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:191)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-transactional.ts:61)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-transactional.ts:203)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-bulk.ts:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-bulk.ts:286)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-send.ts:116)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-send.ts:179)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-send.ts:296)
- **[high] Critically low analyzability score** — Only 58% of skill content could be analyzed. 5 of 12 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-workflows:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-workflows/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/basic-workflow.ts:102)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts:231)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts:226)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts:214)
- **[high] Critically low analyzability score** — Only 53% of skill content could be analyzed. 12 of 24 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/ai-sdk-core:None)
- **[medium] Potential Anthropic brand impersonation** — Skill name or description contains 'Anthropic', suggesting official affiliation (/repo/skills/ai-sdk-core/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/ai-sdk-core/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 67% of skill content could be analyzed. 8 of 25 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-images:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-images/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:62)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:97)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:116)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:227)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:94)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:167)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:195)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/signed-urls-generation.ts:109)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:4)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:38)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:46)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:64)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:83)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:114)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:119)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:135)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:148)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:164)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:199)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:210)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:229)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:237)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:258)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:265)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:273)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-api-basic.ts:65)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-api-basic.ts:91)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-via-url.ts:63)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-via-url.ts:88)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:60)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:79)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:105)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:127)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:147)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:168)
- **[medium] Moderate analyzability score** — Only 87% of skill content could be analyzed. 3 of 23 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/elevenlabs-agents:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/elevenlabs-agents/SKILL.md:None)
- **[medium] Role reassignment pattern in asset file** — Pattern 'You are now ...' detected in asset file (/repo/skills/elevenlabs-agents/assets/agent-config-schema.json:60)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx:14)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx:24)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-session-management/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 59% of skill content could be analyzed. 8 of 20 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/zustand-state-management:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/zustand-state-management/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/zustand-state-management/templates/async-actions-store.ts:296)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/django-cloud-sql-postgres/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 78% of skill content could be analyzed. 2 of 8 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/firebase-firestore:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firebase-firestore/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/open-source-contributions/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 74% of skill content could be analyzed. 3 of 12 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/cloudflare-r2:None)
- **[medium] Undeclared network usage** — Skill code uses network libraries but doesn't declare network requirement (/repo/skills/cloudflare-r2/repo/skills/cloudflare-r2/SKILL.md:None)
- **[medium] Potential description-behavior mismatch** — Skill performs actions not reflected in its description (/repo/skills/cloudflare-r2/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-r2/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts:242)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts:259)
- **[high] Critically low analyzability score** — Only 42% of skill content could be analyzed. 17 of 30 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/openai-agents:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-agents/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts:6)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts:45)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:32)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:80)
- **[high] Prompt injection pattern in asset file** — Pattern 'ignore previous instructions...' detected in asset file (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:84)
- **[high] Prompt injection pattern in asset file** — Pattern 'Ignore previous instructions...' detected in asset file (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:128)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:98)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:131)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:177)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:197)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firebase-storage/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/jquery-4/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-spaces-updates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/fastapi/SKILL.md:None)
- **[medium] File extension does not match actual content type** — File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file. (/repo/skills/fastapi/templates/src/auth/__init__.py:None)
- **[medium] File extension does not match actual content type** — File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file. (/repo/skills/fastapi/templates/tests/__init__.py:None)
- **[high] Critically low analyzability score** — Only 49% of skill content could be analyzed. 15 of 30 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/openai-api:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-api/SKILL.md:None)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:25)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/audio-transcription.ts:43)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:72)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:106)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:138)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:174)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/audio-transcription.ts:178)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/cloudflare-worker.ts:14)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/cloudflare-worker.ts:42)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:26)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:30)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:52)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:53)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:58)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:80)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:86)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:99)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/image-editing.ts:101)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:115)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:124)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:140)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:165)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:169)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:189)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:204)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:209)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:232)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:238)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:244)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:250)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:266)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:269)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/image-generation.ts:156)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-generation.ts:168)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/image-generation.ts:172)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/rate-limit-handling.ts:72)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/streaming-fetch.ts:9)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/streaming-fetch.ts:17)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:32)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:68)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:93)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:104)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:125)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:136)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:147)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:172)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:201)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:230)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/text-to-speech.ts:242)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:279)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:296)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/openai-api/templates/vision-gpt4o.ts:54)
- **[high] Critically low analyzability score** — Only 54% of skill content could be analyzed. 5 of 11 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/electron-base:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/electron-base/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:113)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:144)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:215)
- **[medium] Moderate analyzability score** — Only 71% of skill content could be analyzed. 6 of 21 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/typescript-mcp:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/typescript-mcp/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/typescript-mcp/templates/tool-server.ts:55)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name 'TanStack Start' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/skills/tanstack-start/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-start/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 59% of skill content could be analyzed. 7 of 17 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/auto-animate:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/auto-animate/SKILL.md:None)
- **[medium] Hardcoded password or secret in variable** — Pattern detected: pass**** (/repo/skills/auto-animate/templates/form-validation.tsx:43)
- **[medium] Hardcoded password or secret in variable** — Pattern detected: pass**** (/repo/skills/auto-animate/templates/form-validation.tsx:45)
- **[high] Critically low analyzability score** — Only 61% of skill content could be analyzed. 4 of 11 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-kv:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-kv/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 72% of skill content could be analyzed. 5 of 19 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/cloudflare-turnstile:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-turnstile/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:39)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx:34)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx:165)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:135)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-test-config.ts:280)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:184)
- **[high] Critically low analyzability score** — Only 58% of skill content could be analyzed. 5 of 13 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/neon-vercel-postgres:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/neon-vercel-postgres/SKILL.md:None)
- **[medium] File extension does not match actual content type** — File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/neon-vercel-postgres/assets/drizzle-schema.ts:None)
- **[medium] File extension does not match actual content type** — File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/neon-vercel-postgres/templates/drizzle-schema.ts:None)
- **[high] Critically low analyzability score** — Only 67% of skill content could be analyzed. 7 of 22 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-durable-objects:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-durable-objects/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/basic-do.ts:66)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/location-hints.ts:34)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/location-hints.ts:107)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/location-hints.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:223)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:80)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:114)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:178)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:200)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:212)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:46)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:204)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:223)
- **[high] Critically low analyzability score** — Only 64% of skill content could be analyzed. 8 of 23 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/drizzle-orm-d1:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/drizzle-orm-d1/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/drizzle-orm-d1/templates/client.ts:44)
- **[high] Critically low analyzability score** — Only 56% of skill content could be analyzed. 6 of 14 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/better-auth:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/better-auth/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 49% of skill content could be analyzed. 5 of 10 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/azure-auth:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/azure-auth/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/use-api-token.ts:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/use-api-token.ts:156)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/use-api-token.ts:215)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/workers-jwt-validation.ts:87)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/workers-jwt-validation.ts:206)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-workflow/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 54% of skill content could be analyzed. 8 of 18 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/hono-routing:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/hono-routing/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 60% of skill content could be analyzed. 9 of 23 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/tanstack-query:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-query/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/error-boundary.tsx:171)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/error-boundary.tsx:186)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-infinite-query.tsx:25)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:23)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:37)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:54)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:104)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:157)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-query-basic.tsx:18)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-query-basic.tsx:55)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/favicon-gen/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 52% of skill content could be analyzed. 11 of 24 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/claude-api:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/claude-api/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:10)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:76)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:124)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:151)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:231)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/prompt-caching.ts:84)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/claude-api/templates/tool-use-advanced.ts:52)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:12)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:60)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:61)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:119)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:160)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:215)
- **[medium] Moderate analyzability score** — Only 71% of skill content could be analyzed. 8 of 29 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/clerk-auth:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/clerk-auth/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: https.request( (/repo/skills/clerk-auth/scripts/generate-session-token.js:56)
- **[medium] Hardcoded password or secret in variable** — Pattern detected: pass**** (/repo/skills/clerk-auth/scripts/generate-session-token.js:96)
- **[low] Hidden data file detected** — Hidden file found: templates/env-examples/.dev.vars.example. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/skills/clerk-auth/templates/env-examples/.dev.vars.example:None)
- **[low] Hidden data file detected** — Hidden file found: templates/env-examples/.env.local.example. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/skills/clerk-auth/templates/env-examples/.env.local.example:None)
- **[low] Hidden data file detected** — Hidden file found: templates/env-examples/.env.local.vite.example. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/skills/clerk-auth/templates/env-examples/.env.local.vite.example:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/clerk-auth/templates/react/App.tsx:150)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/accessibility/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 28% of skill content could be analyzed. 13 of 18 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-agents:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-agents/SKILL.md:None)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-agents/templates/browser-agent.ts:126)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-agents/templates/browser-agent.ts:132)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts:12)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts:49)
- **[high] Critically low analyzability score** — Only 57% of skill content could be analyzed. 5 of 12 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/mcp-oauth-cloudflare:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name 'MCP OAuth Cloudflare' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/skills/mcp-oauth-cloudflare/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:87)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:141)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/flask/SKILL.md:None)
- **[medium] File extension does not match actual content type** — File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file. (/repo/skills/flask/templates/tests/__init__.py:None)
- **[critical] INJECTION ATTACK detected by YARA** — Detects SQL injection attack patterns including keywords, tautologies, and database functions: SELECT table_name, row_count, bytes     FROM {quote_identifier(database)}.information_schema (/repo/skills/streamlit-snowflake/templates/pages/data_explorer.py:76)
- **[high] Critically low analyzability score** — Only 59% of skill content could be analyzed. 9 of 22 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/claude-agent-sdk:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/claude-agent-sdk/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts:29)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts:109)
- **[medium] File extension does not match actual content type** — File 'filesystem-settings.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:None)
- **[high] Critically low analyzability score** — Only 68% of skill content could be analyzed. 7 of 24 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-mcp-server:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-mcp-server/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:153)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:159)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:172)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:195)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:202)
- **[medium] File extension does not match actual content type** — File 'mcp-bearer-auth.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:193)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:243)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:366)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:376)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:17)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:23)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:115)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:129)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:149)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts:322)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts:346)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts:522)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts:544)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts:549)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:264)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:286)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:291)
- **[medium] Moderate analyzability score** — Only 74% of skill content could be analyzed. 4 of 15 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/tailwind-patterns:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tailwind-patterns/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tailwind-patterns/templates/components/contact-form.tsx:259)
- **[medium] Undeclared network usage** — Skill code uses network libraries but doesn't declare network requirement (/repo/skills/fastmcp/repo/skills/fastmcp/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/fastmcp/SKILL.md:None)
- **[high] Infinite loop without clear exit condition** — Pattern detected: while True: (/repo/skills/fastmcp/templates/client-example.py:252)
- **[medium] Outbound network request primitives that can transmit data externally** — Pattern detected: httpx.get( (/repo/skills/fastmcp/templates/openapi-integration.py:31)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/sub-agent-patterns/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 64% of skill content could be analyzed. 6 of 17 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/google-gemini-embeddings:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-embeddings/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts:72)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:91)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:124)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:164)
- **[medium] Moderate analyzability score** — Only 84% of skill content could be analyzed. 3 of 15 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/tailwind-v4-shadcn:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tailwind-v4-shadcn/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 62% of skill content could be analyzed. 5 of 14 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/cloudflare-workers-ai:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-workers-ai/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workers-ai/templates/ai-vision-models.ts:323)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name 'OpenAI Apps MCP' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/skills/openai-apps-mcp/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-apps-mcp/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 73% of skill content could be analyzed. 2 of 9 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/vercel-kv:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/vercel-kv/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-kv/templates/simple-rate-limiting.ts:303)
- **[medium] Moderate analyzability score** — Only 76% of skill content could be analyzed. 3 of 13 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/tiptap:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tiptap/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tiptap/templates/image-upload-r2.tsx:87)
- **[high] Critically low analyzability score** — Only 62% of skill content could be analyzed. 6 of 16 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/tanstack-table:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name 'TanStack Table' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/skills/tanstack-table/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-table/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-table/templates/server-paginated-table.tsx:67)
- **[high] Critically low analyzability score** — Only 65% of skill content could be analyzed. 5 of 15 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/motion:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/motion/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-app-engine/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 73% of skill content could be analyzed. 4 of 15 files are opaque to the scanner. Some content could not be verified as safe. (/repo/skills/cloudflare-vectorize:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-vectorize/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/basic-search.ts:32)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:86)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:237)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:259)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts:28)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/rag-chat.ts:40)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/icon-design/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 65% of skill content could be analyzed. 5 of 15 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/office:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/office/SKILL.md:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name '[{'TODO': 'lowercase-hyphen-case-name'}]' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/templates/skill-skeleton/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/templates/skill-skeleton/SKILL.md:None)
- **[medium] Moderate analyzability score** — Only 76% of skill content could be analyzed. 412 of 1701 files are opaque to the scanner. Some content could not be verified as safe. (/repo:None)
- **[low] Skill package contains many files** — Skill package contains 1701 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content. (/repo/.:None)
- **[low] Hidden data file detected** — Hidden file found: .env.development. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/.env.development:None)
- **[low] Hidden data file detected** — Hidden file found: .env.production. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/.env.production:None)
- **[medium] Undeclared network usage** — Skill code uses network libraries but doesn't declare network requirement (/repo/repo/BUN_CROSS_PLATFORM_ENV.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/SKILL.md:None)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: exec( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:2263)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: exec( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:7061)
- **[medium] Hardcoded password or secret in variable** — Pattern detected: toke**** (/repo/scripts/check-github-releases.sh:76)
- **[medium] Hardcoded password or secret in variable** — Pattern detected: pass**** (/repo/skills/auto-animate/templates/form-validation.tsx:43)
- **[medium] Hardcoded password or secret in variable** — Pattern detected: pass**** (/repo/skills/auto-animate/templates/form-validation.tsx:45)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/use-api-token.ts:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/use-api-token.ts:156)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/use-api-token.ts:215)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/workers-jwt-validation.ts:87)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/azure-auth/templates/workers-jwt-validation.ts:206)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts:29)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts:109)
- **[medium] File extension does not match actual content type** — File 'filesystem-settings.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:10)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:76)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:124)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:151)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/claude-api/templates/cloudflare-worker.ts:231)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/prompt-caching.ts:84)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/claude-api/templates/tool-use-advanced.ts:52)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:12)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:60)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:61)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:119)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:160)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/claude-api/templates/vision-image.ts:215)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: https.request( (/repo/skills/clerk-auth/scripts/generate-session-token.js:56)
- **[medium] Hardcoded password or secret in variable** — Pattern detected: pass**** (/repo/skills/clerk-auth/scripts/generate-session-token.js:96)
- **[low] Hidden data file detected** — Hidden file found: skills/clerk-auth/templates/env-examples/.dev.vars.example. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/skills/clerk-auth/templates/env-examples/.dev.vars.example:None)
- **[low] Hidden data file detected** — Hidden file found: skills/clerk-auth/templates/env-examples/.env.local.example. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/skills/clerk-auth/templates/env-examples/.env.local.example:None)
- **[low] Hidden data file detected** — Hidden file found: skills/clerk-auth/templates/env-examples/.env.local.vite.example. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/skills/clerk-auth/templates/env-examples/.env.local.vite.example:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/clerk-auth/templates/react/App.tsx:150)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-agents/templates/browser-agent.ts:126)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-agents/templates/browser-agent.ts:132)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts:12)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts:49)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts:20)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/basic-screenshot.ts:11)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/pdf-generation.ts:26)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/screenshot-with-kv-cache.ts:12)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts:47)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/web-scraper-basic.ts:21)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-browser-rendering/templates/web-scraper-batch.ts:57)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/basic-do.ts:66)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/location-hints.ts:34)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/location-hints.ts:107)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/location-hints.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:223)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:80)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:114)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:178)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:200)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts:212)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:46)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:204)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:223)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/drizzle-mysql.ts:30)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/drizzle-postgres.ts:30)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts:6)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts:17)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts:30)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/postgres-basic.ts:15)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/postgres-js.ts:17)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/postgres-pool.ts:15)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-hyperdrive/templates/prisma-postgres.ts:57)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:62)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:97)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:116)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/batch-upload.ts:227)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:94)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:167)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:195)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/signed-urls-generation.ts:109)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:4)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:38)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:46)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:64)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:83)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:114)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:119)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:135)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:148)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:164)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:199)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:210)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:229)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:237)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:258)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:265)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:273)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-api-basic.ts:65)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-api-basic.ts:91)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-via-url.ts:63)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/upload-via-url.ts:88)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:60)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:79)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:105)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:127)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:147)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-images/templates/variants-management.ts:168)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:153)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:159)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:172)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:195)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:202)
- **[medium] File extension does not match actual content type** — File 'mcp-bearer-auth.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:193)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:243)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:366)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:376)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:17)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:23)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:115)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:129)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:149)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts:322)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts:346)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts:522)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts:544)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts:549)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:264)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:286)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:291)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:76)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:107)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts:242)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts:259)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:39)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx:34)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx:165)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:135)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-test-config.ts:280)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/basic-search.ts:32)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:86)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:237)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:259)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts:28)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-vectorize/templates/rag-chat.ts:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:25)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:51)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/public/script.js:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-worker-base/templates/src/index.ts:77)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workers-ai/templates/ai-vision-models.ts:323)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/basic-workflow.ts:102)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts:231)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts:226)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts:214)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/drizzle-orm-d1/templates/client.ts:44)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:113)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:144)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:215)
- **[medium] Role reassignment pattern in asset file** — Pattern 'You are now ...' detected in asset file (/repo/skills/elevenlabs-agents/assets/agent-config-schema.json:60)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx:14)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx:24)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:110)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:153)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:196)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-send.ts:265)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:225)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/resend-basic.ts:48)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/resend-basic.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/resend-react-email.tsx:152)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:191)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-transactional.ts:61)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/sendgrid-transactional.ts:203)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-bulk.ts:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-bulk.ts:286)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-send.ts:116)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-send.ts:179)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/email-gateway/templates/smtp2go-send.ts:296)
- **[medium] File extension does not match actual content type** — File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file. (/repo/skills/fastapi/templates/src/auth/__init__.py:None)
- **[medium] File extension does not match actual content type** — File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file. (/repo/skills/fastapi/templates/tests/__init__.py:None)
- **[high] Infinite loop without clear exit condition** — Pattern detected: while True: (/repo/skills/fastmcp/templates/client-example.py:252)
- **[medium] Outbound network request primitives that can transmit data externally** — Pattern detected: httpx.get( (/repo/skills/fastmcp/templates/openapi-integration.py:31)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFile( (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:102)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:94)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:126)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:150)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:166)
- **[medium] File extension does not match actual content type** — File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file. (/repo/skills/flask/templates/tests/__init__.py:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/bearer-token-verify.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/interactive-bot.ts:31)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/webhook-handler.ts:17)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-chat-api/templates/webhook-handler.ts:30)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:29)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:91)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:148)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:218)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:230)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-image.ts:29)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-image.ts:56)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:28)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:55)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:82)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:22)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:31)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:134)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch ( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:5)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:22)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:25)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:99)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts:72)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:91)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:124)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:164)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:37)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:79)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:99)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:127)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/google-workspace/templates/oauth-worker.ts:165)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/mcp-cli-scripts/templates/script-template.ts:144)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:87)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:141)
- **[medium] File extension does not match actual content type** — File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/neon-vercel-postgres/assets/drizzle-schema.ts:None)
- **[medium] File extension does not match actual content type** — File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/neon-vercel-postgres/templates/drizzle-schema.ts:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:327)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/nextjs/templates/route-handler-api.ts:102)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts:6)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts:45)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:32)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:80)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:25)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/audio-transcription.ts:43)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:72)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:106)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:138)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/audio-transcription.ts:174)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/audio-transcription.ts:178)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/cloudflare-worker.ts:14)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/cloudflare-worker.ts:42)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:26)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:30)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:52)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:53)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:58)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:80)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:86)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:99)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/image-editing.ts:101)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:115)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:124)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:140)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:165)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:169)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:184)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:189)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:204)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:209)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:232)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:238)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:244)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:250)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-api/templates/image-editing.ts:266)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-editing.ts:269)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/image-generation.ts:156)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/image-generation.ts:168)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/image-generation.ts:172)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/rate-limit-handling.ts:72)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/streaming-fetch.ts:9)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/streaming-fetch.ts:17)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:32)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:68)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:93)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:104)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:125)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:136)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:147)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:172)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:201)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:230)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-api/templates/text-to-speech.ts:242)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:279)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-api/templates/text-to-speech.ts:296)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFileSync( (/repo/skills/openai-api/templates/vision-gpt4o.ts:54)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:40)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:43)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:106)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:66)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:67)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:71)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/file-search-assistant.ts:76)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-assistants/templates/vector-store-setup.ts:101)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-assistants/templates/vector-store-setup.ts:110)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:13)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:74)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:108)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:122)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:146)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:163)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:183)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:200)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:227)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:249)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/cloudflare-worker.ts:297)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:20)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:61)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:66)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:71)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:95)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:128)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:155)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:185)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:190)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:195)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.createReadStream( (/repo/skills/openai-responses/templates/file-search.ts:200)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/openai-responses/templates/image-generation.ts:132)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/openai-responses/templates/image-generation.ts:137)
- **[medium] File extension does not match actual content type** — File 'web-search.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/openai-responses/templates/web-search.ts:None)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFile( (/repo/skills/playwright-local/templates/authenticated-session.ts:27)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.readFile( (/repo/skills/playwright-local/templates/authenticated-session.ts:33)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/playwright-local/templates/basic-scrape.ts:29)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: eval( (/repo/skills/playwright-local/templates/basic-scrape.ts:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:26)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:195)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:241)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/basic-form.tsx:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/react-hook-form-zod/templates/server-validation.ts:222)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:98)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:131)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:177)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:197)
- **[critical] INJECTION ATTACK detected by YARA** — Detects SQL injection attack patterns including keywords, tautologies, and database functions: SELECT table_name, row_count, bytes     FROM {quote_identifier(database)}.information_schema (/repo/skills/streamlit-snowflake/templates/pages/data_explorer.py:76)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tailwind-patterns/templates/components/contact-form.tsx:259)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/error-boundary.tsx:171)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/error-boundary.tsx:186)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-infinite-query.tsx:25)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:23)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:37)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:54)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:40)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:104)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:157)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-query-basic.tsx:18)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-query/templates/use-query-basic.tsx:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tanstack-table/templates/server-paginated-table.tsx:67)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tinacms/templates/cloudflare-worker-backend/src/index.ts:51)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/tiptap/templates/image-upload-r2.tsx:87)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/ts-agent-sdk/templates/api/base.ts:32)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/ts-agent-sdk/templates/client.ts:92)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: from 'child_process' (/repo/skills/ts-agent-sdk/templates/db/client.ts:8)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: execSync( (/repo/skills/ts-agent-sdk/templates/db/client.ts:175)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/ts-agent-sdk/templates/db/client.ts:210)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/typescript-mcp/templates/tool-server.ts:55)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-blob/templates/drag-drop-upload.tsx:115)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-blob/templates/file-list-manager.tsx:30)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-blob/templates/file-list-manager.tsx:66)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/vercel-kv/templates/simple-rate-limiting.ts:303)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/zustand-state-management/templates/async-actions-store.ts:296)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: require('child_process') (/repo/tools/statusline-npm/bin/cli.js:3)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:21)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:31)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:71)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:79)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:107)
- **[low] Skill package contains many files** — Skill package contains 117 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content. (/repo/planning/.:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/planning/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/planning/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/profiles/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/profiles/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/docs/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/docs/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/.claude/agents/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/planning/clerk-docs/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/planning/research-logs/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/planning/research-logs/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-python-workers/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-python-workers/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-browser-rendering/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-browser-rendering/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-browser-rendering/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-browser-rendering/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/ai-sdk-ui/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/ai-sdk-ui/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/ai-sdk-ui/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/ai-sdk-ui/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-worker-base/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-worker-base/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-worker-base/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-worker-base/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-worker-base/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-worker-base/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-worker-base/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/react-hook-form-zod/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/react-hook-form-zod/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/react-hook-form-zod/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/react-hook-form-zod/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tinacms/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tinacms/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tinacms/assets/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tinacms/assets/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-gemini-file-search/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-file-search/references/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 48% of skill content could be analyzed. 1 of 2 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/google-gemini-file-search/scripts:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-gemini-file-search/scripts/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-file-search/scripts/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-gemini-file-search/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-file-search/templates/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-assistants/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-assistants/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-assistants/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-assistants/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/skill-review/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/skill-review/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/responsive-images/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/responsive-images/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/responsive-images/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/responsive-images/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/sveltia-cms/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/sveltia-cms/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/sveltia-cms/templates/cloudflare-workers/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/sveltia-cms/templates/cloudflare-workers/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tanstack-router/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-router/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tanstack-router/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-router/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-responses/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-responses/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-responses/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-responses/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/firebase-auth/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firebase-auth/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/docs-workflow/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/docs-workflow/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/docs-workflow/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/docs-workflow/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/docs-workflow/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/docs-workflow/templates/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/oauth-integrations/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/oauth-integrations/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/firecrawl-scraper/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firecrawl-scraper/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/nextjs/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/nextjs/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/nextjs/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/nextjs/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/nextjs/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/nextjs/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-workspace/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-workspace/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/mcp-cli-scripts/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/mcp-cli-scripts/rules/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 47% of skill content could be analyzed. 1 of 2 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/mcp-cli-scripts/templates:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/mcp-cli-scripts/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/mcp-cli-scripts/templates/SKILL.md:None)
- **[high] Node.js filesystem access that could read or write sensitive data** — Pattern detected: fs.writeFileSync( (/repo/skills/mcp-cli-scripts/templates/script-template.ts:144)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-gemini-api/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-api/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-gemini-api/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-api/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-chat-api/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-chat-api/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/wordpress-plugin-core/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/wordpress-plugin-core/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/wordpress-plugin-core/templates/plugin-simple/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/wordpress-plugin-core/templates/plugin-simple/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/wordpress-plugin-core/templates/plugin-oop/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/wordpress-plugin-core/templates/plugin-oop/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/wordpress-plugin-core/templates/plugin-psr4/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/wordpress-plugin-core/templates/plugin-psr4/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/project-planning/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-planning/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/project-planning/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-planning/templates/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/project-planning/references/example-outputs/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-planning/references/example-outputs/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/developer-toolbox/agents/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/developer-toolbox/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-d1/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-d1/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-d1/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-d1/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/vercel-blob/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/vercel-blob/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/playwright-local/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/playwright-local/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:None)
- **[high] Database connection string with embedded credentials** — Pattern detected: post**** (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:2335)
- **[high] Database connection string with embedded credentials** — Pattern detected: post**** (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:2367)
- **[high] Database connection string with embedded credentials** — Pattern detected: post**** (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:2411)
- **[high] Database connection string with embedded credentials** — Pattern detected: post**** (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:3740)
- **[high] Database connection string with embedded credentials** — Pattern detected: post**** (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:3768)
- **[high] Database connection string with embedded credentials** — Pattern detected: post**** (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:3932)
- **[high] Database connection string with embedded credentials** — Pattern detected: post**** (/repo/skills/cloudflare-hyperdrive/references/SKILL.md:3942)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-hyperdrive/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-hyperdrive/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-queues/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-queues/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-queues/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-queues/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/react-native-expo/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/react-native-expo/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/react-native-expo/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/react-native-expo/assets/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/react-native-expo/assets/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/email-gateway/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/email-gateway/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-workflows/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-workflows/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-workflows/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-workflows/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/ai-sdk-core/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/ai-sdk-core/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/ai-sdk-core/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/ai-sdk-core/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-images/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-images/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-images/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-images/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/elevenlabs-agents/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/elevenlabs-agents/references/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 61% of skill content could be analyzed. 3 of 8 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/elevenlabs-agents/assets:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/elevenlabs-agents/assets/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/elevenlabs-agents/assets/SKILL.md:None)
- **[medium] Role reassignment pattern in asset file** — Pattern 'You are now ...' detected in asset file (/repo/skills/elevenlabs-agents/assets/agent-config-schema.json:60)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx:14)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx:24)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/project-session-management/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-session-management/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/project-session-management/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-session-management/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/project-session-management/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-session-management/templates/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/zustand-state-management/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/zustand-state-management/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/zustand-state-management/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/zustand-state-management/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/django-cloud-sql-postgres/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/django-cloud-sql-postgres/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/django-cloud-sql-postgres/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/django-cloud-sql-postgres/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/firebase-firestore/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firebase-firestore/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/open-source-contributions/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/open-source-contributions/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/open-source-contributions/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/open-source-contributions/assets/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/open-source-contributions/assets/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-r2/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-r2/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-r2/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-r2/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-agents/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-agents/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-agents/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-agents/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/snowflake-platform/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/snowflake-platform/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/snowflake-platform/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/snowflake-platform/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/snowflake-platform/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/firebase-storage/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/firebase-storage/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/jquery-4/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/jquery-4/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/color-palette/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/color-palette/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/color-palette/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/color-palette/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/color-palette/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-spaces-updates/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-spaces-updates/templates/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/agent-development/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/agent-development/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-api/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-api/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-api/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-api/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/electron-base/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/electron-base/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/electron-base/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/electron-base/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/typescript-mcp/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/typescript-mcp/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/typescript-mcp/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/typescript-mcp/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/typescript-mcp/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/typescript-mcp/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tanstack-start/planning/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-start/planning/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/auto-animate/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/auto-animate/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-kv/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-kv/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-kv/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-kv/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-turnstile/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-turnstile/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-turnstile/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-turnstile/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/neon-vercel-postgres/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/neon-vercel-postgres/references/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 36% of skill content could be analyzed. 3 of 5 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/neon-vercel-postgres/templates:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/neon-vercel-postgres/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/neon-vercel-postgres/templates/SKILL.md:None)
- **[medium] File extension does not match actual content type** — File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file. (/repo/skills/neon-vercel-postgres/templates/drizzle-schema.ts:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-durable-objects/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-durable-objects/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-durable-objects/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-durable-objects/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/drizzle-orm-d1/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/drizzle-orm-d1/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/drizzle-orm-d1/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/drizzle-orm-d1/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/drizzle-orm-d1/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/drizzle-orm-d1/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/drizzle-orm-d1/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/better-auth/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/better-auth/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/better-auth/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/better-auth/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/better-auth/assets/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/better-auth/assets/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 46% of skill content could be analyzed. 1 of 2 files are opaque to the scanner. The safety assessment has low confidence. (/repo/skills/better-auth/references/nextjs:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/better-auth/references/nextjs/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/better-auth/references/nextjs/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/azure-auth/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/azure-auth/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/azure-auth/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/azure-auth/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/seo-meta/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/seo-meta/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/seo-meta/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/seo-meta/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/seo-meta/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/project-workflow/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/project-workflow/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/hono-routing/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/hono-routing/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/hono-routing/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/hono-routing/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tanstack-query/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-query/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tanstack-query/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-query/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/favicon-gen/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/favicon-gen/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/favicon-gen/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/favicon-gen/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/favicon-gen/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/image-gen/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/image-gen/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/image-gen/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/image-gen/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/image-gen/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/claude-api/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/claude-api/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/claude-api/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/claude-api/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/clerk-auth/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/clerk-auth/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/clerk-auth/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/clerk-auth/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/clerk-auth/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/clerk-auth/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/clerk-auth/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/accessibility/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/accessibility/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/accessibility/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/accessibility/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/accessibility/rules/SKILL.md:None)
- **[critical] INJECTION ATTACK detected by YARA** — Detects malicious script injection patterns in agent skills: href="javascript:v (/repo/skills/accessibility/rules/SKILL.md:14)
- **[critical] INJECTION ATTACK detected by YARA** — Detects malicious script injection patterns in agent skills: <html (/repo/skills/accessibility/rules/SKILL.md:200)
- **[critical] INJECTION ATTACK detected by YARA** — Detects malicious script injection patterns in agent skills: href="javascript:v (/repo/skills/accessibility/rules/accessibility.md:14)
- **[critical] INJECTION ATTACK detected by YARA** — Detects malicious script injection patterns in agent skills: <html (/repo/skills/accessibility/rules/accessibility.md:200)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-agents/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-agents/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/mcp-oauth-cloudflare/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/mcp-oauth-cloudflare/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/mcp-oauth-cloudflare/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/mcp-oauth-cloudflare/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/streamlit-snowflake/templates-container-runtime/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/streamlit-snowflake/templates-container-runtime/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/streamlit-snowflake/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/streamlit-snowflake/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/streamlit-snowflake/templates-native-app/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/streamlit-snowflake/templates-native-app/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/claude-agent-sdk/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/claude-agent-sdk/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/claude-agent-sdk/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/claude-agent-sdk/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-mcp-server/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-mcp-server/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-mcp-server/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-mcp-server/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-mcp-server/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-mcp-server/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tailwind-patterns/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tailwind-patterns/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tailwind-patterns/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tailwind-patterns/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/fastmcp/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/fastmcp/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/fastmcp/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/fastmcp/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/fastmcp/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/sub-agent-patterns/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-gemini-embeddings/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-embeddings/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-gemini-embeddings/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-gemini-embeddings/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tailwind-v4-shadcn/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tailwind-v4-shadcn/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tailwind-v4-shadcn/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tailwind-v4-shadcn/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tailwind-v4-shadcn/commands/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tailwind-v4-shadcn/commands/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-workers-ai/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-workers-ai/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-workers-ai/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-workers-ai/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/openai-apps-mcp/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/openai-apps-mcp/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/vercel-kv/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/vercel-kv/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tiptap/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tiptap/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tiptap/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tiptap/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tanstack-table/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-table/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/tanstack-table/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/tanstack-table/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/motion/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/motion/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/motion/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/motion/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-app-engine/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-app-engine/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/google-app-engine/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/google-app-engine/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-vectorize/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-vectorize/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/cloudflare-vectorize/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/cloudflare-vectorize/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/icon-design/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/icon-design/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/icon-design/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/icon-design/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/icon-design/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/office/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/office/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/office/agents/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/skills/office/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/office/rules/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/.github/ISSUE_TEMPLATE/SKILL.md:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name 'Skill Request' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/.github/ISSUE_TEMPLATE/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/.github/ISSUE_TEMPLATE/SKILL.md:None)
- **[high] Critically low analyzability score** — Only 65% of skill content could be analyzed. 6 of 18 files are opaque to the scanner. The safety assessment has low confidence. (/repo/examples/cloudflare-worker-base-test:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/examples/cloudflare-worker-base-test/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/examples/cloudflare-worker-base-test/SKILL.md:None)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/public/script.js:25)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/public/script.js:35)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/public/script.js:51)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/public/script.js:68)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/src/index.ts:77)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:217)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:315)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:392)
- **[medium] Outbound network request primitives in JavaScript/TypeScript** — Pattern detected: fetch( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:1452)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: exec( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:2263)
- **[critical] Dangerous code execution functions that can execute arbitrary code** — Pattern detected: exec( (/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts:7061)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/tools/statusline/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/tools/statusline/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/tools/statusline-npm/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/tools/statusline-npm/SKILL.md:None)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: require('child_process') (/repo/tools/statusline-npm/bin/cli.js:3)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:21)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:31)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:71)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:79)
- **[critical] Node.js child_process module usage for shell command execution** — Pattern detected: spawnSync( (/repo/tools/statusline-npm/bin/cli.js:107)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/templates/skill-skeleton/references/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/templates/skill-skeleton/references/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/archive/deprecated-scripts/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/archive/deprecated-scripts/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/archive/session-logs/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/archive/session-logs/SKILL.md:None)

### agent-audit-kit (v0.3.26) — Unsafe / 0.0

- **[high] Generic high-entropy secret** — A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key. (scripts/deep-audit-scrape.py:156)
- **[high] Generic high-entropy secret** — A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key. (skills/firecrawl-scraper/templates/firecrawl-crawl-example.py:36)
- **[high] Generic high-entropy secret** — A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key. (skills/firecrawl-scraper/templates/firecrawl-scrape-python.py:37)
- **[high] Generic high-entropy secret** — A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key. (skills/clerk-auth/templates/env-examples/.env.local.vite.example:39)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:152)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:173)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:180)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:187)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:203)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:204)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:353)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:354)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:354)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:354)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:354)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:393)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:403)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:410)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:411)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:436)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:438)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:439)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (CLAUDE.md:None)
- **[high] Agent instructions reference external URLs** — Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints. (CLAUDE.md:609)
- **[high] Agent instructions reference external URLs** — Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints. (CLAUDE.md:612)
- **[high] Agent instructions reference external URLs** — Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints. (CLAUDE.md:613)
- **[high] Agent instructions reference external URLs** — Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints. (CLAUDE.md:614)
- **[high] Agent instructions reference external URLs** — Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints. (CLAUDE.md:719)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/ai-sdk-ui/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/cloudflare-worker-base/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/tinacms/templates/nextjs/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/tinacms/templates/astro/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/tinacms/templates/vite-react/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/openai-assistants/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/tanstack-router/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/openai-responses/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/nextjs/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/google-gemini-api/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/vercel-blob/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/cloudflare-images/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/openai-agents/templates/shared/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/openai-api/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/neon-vercel-postgres/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/cloudflare-durable-objects/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/hono-routing/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/tanstack-query/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/clerk-auth/templates/vite/package.json:5)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/claude-agent-sdk/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/cloudflare-mcp-server/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/google-gemini-embeddings/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/openai-apps-mcp/templates/basic/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/vercel-kv/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/tiptap/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (skills/tanstack-table/templates/package.json:2)
- **[medium] Dependency with no declared license** — A dependency has no declared license, creating legal uncertainty about usage rights. (examples/cloudflare-worker-base-test/package.json:2)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:14)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:25)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:48)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:69)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:90)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:105)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:114)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:125)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:135)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:145)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:154)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:164)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:172)
- **[critical] SKILL.md contains a post-install / side-effect command** — A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk. (skills/tinacms/SKILL.md:28)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/tinacms/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/google-gemini-file-search/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/openai-responses/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/firebase-auth/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/skill-creator/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/firecrawl-scraper/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/nextjs/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/google-gemini-api/SKILL.md:None)
- **[critical] SKILL.md contains a post-install / side-effect command** — A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk. (skills/playwright-local/SKILL.md:902)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/email-gateway/SKILL.md:None)
- **[critical] SKILL.md contains a post-install / side-effect command** — A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk. (skills/ai-sdk-core/SKILL.md:198)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/ai-sdk-core/SKILL.md:None)
- **[critical] SKILL.md contains a post-install / side-effect command** — A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk. (skills/elevenlabs-agents/SKILL.md:30)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/elevenlabs-agents/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/django-cloud-sql-postgres/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/openai-agents/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/openai-api/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/tanstack-start/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/cloudflare-turnstile/SKILL.md:None)
- **[critical] SKILL.md contains a post-install / side-effect command** — A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk. (skills/neon-vercel-postgres/SKILL.md:154)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/neon-vercel-postgres/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/better-auth/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/clerk-auth/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/fastmcp/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/google-gemini-embeddings/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/vercel-kv/SKILL.md:None)
- **[critical] SKILL.md embeds data-exfiltration primitives** — A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials). (skills/google-app-engine/SKILL.md:None)
- **[critical] SKILL.md contains a post-install / side-effect command** — A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk. (skills/cloudflare-vectorize/SKILL.md:519)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/typescript-mcp/templates/resource-server.ts:14)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/typescript-mcp/templates/tasks-server.ts:22)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/typescript-mcp/templates/basic-mcp-server.ts:14)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/typescript-mcp/templates/tool-server.ts:14)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/typescript-mcp/templates/full-server.ts:14)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-agents/templates/mcp-server-basic.ts:3)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/mcp-oauth-cloudflare/templates/index.ts:14)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:7)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts:27)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-mcp-server/templates/mcp-oauth-proxy.ts:42)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:15)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:41)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-mcp-server/templates/mcp-with-d1.ts:60)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts:9)
- **[medium] Missing rate limiting on MCP endpoint** — An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks. (skills/fastmcp/templates/client-example.py:153)
- **[critical] Unvalidated outbound HTTP in MCP tool handler** — An MCP tool handler fetches a URL provided by the caller with no host/scheme validation. This is the classic SSRF shape (CWE-918). (skills/typescript-mcp/templates/basic-mcp-server.ts:102)
- **[high] Localhost/loopback reachable from MCP tool** — An MCP tool handler forwards user-supplied URLs that could target 127.0.0.1/localhost/::1, reaching internal services bound to loopback. (skills/typescript-mcp/templates/basic-mcp-server.ts:14)
- **[high] Missing SSRF allowlist on outbound fetch** — An MCP tool performs outbound HTTP but has no allowlist of permitted destinations. Deny-by-default with an explicit allowlist is the only reliable defense against SSRF chains. (skills/typescript-mcp/templates/basic-mcp-server.ts:None)
- **[high] Localhost/loopback reachable from MCP tool** — An MCP tool handler forwards user-supplied URLs that could target 127.0.0.1/localhost/::1, reaching internal services bound to loopback. (skills/cloudflare-mcp-server/templates/mcp-oauth-proxy.ts:32)
- **[high] Localhost/loopback reachable from MCP tool** — An MCP tool handler forwards user-supplied URLs that could target 127.0.0.1/localhost/::1, reaching internal services bound to loopback. (skills/cloudflare-mcp-server/templates/basic-mcp-server.ts:28)
- **[critical] Unvalidated outbound HTTP in MCP tool handler** — An MCP tool handler fetches a URL provided by the caller with no host/scheme validation. This is the classic SSRF shape (CWE-918). (skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:194)
- **[high] Missing SSRF allowlist on outbound fetch** — An MCP tool performs outbound HTTP but has no allowlist of permitted destinations. Deny-by-default with an explicit allowlist is the only reliable defense against SSRF chains. (skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts:None)
- **[critical] Unvalidated outbound HTTP in MCP tool handler** — An MCP tool handler fetches a URL provided by the caller with no host/scheme validation. This is the classic SSRF shape (CWE-918). (skills/fastmcp/templates/error-handling.py:189)
- **[high] Missing SSRF allowlist on outbound fetch** — An MCP tool performs outbound HTTP but has no allowlist of permitted destinations. Deny-by-default with an explicit allowlist is the only reliable defense against SSRF chains. (skills/fastmcp/templates/error-handling.py:None)
- **[medium] Bearer token used where DPoP or mTLS is required** — An MCP remote server accepts plain Bearer tokens on a flow that MCP spec 2025-11-25 flags for DPoP (Demonstrating Proof of Possession) or mTLS-bound tokens. A stolen Bearer token is fully replayable. (skills/azure-auth/templates/workers-jwt-validation.ts:None)
- **[medium] Bearer token used where DPoP or mTLS is required** — An MCP remote server accepts plain Bearer tokens on a flow that MCP spec 2025-11-25 flags for DPoP (Demonstrating Proof of Possession) or mTLS-bound tokens. A stolen Bearer token is fully replayable. (skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:None)
- **[medium] MCP task has no TTL or cancellation path** — A task record has no expiration and no cancellation endpoint. Orphaned tasks accumulate forever, including their inputs. (skills/cloudflare-agents/templates/scheduled-agent.ts:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (CHANGELOG.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/RESEARCH_FINDINGS_openai-apps-mcp.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/RESEARCH_FINDINGS_google-gemini-file-search.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/RESEARCH_FINDINGS_ai-sdk-ui.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/RESEARCH_FINDINGS_cloudflare-vectorize.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/RESEARCH_FINDINGS_google-gemini-embeddings.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/SKILL_REVIEW_PROCESS.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (.claude/agents/cloudflare-debug.md:None)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (planning/research-logs/session-handoff-protocol.md:347)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/research-logs/cloudflare-zero-trust-access.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (planning/research-logs/cloudflare-full-stack-integration.md:None)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (planning/research-logs/openai-api.md:342)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-worker-base/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/google-gemini-file-search/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/README.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-r2/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/snowflake-platform/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/fastapi/README.md:None)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/openai-api/SKILL.md:716)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/openai-api/NEXT-SESSION.md:111)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/README.md:75)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/SKILL.md:88)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/favicon-gen/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/flask/README.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/sub-agent-patterns/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/google-gemini-embeddings/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/tailwind-v4-shadcn/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/motion/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/ai-sdk-ui/references/top-ui-errors.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-worker-base/agents/cloudflare-debug.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/tanstack-router/references/common-errors.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/openai-responses/references/top-errors.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/google-gemini-api/references/code-execution-patterns.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/google-gemini-api/references/grounding-guide.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/developer-toolbox/agents/build-verifier.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/developer-toolbox/agents/debugger.md:None)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/developer-toolbox/agents/debugger.md:299)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-hyperdrive/references/query-caching.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/references/cost-optimization.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/references/workflow-examples.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/references/compliance-guide.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/references/system-prompt-guide.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/assets/agent-config-schema.json:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/elevenlabs-agents/assets/system-prompt-template.md:None)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/django-cloud-sql-postgres/references/migrations-in-production.md:166)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/open-source-contributions/references/pr-checklist.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/open-source-contributions/assets/bad-pr-example.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/snowflake-platform/rules/snowflake-jwt-auth.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/snowflake-platform/rules/snowflake-marketplace-listing.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/color-palette/references/dark-mode-palette.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/color-palette/references/contrast-checking.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/openai-api/references/top-errors.md:None)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/references/title-patterns.md:26)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/references/twitter-cards.md:71)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/references/meta-description.md:31)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/references/open-graph.md:26)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/references/json-ld.md:186)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/seo-meta/rules/seo-meta.md:10)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/tanstack-query/references/top-errors.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/favicon-gen/references/shape-templates.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/favicon-gen/references/monogram-patterns.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/claude-api/references/top-errors.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/clerk-auth/rules/clerk-auth.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-mcp-server/references/debugging-guide.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-mcp-server/references/common-issues.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/google-gemini-embeddings/references/dimension-guide.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/tailwind-v4-shadcn/references/common-gotchas.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-workers-ai/rules/cloudflare-workers-ai-prefixes.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/tanstack-table/references/common-errors.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/cloudflare-vectorize/references/embedding-models.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (skills/icon-design/references/semantic-mapping.md:None)
- **[high] Crisis keywords handled without escalation path** — A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure. (skills/icon-design/references/semantic-mapping.md:100)
- **[high] Session token written to log sink in cleartext** — An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern — session tokens ended up in the Splunk '_internal' index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius. (skills/google-gemini-file-search/scripts/create-store.ts:23)
- **[high] Session token written to log sink in cleartext** — An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern — session tokens ended up in the Splunk '_internal' index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius. (skills/clerk-auth/scripts/generate-session-token.js:212)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (planning/RESEARCH_FINDINGS_drizzle-orm-d1.md:253)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (.claude/agents/d1-migration.md:157)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/cloudflare-d1/SKILL.md:82)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/drizzle-orm-d1/SKILL.md:465)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/better-auth/SKILL.md:1678)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/cloudflare-worker-base/agents/d1-migration.md:157)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/cloudflare-d1/references/query-patterns.md:349)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/cloudflare-d1/references/best-practices.md:34)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/cloudflare-hyperdrive/references/query-caching.md:78)
- **[high] Indirect-prompt-injection wild payload checked into repo** — A source / config file ('.md', '.txt', '.yml', '.yaml', '.json', '.py') embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with 'aak corpus update --ipi'. (skills/tanstack-table/references/server-side-patterns.md:329)

### bearer (v2.0.2) — Unsafe / 0.0

- **[critical] Unsanitized dynamic input in OS command** — \#\# Description  Incorporating unsanitized dynamic input directly into operating system commands poses a significant security risk. This practice could give attackers the opportunity to execute harmful commands on your system.  \#\# Remediations  - **Do** use static, hardcoded values in command strings - wherever possible - to avoid relying on dynamic data.   '''javascript   let filePattern = "*.js";   cp.exec('cp ${filePattern} destinationFolder', (error, stdout, stderr) => {});   ''' - **Do** san (/repo/skills/ts-agent-sdk/templates/db/client.ts:175)
- **[critical] Usage of hard-coded secret** — \#\# Description  Storing secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.  \#\# Remediations  - **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.   '''javascript     passport.use(new OAuth2Strategy({         authorizationURL: 'https://www.example.com/oauth2/authorize',         tokenURL: 'https://www.example.com/oauth2/token',         clientID: 'my-i (/repo/skills/auto-animate/templates/form-validation.tsx:43)
- **[critical] Usage of hard-coded secret** — \#\# Description  Storing secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.  \#\# Remediations  - **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.   '''javascript     passport.use(new OAuth2Strategy({         authorizationURL: 'https://www.example.com/oauth2/authorize',         tokenURL: 'https://www.example.com/oauth2/token',         clientID: 'my-i (/repo/skills/auto-animate/templates/form-validation.tsx:45)
- **[critical] Usage of hard-coded secret** — \#\# Description  Storing secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.  \#\# Remediations  - **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.   '''javascript     passport.use(new OAuth2Strategy({         authorizationURL: 'https://www.example.com/oauth2/authorize',         tokenURL: 'https://www.example.com/oauth2/token',         clientID: 'my-i (/repo/skills/auto-animate/templates/form-validation.tsx:49)
- **[critical] Usage of hard-coded secret** — \#\# Description  Storing secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.  \#\# Remediations  - **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.   '''javascript     passport.use(new OAuth2Strategy({         authorizationURL: 'https://www.example.com/oauth2/authorize',         tokenURL: 'https://www.example.com/oauth2/token',         clientID: 'my-i (/repo/skills/clerk-auth/scripts/generate-session-token.js:96)
- **[critical] Usage of hard-coded secret** — \#\# Description  Storing secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.  \#\# Remediations  - **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.   '''javascript     passport.use(new OAuth2Strategy({         authorizationURL: 'https://www.example.com/oauth2/authorize',         tokenURL: 'https://www.example.com/oauth2/token',         clientID: 'my-i (/repo/skills/clerk-auth/scripts/generate-session-token.js:101)
- **[critical] Usage of hard-coded secret** — \#\# Description  Storing secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.  \#\# Remediations  - **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.   '''javascript     passport.use(new OAuth2Strategy({         authorizationURL: 'https://www.example.com/oauth2/authorize',         tokenURL: 'https://www.example.com/oauth2/token',         clientID: 'my-i (/repo/skills/firebase-auth/templates/auth-context.tsx:50)
- **[critical] Usage of hard-coded secret** — \#\# Description  Storing secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.  \#\# Remediations  - **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.   '''javascript     passport.use(new OAuth2Strategy({         authorizationURL: 'https://www.example.com/oauth2/authorize',         tokenURL: 'https://www.example.com/oauth2/token',         clientID: 'my-i (/repo/skills/firebase-auth/templates/auth-context.tsx:52)
- **[critical] Unsanitized user input in OS command** — \#\# Description  Directly incorporating external or user-defined input into an OS command exposes the system to possible command injection attacks. This vulnerability allows attackers to execute unauthorized commands on the operating system, potentially leading to a compromise of system integrity.  \#\# Remediations  - **Do not** use OS commands that include dynamic input directly. Instead, explore safer alternatives such as libraries or built-in functions that achieve the same goal without executi (/repo/scripts/deep-audit-bulk.py:137)
- **[critical] Unsanitized user input in OS command** — \#\# Description  Directly incorporating external or user-defined input into an OS command exposes the system to possible command injection attacks. This vulnerability allows attackers to execute unauthorized commands on the operating system, potentially leading to a compromise of system integrity.  \#\# Remediations  - **Do not** use OS commands that include dynamic input directly. Instead, explore safer alternatives such as libraries or built-in functions that achieve the same goal without executi (/repo/scripts/deep-audit-bulk.py:176)
- **[high] Unsanitized user input in dynamic HTML insertion (XSS)** — \#\# Description  Unsanitized user input in dynamic HTML insertion can lead to Cross-Site Scripting (XSS) attacks. This vulnerability arises when user-provided data is directly inserted into the DOM without proper sanitization, potentially allowing attackers to execute malicious scripts.  \#\# Remediations  - **Do** use an HTML sanitization library to clean user input before inserting it into the HTML. This step helps prevent XSS attacks by removing or neutralizing any potentially harmful scripts.   (/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js:93)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:46)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:64)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:83)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:119)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:148)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:183)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:210)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:237)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:265)
- **[high] Unsanitized user input in HTTP request (SSRF)** — \#\# Description  Constructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.  \#\# Remediations  - **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.   '''javascript   const response = axios.get('https://${req.params.host}') // unsafe   ''' - **Do** validate or map user input against (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:273)
- **[high] Usage of manual HTML sanitization (XSS)** — \#\# Description  Manually sanitizing HTML is prone to mistakes and can lead to Cross-Site Scripting (XSS) vulnerabilities. This occurs when user input is not properly sanitized, allowing attackers to inject malicious scripts into web pages viewed by other users.  \#\# Remediations  - **Do not** manually escape HTML to sanitize user input. This method is unreliable and can easily miss certain exploits.   '''javascript   const sanitizedUserInput = user.Input     .replaceAll('<', '&lt;')     .replaceA (/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts:71)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/nodejs-example.ts:107)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/nodejs-example.ts:143)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/nodejs-example.ts:149)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/nodejs-example.ts:325)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/nodejs-example.ts:329)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/nodejs-example.ts:330)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/nodejs-example.ts:354)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:12)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:60)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:61)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:119)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:160)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:215)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:314)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/claude-api/templates/vision-image.ts:318)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/mcp-cli-scripts/templates/script-template.ts:144)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:68)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:72)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:90)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:95)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:106)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:138)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:174)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/audio-transcription.ts:178)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/image-generation.ts:172)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/text-to-speech.ts:68)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-api/templates/text-to-speech.ts:172)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:106)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-assistants/templates/vector-store-setup.ts:101)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-assistants/templates/vector-store-setup.ts:110)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Allowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.  \#\# Remediations  - **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access. - **Do** use a combination of hard-coded s (/repo/skills/openai-assistants/templates/vector-store-setup.ts:118)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Using unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.  \#\# Remediations  - **Do not** directly use user input to construct file paths. This can lead to unauthorized file access. - **Do** sanitize user input used in file paths. Replace patterns that can nav (/repo/skills/playwright-local/templates/screenshot-capture.ts:26)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Using unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.  \#\# Remediations  - **Do not** directly use user input to construct file paths. This can lead to unauthorized file access. - **Do** sanitize user input used in file paths. Replace patterns that can nav (/repo/skills/playwright-local/templates/screenshot-capture.ts:41)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Using unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.  \#\# Remediations  - **Do not** directly use user input to construct file paths. This can lead to unauthorized file access. - **Do** sanitize user input used in file paths. Replace patterns that can nav (/repo/skills/playwright-local/templates/screenshot-capture.ts:51)
- **[high] Unsanitized dynamic input in file path** — \#\# Description  Using unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.  \#\# Remediations  - **Do not** directly use user input to construct file paths. This can lead to unauthorized file access. - **Do** sanitize user input used in file paths. Replace patterns that can nav (/repo/skills/playwright-local/templates/screenshot-capture.ts:58)
- **[high] Unsanitized user input in raw HTML strings (XSS)** — \#\# Description  Including unsanitized user input in HTML exposes your application to cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.  \#\# Remediations  - **Do not** include user input directly in HTML strings. This practice can lead to XSS vulnerabilities.   '''javascript   const html = '<h1>${req.params.title}</h1>' // unsafe   ''' - **Do** use a framework or templating language that automatically handles t (/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts:325)
- **[high] Unsanitized user input in raw HTML strings (XSS)** — \#\# Description  Including unsanitized user input in HTML exposes your application to cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.  \#\# Remediations  - **Do not** include user input directly in HTML strings. This practice can lead to XSS vulnerabilities.   '''javascript   const html = '<h1>${req.params.title}</h1>' // unsafe   ''' - **Do** use a framework or templating language that automatically handles t (/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts:651)
- **[high] Unsanitized user input in React inner HTML method (XSS)** — \#\# Description  Using React's dangerouslySetInnerHTML with unsanitized data can introduce Cross-Site Scripting (XSS) vulnerabilities. This occurs when external input is embedded directly into the HTML without proper sanitization, allowing attackers to inject malicious scripts.  \#\# Remediations  - **Do** sanitize data before using it with dangerouslySetInnerHTML. This step is crucial to prevent XSS attacks by ensuring that the input does not contain harmful scripts. '''javascript <div dangerously (/repo/skills/ai-sdk-ui/templates/custom-message-renderer.tsx:266)
- **[high] Unsanitized user input in React inner HTML method (XSS)** — \#\# Description  Using React's dangerouslySetInnerHTML with unsanitized data can introduce Cross-Site Scripting (XSS) vulnerabilities. This occurs when external input is embedded directly into the HTML without proper sanitization, allowing attackers to inject malicious scripts.  \#\# Remediations  - **Do** sanitize data before using it with dangerouslySetInnerHTML. This step is crucial to prevent XSS attacks by ensuring that the input does not contain harmful scripts. '''javascript <div dangerously (/repo/skills/nextjs/templates/app-router-async-params.tsx:40)
- **[high] Unsanitized user input in React inner HTML method (XSS)** — \#\# Description  Using React's dangerouslySetInnerHTML with unsanitized data can introduce Cross-Site Scripting (XSS) vulnerabilities. This occurs when external input is embedded directly into the HTML without proper sanitization, allowing attackers to inject malicious scripts.  \#\# Remediations  - **Do** sanitize data before using it with dangerouslySetInnerHTML. This step is crucial to prevent XSS attacks by ensuring that the input does not contain harmful scripts. '''javascript <div dangerously (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:94)
- **[medium] Missing Helmet configuration on HTTP headers** — \#\# Description  Helmet can help protect your app from some well-known web vulnerabilities by setting HTTP headers appropriately. Failing to configure Helmet for HTTP headers leaves your application vulnerable to several web attacks.  \#\# Remediations  - **Do** use Helmet middleware to secure your app by adding it to your application's middleware.   '''javascript   const helmet = require("helmet");   app.use(helmet());   '''  \#\# References  - [Express Security Best Practices: Use Helmet](https://e (/repo/skills/react-hook-form-zod/templates/server-validation.ts:122)
- **[medium] Missing server configuration to reduce server fingerprinting** — \#\# Description  Reducing server fingerprinting enhances security by making it harder for attackers to identify the software your server is running. Server fingerprinting involves analyzing the unique responses of server software to specific requests, which can reveal information about the server's software and version. While not a direct security vulnerability, minimizing this information leakage is a proactive step to obscure details that could be used in targeted attacks.  \#\# Remediations  - * (/repo/skills/react-hook-form-zod/templates/server-validation.ts:122)
- **[medium] Leakage of sensitive data in exception message** — \#\# Description  Leakage of sensitive data in exception messages can lead to data breaches. This vulnerability occurs when sensitive information is included in exceptions, making it accessible to unauthorized users.  \#\# Remediations  - **Do not** include sensitive data in exception messages. This can inadvertently expose personal or confidential information.   '''javascript   throw new CustomError('Error with ${user.email}') // unsafe   ''' - **Do** use non-sensitive, unique identifiers in except (/repo/skills/drizzle-orm-d1/templates/transactions.ts:150)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/better-auth/references/cloudflare-worker-drizzle.ts:90)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/better-auth/references/cloudflare-worker-kysely.ts:82)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/better-auth/references/nextjs/postgres-example.ts:105)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:162)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/cloudflare-workflows/templates/basic-workflow.ts:58)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/hono-routing/templates/context-extension.ts:359)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:215)
- **[medium] Leakage of sensitive information in logger message** — \#\# Description  Sensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.  \#\# Remediations  - **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.   '''javascript   logger.info('User is: ${user.email}') // unsafe   ''' - **Do (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:87)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/core/performance/CRC32Performance.ts:75)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/core/performance/CRC32Performance.ts:102)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:175)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:61)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/skills/hono-routing/templates/context-extension.ts:221)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/skills/hono-routing/templates/error-handling.ts:87)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/skills/hono-routing/templates/middleware-composition.ts:133)
- **[medium] Observable Timing Discrepancy** — \#\# Description  Observable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.  \#\# Remediations  - **Do** implement algorithms that process sensitive  (/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts:237)
- **[medium] Usage of Django debug mode** — \#\# Description    When debug mode is enabled, Django displays detailed error pages with stack traces and other sensitive information when an error occurs. While this can be useful during development, debug mode should never be enabled in production or other such environments because it can lead to the exposure of sensitive data to unauthorized users.    \#\# Remediations  - **Do not** set DEBUG to True in production or other such environments '''python DEBUG = True \# not safe for production ''' -  (/repo/skills/flask/templates/config.py:20)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/core/pipeline/DataFlowPipeline.ts:221)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/auto-animate/templates/react-basic.tsx:44)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/claude-api/templates/tool-use-advanced.ts:242)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:205)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/cloudflare-worker-base/templates/public/script.js:48)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/google-gemini-embeddings/templates/clustering.ts:69)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/motion/templates/layout-transitions.tsx:159)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/motion/templates/layout-transitions.tsx:464)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/motion/templates/layout-transitions.tsx:469)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/nextjs/templates/proxy-migration.ts:108)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts:32)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts:63)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/openai-agents/templates/text-agents/agent-basic.ts:23)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts:61)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/playwright-local/templates/stealth-mode.ts:36)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/playwright-local/templates/stealth-mode.ts:41)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/playwright-local/templates/stealth-mode.ts:42)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/playwright-local/templates/stealth-mode.ts:73)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/tanstack-table/templates/virtualized-large-dataset.tsx:24)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/tanstack-table/templates/virtualized-large-dataset.tsx:25)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/typescript-mcp/templates/tasks-server.ts:266)
- **[low] Usage of insufficient random value** — \#\# Description  Using predictable random values compromises your application's security, particularly if these values serve security-related functions.  \#\# Remediations  - **Do** use a robust library for generating random values to enhance security.   '''javascript   const crypto = require('crypto');   crypto.randomBytes(16).toString('hex');   ''' (/repo/skills/vercel-kv/templates/simple-rate-limiting.ts:82)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:16)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:17)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:18)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:19)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:20)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:91)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:131)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:135)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:139)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:142)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:149)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:165)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/BUN_V136_INTEGRATION_DEMO.ts:169)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:17)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:19)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:169)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:187)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:190)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:192)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:213)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:214)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:227)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:228)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:229)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:249)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:250)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts:279)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:42)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:93)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:97)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:121)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:138)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:158)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:159)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:175)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:199)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:200)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:201)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/cli/omega-profile.ts:202)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/performance/CRC32Performance.ts:175)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/performance/CRC32Performance.ts:193)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/performance/CRC32Performance.ts:194)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/performance/CRC32Performance.ts:195)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/performance/CRC32Performance.ts:196)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/performance/CRC32Performance.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/pipeline/DataFlowPipeline.ts:295)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3Client.ts:271)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3Client.ts:290)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3Client.ts:302)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3Client.ts:303)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3Client.ts:307)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:328)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:411)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:418)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:440)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:444)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:448)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:473)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:475)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/s3/OMEGAS3RequesterPays.ts:511)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:24)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:25)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:51)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.demo.ts:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelper.ts:232)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelperWithDefaults.ts:256)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelperWithDefaults.ts:350)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelperWithDefaults.ts:363)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sql/SQLHelperWithDefaults.ts:376)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sqlite/OMEGADatabase.ts:414)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sqlite/OMEGADatabase.ts:422)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sqlite/OMEGADatabase.ts:425)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/sqlite/OMEGADatabase.ts:429)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/websocket/OMEGAWebSocketProxy.ts:242)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/websocket/OMEGAWebSocketProxy.ts:244)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/websocket/OMEGAWebSocketProxy.ts:275)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/websocket/OMEGAWebSocketProxy.ts:284)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/core/websocket/OMEGAWebSocketProxy.ts:292)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/agent-with-tools.ts:19)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/agent-with-tools.ts:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/agent-with-tools.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/agent-with-tools.ts:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/agent-with-tools.ts:82)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/anthropic-setup.ts:42)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/anthropic-setup.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/anthropic-setup.ts:45)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/anthropic-setup.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/anthropic-setup.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/generate-object-zod.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/generate-object-zod.ts:32)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/generate-object-zod.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/generate-object-zod.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/generate-text-basic.ts:15)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/generate-text-basic.ts:16)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/generate-text-basic.ts:17)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/google-setup.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/google-setup.ts:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/google-setup.ts:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/google-setup.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/google-setup.ts:58)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/google-setup.ts:68)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/google-setup.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:18)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:36)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:88)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:102)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/multi-step-execution.ts:103)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/nextjs-server-action.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/openai-setup.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/openai-setup.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/openai-setup.ts:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/openai-setup.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/openai-setup.ts:58)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/openai-setup.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/stream-object-zod.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/stream-object-zod.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/stream-object-zod.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/stream-text-chat.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/stream-text-chat.ts:36)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/tools-basic.ts:20)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/tools-basic.ts:42)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/tools-basic.ts:62)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/tools-basic.ts:65)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/tools-basic.ts:68)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/tools-basic.ts:69)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-core/templates/tools-basic.ts:70)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-ui/templates/message-persistence.tsx:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-ui/templates/message-persistence.tsx:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-ui/templates/message-persistence.tsx:57)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/ai-sdk-ui/templates/nextjs-chat-app-router.tsx:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/msal-config.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/msal-config.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/msal-config.ts:55)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/msal-provider.tsx:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/msal-provider.tsx:100)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/protected-route.tsx:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/protected-route.tsx:136)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/protected-route.tsx:191)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/workers-jwt-validation.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/workers-jwt-validation.ts:154)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/azure-auth/templates/workers-jwt-validation.ts:195)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/better-auth/references/cloudflare-worker-drizzle.ts:91)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/better-auth/references/cloudflare-worker-kysely.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/better-auth/references/nextjs/postgres-example.ts:134)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/better-auth/references/nextjs/postgres-example.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/basic-query.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/basic-query.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/basic-query.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/basic-query.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/basic-query.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/basic-query.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts:155)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:31)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:81)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:105)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:127)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:149)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:178)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:208)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:257)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:273)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/error-handling.ts:278)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:55)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:128)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts:169)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:31)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:220)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:258)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:263)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:267)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:272)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:276)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:282)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:283)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:285)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts:313)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/permission-control.ts:26)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/permission-control.ts:45)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/permission-control.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/permission-control.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/permission-control.ts:177)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/permission-control.ts:199)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/permission-control.ts:206)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/query-with-tools.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/query-with-tools.ts:42)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/query-with-tools.ts:43)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/query-with-tools.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/query-with-tools.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:54)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:70)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/session-management.ts:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/subagents-orchestration.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/subagents-orchestration.ts:96)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-agent-sdk/templates/subagents-orchestration.ts:160)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:24)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:59)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/basic-chat.ts:96)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/cloudflare-worker.ts:199)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/cloudflare-worker.ts:215)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/cloudflare-worker.ts:262)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:19)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:20)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:21)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:116)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:175)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:178)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:179)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:186)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:201)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:281)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:303)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:336)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/error-handling.ts:337)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:36)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:45)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:99)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:103)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:125)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:139)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:188)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:191)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:192)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:196)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:227)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:231)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:280)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:281)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/extended-thinking.ts:292)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:32)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:88)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:169)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:236)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nextjs-api-route.ts:275)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:43)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:93)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:110)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:135)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:144)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:176)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:177)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:203)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:230)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/nodejs-example.ts:283)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:51)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:113)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:183)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:184)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:224)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:249)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:250)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:251)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/prompt-caching.ts:252)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:31)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:117)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:155)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/streaming-chat.ts:165)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:19)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:115)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:126)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:144)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:167)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:191)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:195)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:221)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:225)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:230)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:263)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-advanced.ts:265)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:71)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:102)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:117)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:118)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:134)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:177)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:184)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:282)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/tool-use-basic.ts:286)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:97)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:151)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:191)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:209)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:243)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:247)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:276)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:308)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:340)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:344)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:352)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/claude-api/templates/vision-image.ts:379)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:112)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:126)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:133)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:150)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:189)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:207)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:212)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:223)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:225)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:231)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/scripts/generate-session-token.js:235)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/templates/cloudflare/worker-auth.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/templates/cloudflare/worker-auth.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/clerk-auth/templates/cloudflare/worker-auth.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/basic-agent.ts:26)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/basic-agent.ts:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/basic-agent.ts:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/basic-agent.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/chat-agent-streaming.ts:104)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/chat-agent-streaming.ts:105)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/chat-agent-streaming.ts:115)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/hitl-agent.ts:168)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/hitl-agent.ts:232)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/mcp-server-basic.ts:148)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx:125)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx:130)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx:227)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/scheduled-agent.ts:113)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/scheduled-agent.ts:127)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/scheduled-agent.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/state-sync-agent.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/state-sync-agent.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/state-sync-agent.ts:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/websocket-agent.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/websocket-agent.ts:113)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/websocket-agent.ts:120)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/websocket-agent.ts:131)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/websocket-agent.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/websocket-agent.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/workflow-agent.ts:97)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/workflow-agent.ts:102)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/workflow-agent.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-agents/templates/workflow-agent.ts:120)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts:24)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts:56)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:139)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:163)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:183)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:274)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:296)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:322)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:342)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:373)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:417)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:452)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:489)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:527)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts:582)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:51)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:53)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:98)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:175)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:200)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts:223)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:56)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:98)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:116)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:174)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:184)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:188)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:136)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts:169)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-hyperdrive/templates/drizzle-mysql.ts:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-hyperdrive/templates/drizzle-postgres.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-hyperdrive/templates/postgres-basic.ts:53)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-hyperdrive/templates/postgres-js.ts:97)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-hyperdrive/templates/postgres-pool.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-hyperdrive/templates/prisma-postgres.ts:137)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:286)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-images/templates/transform-via-workers.ts:293)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-images/templates/upload-api-basic.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-images/templates/upload-via-url.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-kv/templates/kv-caching-pattern.ts:284)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:206)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:32)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:65)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:112)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:126)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:41)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:43)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:99)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:127)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:155)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:32)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:41)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:53)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:54)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:55)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:56)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:99)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:168)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:186)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:214)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:112)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:129)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:151)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts:163)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts:133)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts:165)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts:88)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts:159)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts:219)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts:139)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts:174)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts:209)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:57)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:63)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:112)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:211)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx:124)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx:272)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx:335)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:121)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:159)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:173)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:182)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:214)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:217)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:243)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:244)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:255)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts:256)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/basic-search.ts:88)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/basic-search.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/basic-search.ts:176)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:199)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:211)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:274)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts:328)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts:206)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts:315)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/rag-chat.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/rag-chat.ts:204)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-vectorize/templates/rag-chat.ts:265)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-worker-base/templates/public/script.js:20)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-workers-ai/templates/ai-gateway-integration.ts:339)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-workers-ai/templates/ai-text-generation.ts:288)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-workflows/templates/basic-workflow.ts:42)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts:171)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts:201)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts:190)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts:315)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts:324)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/transactions.ts:25)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/transactions.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/drizzle-orm-d1/templates/transactions.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:65)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:100)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:133)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:155)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/electron-base/templates/main.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/electron-base/templates/main.ts:149)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js:31)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js:61)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js:65)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js:72)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js:130)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js:139)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx:26)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx:85)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx:96)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:71)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:99)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:127)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:211)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/email-gateway/templates/mailgun-webhooks.ts:251)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/email-gateway/templates/smtp2go-bulk.ts:245)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firebase-auth/templates/api-session.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firebase-auth/templates/api-session.ts:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firebase-auth/templates/api-session.ts:117)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:65)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:86)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:88)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:92)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:223)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:232)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:256)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:266)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:301)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-chat-api/templates/bearer-token-verify.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-chat-api/templates/bearer-token-verify.ts:118)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:86)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:115)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:183)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:186)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/code-execution.ts:204)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:69)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:103)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:111)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:130)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:136)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:137)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:156)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:176)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:239)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:242)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:246)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:253)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/combined-advanced.ts:276)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:51)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:60)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:110)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:131)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:138)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/context-caching.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:71)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:72)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:82)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:110)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-basic.ts:113)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-parallel.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-parallel.ts:86)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-parallel.ts:125)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/function-calling-parallel.ts:128)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:45)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:97)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:102)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:104)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:105)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:112)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:116)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:118)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:162)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:168)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:187)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:188)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:202)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:203)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:209)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:227)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:235)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:236)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:238)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:245)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:246)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/grounding-search.ts:264)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-image.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-image.ts:72)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-image.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-image.ts:93)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:102)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:120)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/streaming-chat.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/streaming-chat.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:100)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/text-generation-basic.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/text-generation-basic.ts:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/text-generation-basic.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/text-generation-basic.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/text-generation-basic.ts:43)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/text-generation-basic.ts:56)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:120)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/thinking-mode.ts:36)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/thinking-mode.ts:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/thinking-mode.ts:63)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/thinking-mode.ts:64)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/thinking-mode.ts:93)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/thinking-mode.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-api/templates/thinking-mode.ts:97)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts:42)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts:43)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts:87)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:53)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:124)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:145)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:150)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:226)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:230)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:231)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:232)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts:235)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:127)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:188)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:192)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:193)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:200)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:203)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:234)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:248)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:251)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:286)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:287)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:288)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:289)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:290)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:291)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/clustering.ts:295)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts:115)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:199)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:206)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:232)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:255)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:280)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:319)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:117)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:128)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:236)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:237)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:249)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:250)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:261)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:262)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:276)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:277)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-embeddings/templates/semantic-search.ts:284)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:72)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:81)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/google-gemini-file-search/scripts/create-store.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:92)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:103)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:172)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:177)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:182)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:187)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:196)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:235)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:279)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:344)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:367)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/context-extension.ts:407)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/error-handling.ts:134)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/error-handling.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/error-handling.ts:232)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/error-handling.ts:384)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/middleware-composition.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/middleware-composition.ts:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/middleware-composition.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/middleware-composition.ts:255)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/middleware-composition.ts:256)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/middleware-composition.ts:257)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/middleware-composition.ts:284)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:56)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:115)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:120)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:125)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:127)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:163)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:177)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:188)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:210)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/rpc-client.ts:233)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/validation-valibot.ts:192)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/hono-routing/templates/validation-zod.ts:240)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-cli-scripts/templates/script-template.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-cli-scripts/templates/script-template.ts:149)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-cli-scripts/templates/script-template.ts:154)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-oauth-cloudflare/templates/index.ts:41)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-oauth-cloudflare/templates/oauth/google-handler.ts:111)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:103)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:148)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:42)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:54)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:55)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:58)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:85)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/scripts/test-connection.ts:91)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/neon-vercel-postgres/templates/drizzle-queries.ts:363)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/nextjs/templates/route-handler-api.ts:208)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/nextjs/templates/route-handler-api.ts:215)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/nextjs/templates/route-handler-api.ts:220)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/nextjs/templates/route-handler-api.ts:323)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/office/templates/docx-basic.ts:264)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/office/templates/pdf-basic.ts:281)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/office/templates/xlsx-basic.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/nextjs/api-agent-route.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/nextjs/api-realtime-route.ts:69)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts:132)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts:137)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts:150)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts:166)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts:170)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts:174)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts:178)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts:179)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts:183)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:145)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx:165)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:57)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:62)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:68)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:81)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:86)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:87)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:96)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:103)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:129)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:134)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:135)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/error-handling.ts:138)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:51)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:81)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:82)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:84)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/shared/tracing-setup.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-basic.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-basic.ts:45)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-basic.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-basic.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:138)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:139)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:151)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:154)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:187)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:196)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts:201)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:144)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:145)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:158)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:184)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:185)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:187)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:192)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:198)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:200)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts:213)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts:109)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts:115)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts:116)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:86)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:88)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:91)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:112)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:122)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:169)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts:194)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:63)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:64)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:65)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:69)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:70)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:71)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:77)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:81)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:82)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:125)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:139)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:144)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:148)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:158)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:163)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:166)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:167)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:173)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:215)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts:245)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:59)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:85)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:91)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:92)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:142)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:163)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:166)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts:171)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:86)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:88)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:102)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:103)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:104)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:105)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:118)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:122)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:124)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:127)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts:136)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:53)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:69)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:76)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:98)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:134)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:148)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:156)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:163)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:180)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/audio-transcription.ts:181)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/chat-completion-basic.ts:21)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/chat-completion-nodejs.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/chat-completion-nodejs.ts:54)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/chat-completion-nodejs.ts:58)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/chat-completion-nodejs.ts:59)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/chat-completion-nodejs.ts:60)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/chat-completion-nodejs.ts:68)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:55)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:84)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:172)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:192)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:209)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/embeddings.ts:213)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/function-calling.ts:98)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/function-calling.ts:113)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/function-calling.ts:118)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/function-calling.ts:121)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/function-calling.ts:128)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:68)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:96)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:134)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:150)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:179)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:199)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:219)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-editing.ts:291)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:55)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:65)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:85)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:132)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:150)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:151)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:173)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:203)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:213)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:222)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:247)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/image-generation.ts:287)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:63)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:64)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:109)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:110)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:117)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:142)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:149)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:218)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:246)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:289)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:343)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/moderation.ts:380)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/rate-limit-handling.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/rate-limit-handling.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:167)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:222)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:241)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:285)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:337)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/structured-output.ts:384)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:59)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:162)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:190)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:203)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:233)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:234)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:266)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/text-to-speech.ts:307)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:43)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:109)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:148)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:174)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:200)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:229)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:282)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:313)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:327)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:340)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:364)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-api/templates/vision-gpt4o.ts:396)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:56)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:62)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/basic-assistant.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:61)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:75)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:93)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:100)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:120)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:122)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts:133)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:80)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:121)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:160)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:195)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:202)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:203)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/file-search-assistant.ts:210)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:98)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:108)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:122)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:129)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:141)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:149)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:152)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:160)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:184)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:218)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/function-calling-assistant.ts:242)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/streaming-assistant.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/streaming-assistant.ts:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/streaming-assistant.ts:99)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/streaming-assistant.ts:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/streaming-assistant.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/streaming-assistant.ts:131)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:24)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:41)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:73)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:100)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:151)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:165)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:168)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:172)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:188)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:197)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:202)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:207)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:213)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:214)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/thread-management.ts:222)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:37)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:102)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:115)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:131)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:132)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:151)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:158)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:161)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:167)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:178)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:179)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:180)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:189)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:190)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:191)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:199)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:200)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:201)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:220)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:223)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:229)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:230)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:232)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:233)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-assistants/templates/vector-store-setup.ts:238)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:25)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:26)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:41)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:56)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:64)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:70)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:71)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:92)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:96)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:109)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:112)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:144)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:145)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:146)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:154)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:155)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:156)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:168)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:176)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:182)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:189)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:207)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:211)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:214)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:230)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:237)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/background-mode.ts:239)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/basic-response.ts:22)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/basic-response.ts:26)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/basic-response.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/basic-response.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/basic-response.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/basic-response.ts:58)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:23)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:60)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:84)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:118)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:135)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:140)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:143)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:144)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:165)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:189)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:191)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:208)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/code-interpreter.ts:215)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:24)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:43)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:87)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:110)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:120)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:138)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:145)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:170)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:172)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:173)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:216)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:237)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:249)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:251)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:252)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:253)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:254)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/file-search.ts:262)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:22)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:58)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:71)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:81)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:83)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:101)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:113)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:129)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:157)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:167)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:177)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:190)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:194)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:198)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:208)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:213)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/image-generation.ts:230)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:30)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:40)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:62)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:128)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:149)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:153)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:156)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/mcp-integration.ts:159)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:25)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:46)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:55)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:93)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:104)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:105)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:107)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/stateful-conversation.ts:114)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:23)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:28)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:29)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:32)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:34)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:50)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:62)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:69)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:84)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:101)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:111)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:123)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:135)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:162)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/openai-responses/templates/web-search.ts:185)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/authenticated-session.ts:95)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/authenticated-session.ts:98)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/basic-scrape.ts:44)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/basic-scrape.ts:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/infinite-scroll.ts:35)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/infinite-scroll.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/infinite-scroll.ts:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/infinite-scroll.ts:90)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/infinite-scroll.ts:94)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/pdf-generation.ts:19)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/pdf-generation.ts:22)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/pdf-generation.ts:49)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/pdf-generation.ts:61)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/pdf-generation.ts:67)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/pdf-generation.ts:91)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/pdf-generation.ts:93)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/screenshot-capture.ts:69)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/stealth-mode.ts:82)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/playwright-local/templates/stealth-mode.ts:85)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/advanced-form.tsx:122)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:57)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:210)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:254)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/async-validation.tsx:273)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/basic-form.tsx:52)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/basic-form.tsx:66)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/basic-form.tsx:71)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/basic-form.tsx:195)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/custom-error-display.tsx:138)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/custom-error-display.tsx:274)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/dynamic-fields.tsx:51)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/dynamic-fields.tsx:219)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/multi-step-form.tsx:111)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/server-validation.ts:106)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/server-validation.ts:155)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/server-validation.ts:250)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/shadcn-form.tsx:68)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/react-hook-form-zod/templates/shadcn-form.tsx:226)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts:187)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tailwind-patterns/templates/components/contact-form.tsx:86)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-query/templates/error-boundary.tsx:38)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-query/templates/query-client-config.ts:48)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:87)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:134)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:181)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-table/templates/column-configuration.tsx:113)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-table/templates/column-configuration.tsx:119)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tanstack-table/templates/d1-database-example.tsx:78)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tinacms/templates/cloudflare-worker-backend/src/index.ts:98)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/tiptap/templates/image-upload-r2.tsx:116)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/vercel-blob/templates/avatar-upload-flow.tsx:74)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/vercel-blob/templates/avatar-upload-flow.tsx:100)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/vercel-blob/templates/drag-drop-upload.tsx:147)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/vercel-blob/templates/file-list-manager.tsx:47)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/skills/vercel-blob/templates/file-list-manager.tsx:79)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:23)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:24)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:25)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:26)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:27)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:33)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:39)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:89)
- **[low] Leakage of information in logger message** — \#\# Description  Information leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.  \#\# Remediations  - **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.   '''javascript   logger.info('Results: ${data}') // unsafe   ''' - **Do** use loggin (/repo/tools/statusline-npm/bin/cli.js:101)

### nerlo-behavioral (v0.1.0) — Unsafe / 0.0

- **[high] opt.nerlo-rules.nerlo-dynamic-exec** — Dynamic command or code execution with a non-literal argument (child_process exec / eval / new Function) — a classic backdoor primitive. (/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts:109)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/claude-api/templates/cloudflare-worker.ts:29)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/claude-api/templates/cloudflare-worker.ts:29)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/claude-api/templates/cloudflare-worker.ts:76)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/claude-api/templates/cloudflare-worker.ts:76)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/claude-api/templates/cloudflare-worker.ts:183)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/claude-api/templates/cloudflare-worker.ts:183)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/claude-api/templates/cloudflare-worker.ts:231)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/claude-api/templates/cloudflare-worker.ts:231)
- **[high] opt.nerlo-rules.nerlo-dynamic-exec** — Dynamic command or code execution with a non-literal argument (child_process exec / eval / new Function) — a classic backdoor primitive. (/repo/skills/claude-api/templates/tool-use-advanced.ts:52)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/clerk-auth/templates/react/App.tsx:150)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/clerk-auth/templates/react/App.tsx:150)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-agents/templates/browser-agent.ts:132)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-agents/templates/browser-agent.ts:132)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-images/templates/batch-upload.ts:62)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/batch-upload.ts:62)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-images/templates/batch-upload.ts:97)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/batch-upload.ts:97)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/batch-upload.ts:116)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:68)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts:167)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/upload-api-basic.ts:65)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/upload-via-url.ts:63)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/variants-management.ts:35)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/variants-management.ts:60)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/variants-management.ts:79)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/variants-management.ts:105)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/variants-management.ts:127)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-images/templates/variants-management.ts:147)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts:193)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:76)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts:76)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:107)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts:107)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts:126)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts:39)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts:82)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/basic-workflow.ts:76)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts:163)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts:222)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts:71)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts:174)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts:204)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts:78)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts:120)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts:186)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:113)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:113)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:144)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:144)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:184)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:184)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:215)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/electron-base/templates/ipc-handlers/auth.ts:215)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/electron-base/templates/main.ts:140)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/electron-base/templates/main.ts:144)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx:14)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/mailgun-send.ts:110)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/mailgun-send.ts:153)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/mailgun-send.ts:196)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/resend-basic.ts:48)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/resend-basic.ts:48)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/resend-react-email.tsx:120)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/resend-react-email.tsx:152)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/resend-react-email.tsx:152)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:29)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:29)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:68)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts:68)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/sendgrid-transactional.ts:61)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/sendgrid-transactional.ts:61)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/smtp2go-bulk.ts:55)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/smtp2go-bulk.ts:55)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/smtp2go-send.ts:116)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/smtp2go-send.ts:116)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/email-gateway/templates/smtp2go-send.ts:179)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/email-gateway/templates/smtp2go-send.ts:179)
- **[high] opt.nerlo-rules.nerlo-py-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (requests / httpx / urllib / socket). This is the postmark-mcp supply-chain exfiltration shape: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/fastmcp/templates/openapi-integration.py:31)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:94)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:94)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:126)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:126)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts:150)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-chat-api/templates/bearer-token-verify.ts:82)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:91)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:91)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:148)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-api/templates/cloudflare-worker.ts:148)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:31)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:31)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:134)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-api/templates/streaming-fetch.ts:134)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:25)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:25)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:99)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-api/templates/text-generation-fetch.ts:99)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts:72)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts:72)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:91)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:91)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:124)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts:124)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-workspace/templates/oauth-worker.ts:79)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-workspace/templates/oauth-worker.ts:79)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-workspace/templates/oauth-worker.ts:99)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-workspace/templates/oauth-worker.ts:99)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-workspace/templates/oauth-worker.ts:127)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-workspace/templates/oauth-worker.ts:127)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/google-workspace/templates/oauth-worker.ts:165)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/google-workspace/templates/oauth-worker.ts:165)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/hono-routing/templates/error-handling.ts:215)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:87)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:141)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts:141)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/app-router-async-params.tsx:167)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:18)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:77)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:163)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:171)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:215)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:228)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:247)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:256)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:267)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/cache-component-use-cache.tsx:271)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/parallel-routes-with-default.tsx:109)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/route-handler-api.ts:17)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/route-handler-api.ts:26)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/route-handler-api.ts:123)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/nextjs/templates/route-handler-api.ts:123)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/route-handler-api.ts:160)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/nextjs/templates/route-handler-api.ts:160)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/route-handler-api.ts:315)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/server-actions-form.tsx:28)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/server-actions-form.tsx:102)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/server-actions-form.tsx:322)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/server-actions-form.tsx:399)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/nextjs/templates/server-actions-form.tsx:504)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/audio-transcription.ts:43)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/audio-transcription.ts:43)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/cloudflare-worker.ts:42)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/cloudflare-worker.ts:42)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:30)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:30)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:58)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:58)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:86)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:86)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:99)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:124)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:124)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:140)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:140)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:169)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:169)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:189)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:189)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:209)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:209)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/image-editing.ts:269)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/image-editing.ts:269)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/rate-limit-handling.ts:72)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/rate-limit-handling.ts:72)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/streaming-fetch.ts:17)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/streaming-fetch.ts:17)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-api/templates/text-to-speech.ts:242)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-api/templates/text-to-speech.ts:242)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-responses/templates/cloudflare-worker.ts:55)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-responses/templates/cloudflare-worker.ts:55)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/openai-responses/templates/cloudflare-worker.ts:108)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-responses/templates/cloudflare-worker.ts:108)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-responses/templates/cloudflare-worker.ts:227)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/openai-responses/templates/image-generation.ts:132)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/tanstack-query/templates/custom-hooks-pattern.tsx:22)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/tanstack-query/templates/custom-hooks-pattern.tsx:34)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/tanstack-query/templates/use-mutation-basic.tsx:23)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx:40)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/tanstack-query/templates/use-query-basic.tsx:18)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/ts-agent-sdk/templates/client.ts:92)
- **[high] opt.nerlo-rules.nerlo-dynamic-exec** — Dynamic command or code execution with a non-literal argument (child_process exec / eval / new Function) — a classic backdoor primitive. (/repo/skills/ts-agent-sdk/templates/db/client.ts:175)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/ts-agent-sdk/templates/db/client.ts:210)
- **[high] opt.nerlo-rules.nerlo-js-secret-to-network-egress** — A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host. (/repo/skills/typescript-mcp/templates/tool-server.ts:55)
- **[informational] opt.nerlo-rules.nerlo-hardcoded-external-egress** — Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict — it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine. (/repo/skills/zustand-state-management/templates/async-actions-store.ts:128)

### nerlo-install-instruction (v0.1.0) — Unsafe / 59.0

- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/CLAUDE.md:297)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/CONTRIBUTING.md:363)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/VERSIONS_REPORT.md:72)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/docs/MARKETPLACE.md:298)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/planning/RESEARCH_FINDINGS_openai-assistants.md:315)
- **[high] opt.nerlo-rules.nerlo-install-pipe-to-shell** — Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... \| bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders — the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal. (/repo/planning/RESEARCH_FINDINGS_playwright-local.md:425)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/planning/gemini-skills-verification-2025-10-26.md:261)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/skills/open-source-contributions/scripts/clean-branch.sh:179)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/skills/open-source-contributions/scripts/pre-pr-check.sh:247)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/skills/openai-assistants/SKILL.md:164)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/skills/skill-review/SKILL.md:36)
- **[informational] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact ("run resource.txt", "double-click setup.exe") — the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place. (/repo/skills/sub-agent-patterns/SKILL.md:158)

### capslock (vv0.3.2) — not_applicable / n/a

No findings.

## 4. Threat Model

Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.

## 5. Audit Chain

- **Scan job:** `d8265201-cf44-48c3-9762-8e5a8621c1f2`
- **Completed:** 2026-08-11T17:52:12.511592+00:00
- **Scanner base image:** `us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:d5aaefa8b517d1f03832091ab094e20dc73160a07ae1102af1b2e395ce6ce852`
- **AI decision log entries:** 1
  - `299dd34e-d9cd-4996-a178-79dbcf199f1d`

## 6. Appendix — Raw Scanner Output

```json
[
  {
    "scanner_name": "agentshield",
    "scanner_version": "1.4.0",
    "score": 84.0,
    "scanner_badge": "Caution",
    "findings": [
      {
        "tool_name": "agentshield",
        "severity": "high",
        "category": "injection",
        "file_path": "agents/cloudflare-debug.md",
        "line_number": null,
        "rule_identifier": "agents-skill-tamper-3905",
        "title": "Skill tampering or unsigned skill loading instruction",
        "description": "Found \"Skip verification\" \u2014 Instructs agent to skip skill verification \u2014 allows tampered skills to execute. Reference: OpenClaw skill verification gate (vgzotta PR #14893).",
        "remediation": null
      },
      {
        "tool_name": "agentshield",
        "severity": "high",
        "category": "injection",
        "file_path": "agents/cloudflare-deploy.md",
        "line_number": null,
        "rule_identifier": "agents-skill-tamper-2499",
        "title": "Skill tampering or unsigned skill loading instruction",
        "description": "Found \"Skip verification\" \u2014 Instructs agent to skip skill verification \u2014 allows tampered skills to execute. Reference: OpenClaw skill verification gate (vgzotta PR #14893).",
        "remediation": null
      },
      {
        "tool_name": "agentshield",
        "severity": "high",
        "category": "injection",
        "file_path": "agents/d1-migration.md",
        "line_number": null,
        "rule_identifier": "agents-skill-tamper-3282",
        "title": "Skill tampering or unsigned skill loading instruction",
        "description": "Found \"Skip verification\" \u2014 Instructs agent to skip skill verification \u2014 allows tampered skills to execute. Reference: OpenClaw skill verification gate (vgzotta PR #14893).",
        "remediation": null
      },
      {
        "tool_name": "agentshield",
        "severity": "high",
        "category": "injection",
        "file_path": "agents/d1-migration.md",
        "line_number": null,
        "rule_identifier": "agents-destructive-tool-3359",
        "title": "Destructive tool usage instruction detected",
        "description": "Found \"Drop tables\" \u2014 Contains destructive SQL/database operations \u2014 drop tables, truncate, mass delete. From openclaw-security-guard tool manipulation patterns.",
        "remediation": null
      },
      {
        "tool_name": "agentshield",
        "severity": "medium",
        "category": "agents",
        "file_path": "agents/a11y-auditor.md",
        "line_number": null,
        "rule_identifier": "agents-oversized-prompt-agents/a11y-auditor.md",
        "title": "Agent definition effective size is 5580 characters (>5000 threshold)",
        "description": "The agent definition at agents/a11y-auditor.md has an effective size of 5580 characters after discounting fenced code blocks and markdown tables. Unusually large agent definitions may contain hidden malicious instructions buried in legitimate-looking text. Review the full content carefully, especially any instructions near the end of the file.",
        "remediation": null
      },
      {
        "tool_name": "agentshield",
        "severity": "medium",
        "category": "agents",
        "file_path": "agents/code-example-validator.md",
        "line_number": null,
        "rule_identifier": "agents-oversized-prompt-agents/code-example-validator.md",
        "title": "Agent definition effective size is 5564 characters (>5000 threshold)",
        "description": "The agent definition at agents/code-example-validator.md has an effective size of 5564 characters after discounting fenced code blocks and markdown tables. Unusually large agent definitions may contain hidden malicious instructions buried in legitimate-looking text. Review the full content carefully, especially any instructions near the end of the file.",
        "remediation": null
      },
      {
        "tool_name": "agentshield",
        "severity": "medium",
        "category": "agents",
        "file_path": "agents/content-accuracy-auditor.md",
        "line_number": null,
        "rule_identifier": "agents-oversized-prompt-agents/content-accuracy-auditor.md",
        "title": "Agent definition effective size is 7700 characters (>5000 threshold)",
        "description": "The agent definition at agents/content-accuracy-auditor.md has an effective size of 7700 characters after discounting fenced code blocks and markdown tables. Unusually large agent definitions may contain hidden malicious instructions buried in legitimate-looking text. Review the full content carefully, especially any instructions near the end of the file.",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 1.1170961870229803,
    "status": "complete",
    "examined": {
      "unit": "scan_targets",
      "count": 1
    },
    "metadata": {
      "source": "npm",
      "source_url": "https://www.npmjs.com/package/ecc-agentshield",
      "install_command": "npm install -g ecc-agentshield@1.4.0",
      "scans_performed": [
        "claude_config"
      ],
      "score_breakdown": {
        "mcp": 100,
        "hooks": 100,
        "agents": 25,
        "secrets": 100,
        "permissions": 100
      }
    },
    "display_score": 84.0,
    "display_badge": "Caution"
  },
  {
    "scanner_name": "cisco-skill-scanner",
    "scanner_version": "2.0.11",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-python-workers/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-browser-rendering",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 58% of skill content could be analyzed. 8 of 18 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-browser-rendering/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts",
        "line_number": 20,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts",
        "line_number": 40,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/basic-screenshot.ts",
        "line_number": 11,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/pdf-generation.ts",
        "line_number": 26,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/screenshot-with-kv-cache.ts",
        "line_number": 12,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts",
        "line_number": 47,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/web-scraper-basic.ts",
        "line_number": 21,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/web-scraper-batch.ts",
        "line_number": 57,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-ui",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 51% of skill content could be analyzed. 10 of 21 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-ui/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-worker-base",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 88% of skill content could be analyzed. 3 of 21 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-worker-base/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 35,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 51,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/src/index.ts",
        "line_number": 77,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-hook-form-zod",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 61% of skill content could be analyzed. 8 of 22 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-hook-form-zod/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 26,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 241,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/basic-form.tsx",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/server-validation.ts",
        "line_number": 222,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/tinacms",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 53% of skill content could be analyzed. 11 of 24 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tinacms/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tinacms/templates/cloudflare-worker-backend/src/index.ts",
        "line_number": 51,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-file-search",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 89% of skill content could be analyzed. 1 of 9 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-file-search/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-assistants",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 64% of skill content could be analyzed. 7 of 20 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-assistants/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 43,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 106,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 67,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 71,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 76,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 101,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 110,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/skill-review/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/sveltia-cms/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "command_injection",
        "file_path": "/repo/skills/sveltia-cms/SKILL.md",
        "line_number": 504,
        "rule_identifier": "FIND_EXEC_PATTERN",
        "title": "find command with -exec flag can execute arbitrary commands on discovered files",
        "description": "Pattern detected: find content -name \"*.md\" -exec ",
        "remediation": "Avoid find -exec with untrusted directories. Use explicit file lists instead"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "command_injection",
        "file_path": "/repo/skills/sveltia-cms/SKILL.md",
        "line_number": 521,
        "rule_identifier": "FIND_EXEC_PATTERN",
        "title": "find command with -exec flag can execute arbitrary commands on discovered files",
        "description": "Pattern detected: find content -name \"*.md\" -exec ",
        "remediation": "Avoid find -exec with untrusted directories. Use explicit file lists instead"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-router",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 77% of skill content could be analyzed. 2 of 8 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-router/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name 'TanStack Router' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-router/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-responses",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 58% of skill content could be analyzed. 9 of 22 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-responses/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 13,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 74,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 108,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 122,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 146,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 163,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 200,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 227,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 249,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 297,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 20,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 61,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 71,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 95,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 128,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 155,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 185,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 190,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 200,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 132,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 137,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'web-search.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-auth",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 51% of skill content could be analyzed. 4 of 8 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-auth/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/skill-creator/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/docs-workflow/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/firecrawl-scraper",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 78% of skill content could be analyzed. 2 of 9 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firecrawl-scraper/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 102,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFile(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 94,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 126,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 150,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 166,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/nextjs",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 58% of skill content could be analyzed. 6 of 15 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/nextjs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 327,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 102,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-workspace",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 79% of skill content could be analyzed. 1 of 5 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-workspace/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 37,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 79,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 99,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 127,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 165,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-cli-scripts",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 82% of skill content could be analyzed. 1 of 6 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-cli-scripts/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/mcp-cli-scripts/templates/script-template.ts",
        "line_number": 144,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-api",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 54% of skill content could be analyzed. 14 of 31 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-api/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 91,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 148,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 218,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 230,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 56,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 28,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 22,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 31,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 134,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 5,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch (",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 22,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 99,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-chat-api",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 55% of skill content could be analyzed. 5 of 12 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-chat-api/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/bearer-token-verify.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/interactive-bot.ts",
        "line_number": 31,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/webhook-handler.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/webhook-handler.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/wordpress-plugin-core/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/ts-agent-sdk",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 15% of skill content could be analyzed. 16 of 19 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/ts-agent-sdk/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/api/base.ts",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/client.ts",
        "line_number": 92,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 8,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: from 'child_process'",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 175,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: execSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 210,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-planning/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-d1",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 88% of skill content could be analyzed. 1 of 9 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-d1/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/vercel-blob",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 63% of skill content could be analyzed. 3 of 10 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/vercel-blob/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-blob/templates/drag-drop-upload.tsx",
        "line_number": 115,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-blob/templates/file-list-manager.tsx",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-blob/templates/file-list-manager.tsx",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/playwright-local",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 56% of skill content could be analyzed. 6 of 13 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/playwright-local/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/playwright-local/templates/authenticated-session.ts",
        "line_number": 27,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFile(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/playwright-local/templates/authenticated-session.ts",
        "line_number": 33,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFile(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/playwright-local/templates/basic-scrape.ts",
        "line_number": 29,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/playwright-local/templates/basic-scrape.ts",
        "line_number": 35,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-hyperdrive",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 71% of skill content could be analyzed. 7 of 22 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-hyperdrive/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/drizzle-mysql.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/drizzle-postgres.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts",
        "line_number": 6,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts",
        "line_number": 30,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-basic.ts",
        "line_number": 15,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-js.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-pool.ts",
        "line_number": 15,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/prisma-postgres.ts",
        "line_number": 57,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-queues",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 65% of skill content could be analyzed. 5 of 14 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-queues/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 76,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 107,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-native-expo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/email-gateway",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 48% of skill content could be analyzed. 8 of 15 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 110,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 153,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 196,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 265,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 225,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-basic.ts",
        "line_number": 48,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-basic.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-react-email.tsx",
        "line_number": 152,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 191,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-transactional.ts",
        "line_number": 61,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-transactional.ts",
        "line_number": 203,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-bulk.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-bulk.ts",
        "line_number": 286,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 116,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 179,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 296,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workflows",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 58% of skill content could be analyzed. 5 of 12 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workflows/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/basic-workflow.ts",
        "line_number": 102,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts",
        "line_number": 231,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts",
        "line_number": 226,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts",
        "line_number": 214,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-core",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 53% of skill content could be analyzed. 12 of 24 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "social_engineering",
        "file_path": "/repo/skills/ai-sdk-core/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_ANTHROPIC_IMPERSONATION",
        "title": "Potential Anthropic brand impersonation",
        "description": "Skill name or description contains 'Anthropic', suggesting official affiliation",
        "remediation": "Do not impersonate official skills or use unauthorized branding"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-core/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-images",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 67% of skill content could be analyzed. 8 of 25 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-images/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 62,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 97,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 116,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 227,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 94,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 167,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/signed-urls-generation.ts",
        "line_number": 109,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 4,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 38,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 46,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 64,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 83,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 114,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 119,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 135,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 148,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 164,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 199,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 210,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 229,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 237,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 258,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 265,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 273,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-api-basic.ts",
        "line_number": 65,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-api-basic.ts",
        "line_number": 91,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-via-url.ts",
        "line_number": 63,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-via-url.ts",
        "line_number": 88,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 35,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 60,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 79,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 105,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 127,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 147,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 168,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/elevenlabs-agents",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 87% of skill content could be analyzed. 3 of 23 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/elevenlabs-agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "prompt_injection",
        "file_path": "/repo/skills/elevenlabs-agents/assets/agent-config-schema.json",
        "line_number": 60,
        "rule_identifier": "ASSET_PROMPT_INJECTION",
        "title": "Role reassignment pattern in asset file",
        "description": "Pattern 'You are now ...' detected in asset file",
        "remediation": "Review the asset file and remove any malicious or unnecessary dynamic patterns"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx",
        "line_number": 14,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx",
        "line_number": 24,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-session-management/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/zustand-state-management",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 59% of skill content could be analyzed. 8 of 20 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/zustand-state-management/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/zustand-state-management/templates/async-actions-store.ts",
        "line_number": 296,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/django-cloud-sql-postgres/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-firestore",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 78% of skill content could be analyzed. 2 of 8 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-firestore/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/open-source-contributions/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-r2",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 74% of skill content could be analyzed. 3 of 12 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unauthorized_tool_use",
        "file_path": "/repo/skills/cloudflare-r2/repo/skills/cloudflare-r2/SKILL.md",
        "line_number": null,
        "rule_identifier": "TOOL_ABUSE_UNDECLARED_NETWORK",
        "title": "Undeclared network usage",
        "description": "Skill code uses network libraries but doesn't declare network requirement",
        "remediation": "Declare network usage in compatibility field or remove network calls"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-r2/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_MISLEADING_DESC",
        "title": "Potential description-behavior mismatch",
        "description": "Skill performs actions not reflected in its description",
        "remediation": "Ensure description accurately reflects all skill capabilities"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-r2/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts",
        "line_number": 242,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts",
        "line_number": 259,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-agents",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 42% of skill content could be analyzed. 17 of 30 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts",
        "line_number": 6,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts",
        "line_number": 45,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 80,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "prompt_injection",
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 84,
        "rule_identifier": "ASSET_PROMPT_INJECTION",
        "title": "Prompt injection pattern in asset file",
        "description": "Pattern 'ignore previous instructions...' detected in asset file",
        "remediation": "Review the asset file and remove any malicious or unnecessary dynamic patterns"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "prompt_injection",
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 128,
        "rule_identifier": "ASSET_PROMPT_INJECTION",
        "title": "Prompt injection pattern in asset file",
        "description": "Pattern 'Ignore previous instructions...' detected in asset file",
        "remediation": "Review the asset file and remove any malicious or unnecessary dynamic patterns"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 98,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 131,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 177,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 197,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-storage/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/jquery-4/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-spaces-updates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/fastapi/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/fastapi/templates/src/auth/__init__.py",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/fastapi/templates/tests/__init__.py",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-api",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 49% of skill content could be analyzed. 15 of 30 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-api/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 43,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 72,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 106,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 138,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 174,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 178,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/cloudflare-worker.ts",
        "line_number": 14,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/cloudflare-worker.ts",
        "line_number": 42,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 26,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 52,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 53,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 58,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 80,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 86,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 99,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 101,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 115,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 124,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 140,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 165,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 169,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 189,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 204,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 209,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 232,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 238,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 244,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 250,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 266,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 269,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 156,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 168,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 172,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/rate-limit-handling.ts",
        "line_number": 72,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/streaming-fetch.ts",
        "line_number": 9,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/streaming-fetch.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 93,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 104,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 125,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 136,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 147,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 172,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 201,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 230,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 242,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 279,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 296,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 54,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/electron-base",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 54% of skill content could be analyzed. 5 of 11 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/electron-base/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 113,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 144,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 215,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/typescript-mcp",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 71% of skill content could be analyzed. 6 of 21 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/typescript-mcp/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/typescript-mcp/templates/tool-server.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-start/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name 'TanStack Start' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-start/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/auto-animate",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 59% of skill content could be analyzed. 7 of 17 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/auto-animate/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/auto-animate/templates/form-validation.tsx",
        "line_number": 43,
        "rule_identifier": "SECRET_PASSWORD_VAR",
        "title": "Hardcoded password or secret in variable",
        "description": "Pattern detected: pass****",
        "remediation": "Use environment variables or secure vaults for secrets"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/auto-animate/templates/form-validation.tsx",
        "line_number": 45,
        "rule_identifier": "SECRET_PASSWORD_VAR",
        "title": "Hardcoded password or secret in variable",
        "description": "Pattern detected: pass****",
        "remediation": "Use environment variables or secure vaults for secrets"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-kv",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 61% of skill content could be analyzed. 4 of 11 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-kv/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-turnstile",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 72% of skill content could be analyzed. 5 of 19 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-turnstile/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 39,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx",
        "line_number": 34,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx",
        "line_number": 165,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 135,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-test-config.ts",
        "line_number": 280,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/neon-vercel-postgres",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 58% of skill content could be analyzed. 5 of 13 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/neon-vercel-postgres/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/neon-vercel-postgres/assets/drizzle-schema.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/neon-vercel-postgres/templates/drizzle-schema.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-durable-objects",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 67% of skill content could be analyzed. 7 of 22 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-durable-objects/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/basic-do.ts",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/location-hints.ts",
        "line_number": 34,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/location-hints.ts",
        "line_number": 107,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/location-hints.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 223,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 80,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 114,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 178,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 200,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 212,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 46,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 204,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 223,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/drizzle-orm-d1",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 64% of skill content could be analyzed. 8 of 23 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/drizzle-orm-d1/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/drizzle-orm-d1/templates/client.ts",
        "line_number": 44,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/better-auth",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 56% of skill content could be analyzed. 6 of 14 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/better-auth/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/azure-auth",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 49% of skill content could be analyzed. 5 of 10 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/azure-auth/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/use-api-token.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/use-api-token.ts",
        "line_number": 156,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/use-api-token.ts",
        "line_number": 215,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": 87,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": 206,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-workflow/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/hono-routing",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 54% of skill content could be analyzed. 8 of 18 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/hono-routing/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-query",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 60% of skill content could be analyzed. 9 of 23 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-query/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/error-boundary.tsx",
        "line_number": 171,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/error-boundary.tsx",
        "line_number": 186,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-infinite-query.tsx",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 23,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 37,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 54,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 104,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 157,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-query-basic.tsx",
        "line_number": 18,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-query-basic.tsx",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/favicon-gen/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-api",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 52% of skill content could be analyzed. 11 of 24 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-api/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 10,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 76,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 124,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 151,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 231,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 84,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 52,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 12,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 60,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 61,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 119,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 160,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 215,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/clerk-auth",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 71% of skill content could be analyzed. 8 of 29 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/clerk-auth/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 56,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: https.request(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 96,
        "rule_identifier": "SECRET_PASSWORD_VAR",
        "title": "Hardcoded password or secret in variable",
        "description": "Pattern detected: pass****",
        "remediation": "Use environment variables or secure vaults for secrets"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/skills/clerk-auth/templates/env-examples/.dev.vars.example",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: templates/env-examples/.dev.vars.example. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/skills/clerk-auth/templates/env-examples/.env.local.example",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: templates/env-examples/.env.local.example. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/skills/clerk-auth/templates/env-examples/.env.local.vite.example",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: templates/env-examples/.env.local.vite.example. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/clerk-auth/templates/react/App.tsx",
        "line_number": 150,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/accessibility/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-agents",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 28% of skill content could be analyzed. 13 of 18 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-agents/templates/browser-agent.ts",
        "line_number": 126,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-agents/templates/browser-agent.ts",
        "line_number": 132,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts",
        "line_number": 12,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts",
        "line_number": 49,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-oauth-cloudflare",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 57% of skill content could be analyzed. 5 of 12 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name 'MCP OAuth Cloudflare' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 87,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 141,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/flask/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/flask/templates/tests/__init__.py",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/streamlit-snowflake/templates/pages/data_explorer.py",
        "line_number": 76,
        "rule_identifier": "YARA_sql_injection_generic",
        "title": "INJECTION ATTACK detected by YARA",
        "description": "Detects SQL injection attack patterns including keywords, tautologies, and database functions: SELECT table_name, row_count, bytes\n    FROM {quote_identifier(database)}.information_schema",
        "remediation": "Review and remove injection attack pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-agent-sdk",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 59% of skill content could be analyzed. 9 of 22 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-agent-sdk/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts",
        "line_number": 109,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'filesystem-settings.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-mcp-server",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 68% of skill content could be analyzed. 7 of 24 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-mcp-server/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 153,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 159,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 172,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 202,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'mcp-bearer-auth.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 193,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 243,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 366,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 376,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 23,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 115,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 129,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 149,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts",
        "line_number": 322,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts",
        "line_number": 346,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts",
        "line_number": 522,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts",
        "line_number": 544,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts",
        "line_number": 549,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 264,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 286,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 291,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-patterns",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 74% of skill content could be analyzed. 4 of 15 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-patterns/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tailwind-patterns/templates/components/contact-form.tsx",
        "line_number": 259,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unauthorized_tool_use",
        "file_path": "/repo/skills/fastmcp/repo/skills/fastmcp/SKILL.md",
        "line_number": null,
        "rule_identifier": "TOOL_ABUSE_UNDECLARED_NETWORK",
        "title": "Undeclared network usage",
        "description": "Skill code uses network libraries but doesn't declare network requirement",
        "remediation": "Declare network usage in compatibility field or remove network calls"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/fastmcp/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "resource_abuse",
        "file_path": "/repo/skills/fastmcp/templates/client-example.py",
        "line_number": 252,
        "rule_identifier": "RESOURCE_ABUSE_INFINITE_LOOP",
        "title": "Infinite loop without clear exit condition",
        "description": "Pattern detected: while True:",
        "remediation": "Add proper exit conditions or limits to loops"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/fastmcp/templates/openapi-integration.py",
        "line_number": 31,
        "rule_identifier": "DATA_EXFIL_NETWORK_REQUESTS",
        "title": "Outbound network request primitives that can transmit data externally",
        "description": "Pattern detected: httpx.get(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/sub-agent-patterns/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-embeddings",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 64% of skill content could be analyzed. 6 of 17 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-embeddings/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts",
        "line_number": 35,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts",
        "line_number": 72,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 91,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 124,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 164,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-v4-shadcn",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 84% of skill content could be analyzed. 3 of 15 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-v4-shadcn/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workers-ai",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 62% of skill content could be analyzed. 5 of 14 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workers-ai/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workers-ai/templates/ai-vision-models.ts",
        "line_number": 323,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-apps-mcp/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name 'OpenAI Apps MCP' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-apps-mcp/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/vercel-kv",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 73% of skill content could be analyzed. 2 of 9 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/vercel-kv/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-kv/templates/simple-rate-limiting.ts",
        "line_number": 303,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/tiptap",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 76% of skill content could be analyzed. 3 of 13 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tiptap/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tiptap/templates/image-upload-r2.tsx",
        "line_number": 87,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-table",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 62% of skill content could be analyzed. 6 of 16 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-table/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name 'TanStack Table' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-table/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-table/templates/server-paginated-table.tsx",
        "line_number": 67,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/motion",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 65% of skill content could be analyzed. 5 of 15 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/motion/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-app-engine/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-vectorize",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 73% of skill content could be analyzed. 4 of 15 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-vectorize/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/basic-search.ts",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 86,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 237,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 259,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts",
        "line_number": 28,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/rag-chat.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/icon-design/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/office",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 65% of skill content could be analyzed. 5 of 15 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/office/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/templates/skill-skeleton/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name '[{'TODO': 'lowercase-hyphen-case-name'}]' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/templates/skill-skeleton/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "policy_violation",
        "file_path": "/repo",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Moderate analyzability score",
        "description": "Only 76% of skill content could be analyzed. 412 of 1701 files are opaque to the scanner. Some content could not be verified as safe.",
        "remediation": "Review opaque files and replace with inspectable formats where possible."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "policy_violation",
        "file_path": "/repo/.",
        "line_number": null,
        "rule_identifier": "EXCESSIVE_FILE_COUNT",
        "title": "Skill package contains many files",
        "description": "Skill package contains 1701 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content.",
        "remediation": "Review file inventory and remove unnecessary files."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/.env.development",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .env.development. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/.env.production",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .env.production. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unauthorized_tool_use",
        "file_path": "/repo/repo/BUN_CROSS_PLATFORM_ENV.md",
        "line_number": null,
        "rule_identifier": "TOOL_ABUSE_UNDECLARED_NETWORK",
        "title": "Undeclared network usage",
        "description": "Skill code uses network libraries but doesn't declare network requirement",
        "remediation": "Declare network usage in compatibility field or remove network calls"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 2263,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: exec(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 7061,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: exec(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "hardcoded_secrets",
        "file_path": "/repo/scripts/check-github-releases.sh",
        "line_number": 76,
        "rule_identifier": "SECRET_PASSWORD_VAR",
        "title": "Hardcoded password or secret in variable",
        "description": "Pattern detected: toke****",
        "remediation": "Use environment variables or secure vaults for secrets"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/auto-animate/templates/form-validation.tsx",
        "line_number": 43,
        "rule_identifier": "SECRET_PASSWORD_VAR",
        "title": "Hardcoded password or secret in variable",
        "description": "Pattern detected: pass****",
        "remediation": "Use environment variables or secure vaults for secrets"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/auto-animate/templates/form-validation.tsx",
        "line_number": 45,
        "rule_identifier": "SECRET_PASSWORD_VAR",
        "title": "Hardcoded password or secret in variable",
        "description": "Pattern detected: pass****",
        "remediation": "Use environment variables or secure vaults for secrets"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/use-api-token.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/use-api-token.ts",
        "line_number": 156,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/use-api-token.ts",
        "line_number": 215,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": 87,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": 206,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts",
        "line_number": 109,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'filesystem-settings.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 10,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 76,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 124,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 151,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 231,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 84,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 52,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 12,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 60,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 61,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 119,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 160,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 215,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 56,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: https.request(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 96,
        "rule_identifier": "SECRET_PASSWORD_VAR",
        "title": "Hardcoded password or secret in variable",
        "description": "Pattern detected: pass****",
        "remediation": "Use environment variables or secure vaults for secrets"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/skills/clerk-auth/templates/env-examples/.dev.vars.example",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: skills/clerk-auth/templates/env-examples/.dev.vars.example. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/skills/clerk-auth/templates/env-examples/.env.local.example",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: skills/clerk-auth/templates/env-examples/.env.local.example. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/skills/clerk-auth/templates/env-examples/.env.local.vite.example",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: skills/clerk-auth/templates/env-examples/.env.local.vite.example. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/clerk-auth/templates/react/App.tsx",
        "line_number": 150,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-agents/templates/browser-agent.ts",
        "line_number": 126,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-agents/templates/browser-agent.ts",
        "line_number": 132,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts",
        "line_number": 12,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-agents/templates/calling-agents-worker.ts",
        "line_number": 49,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts",
        "line_number": 20,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/ai-enhanced-scraper.ts",
        "line_number": 40,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/basic-screenshot.ts",
        "line_number": 11,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/pdf-generation.ts",
        "line_number": 26,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/screenshot-with-kv-cache.ts",
        "line_number": 12,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts",
        "line_number": 47,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/web-scraper-basic.ts",
        "line_number": 21,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/web-scraper-batch.ts",
        "line_number": 57,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/basic-do.ts",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/location-hints.ts",
        "line_number": 34,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/location-hints.ts",
        "line_number": 107,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/location-hints.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 223,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 80,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 114,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 178,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 200,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/rpc-vs-fetch.ts",
        "line_number": 212,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 46,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 204,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 223,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/drizzle-mysql.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/drizzle-postgres.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts",
        "line_number": 6,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts",
        "line_number": 30,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-basic.ts",
        "line_number": 15,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-js.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-pool.ts",
        "line_number": 15,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/prisma-postgres.ts",
        "line_number": 57,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 62,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 97,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 116,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 227,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 94,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 167,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/signed-urls-generation.ts",
        "line_number": 109,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 4,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 38,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 46,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 64,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 83,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 114,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 119,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 135,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 148,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 164,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 199,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 210,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 229,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 237,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 258,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 265,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 273,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-api-basic.ts",
        "line_number": 65,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-api-basic.ts",
        "line_number": 91,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-via-url.ts",
        "line_number": 63,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-via-url.ts",
        "line_number": 88,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 35,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 60,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 79,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 105,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 127,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 147,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 168,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 153,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 159,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 172,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 202,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'mcp-bearer-auth.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 193,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 243,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 366,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 376,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 23,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 115,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 129,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 149,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts",
        "line_number": 322,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts",
        "line_number": 346,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts",
        "line_number": 522,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts",
        "line_number": 544,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-d1.ts",
        "line_number": 549,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 264,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 286,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 291,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 76,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 107,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts",
        "line_number": 242,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts",
        "line_number": 259,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 39,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx",
        "line_number": 34,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx",
        "line_number": 165,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 135,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-test-config.ts",
        "line_number": 280,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/basic-search.ts",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 86,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 237,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 259,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts",
        "line_number": 28,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-vectorize/templates/rag-chat.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 35,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 51,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-worker-base/templates/src/index.ts",
        "line_number": 77,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workers-ai/templates/ai-vision-models.ts",
        "line_number": 323,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/basic-workflow.ts",
        "line_number": 102,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts",
        "line_number": 231,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts",
        "line_number": 226,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts",
        "line_number": 214,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/drizzle-orm-d1/templates/client.ts",
        "line_number": 44,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 113,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 144,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 215,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "prompt_injection",
        "file_path": "/repo/skills/elevenlabs-agents/assets/agent-config-schema.json",
        "line_number": 60,
        "rule_identifier": "ASSET_PROMPT_INJECTION",
        "title": "Role reassignment pattern in asset file",
        "description": "Pattern 'You are now ...' detected in asset file",
        "remediation": "Review the asset file and remove any malicious or unnecessary dynamic patterns"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx",
        "line_number": 14,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx",
        "line_number": 24,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 110,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 153,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 196,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 265,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 225,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-basic.ts",
        "line_number": 48,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-basic.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-react-email.tsx",
        "line_number": 152,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 191,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-transactional.ts",
        "line_number": 61,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-transactional.ts",
        "line_number": 203,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-bulk.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-bulk.ts",
        "line_number": 286,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 116,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 179,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 296,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/fastapi/templates/src/auth/__init__.py",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/fastapi/templates/tests/__init__.py",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "resource_abuse",
        "file_path": "/repo/skills/fastmcp/templates/client-example.py",
        "line_number": 252,
        "rule_identifier": "RESOURCE_ABUSE_INFINITE_LOOP",
        "title": "Infinite loop without clear exit condition",
        "description": "Pattern detected: while True:",
        "remediation": "Add proper exit conditions or limits to loops"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/fastmcp/templates/openapi-integration.py",
        "line_number": 31,
        "rule_identifier": "DATA_EXFIL_NETWORK_REQUESTS",
        "title": "Outbound network request primitives that can transmit data externally",
        "description": "Pattern detected: httpx.get(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 102,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFile(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 94,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 126,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 150,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 166,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/flask/templates/tests/__init__.py",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File '__init__.py' extension (.py) suggests one format but Magika detected a different text format: Markdown document (markdown). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/bearer-token-verify.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/interactive-bot.ts",
        "line_number": 31,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/webhook-handler.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-chat-api/templates/webhook-handler.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 91,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 148,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 218,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 230,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 29,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 56,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 28,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 82,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 22,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 31,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 134,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 5,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch (",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 22,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 99,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts",
        "line_number": 35,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts",
        "line_number": 72,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 91,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 124,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 164,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 37,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 79,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 99,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 127,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 165,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/mcp-cli-scripts/templates/script-template.ts",
        "line_number": 144,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 87,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 141,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/neon-vercel-postgres/assets/drizzle-schema.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/neon-vercel-postgres/templates/drizzle-schema.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 327,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 102,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts",
        "line_number": 6,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts",
        "line_number": 45,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 80,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 43,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 72,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 106,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 138,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 174,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 178,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/cloudflare-worker.ts",
        "line_number": 14,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/cloudflare-worker.ts",
        "line_number": 42,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 26,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 52,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 53,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 58,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 80,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 86,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 99,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 101,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 115,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 124,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 140,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 165,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 169,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 184,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 189,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 204,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 209,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 232,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 238,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 244,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 250,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 266,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 269,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 156,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 168,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 172,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/rate-limit-handling.ts",
        "line_number": 72,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/streaming-fetch.ts",
        "line_number": 9,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/streaming-fetch.ts",
        "line_number": 17,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 93,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 104,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 125,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 136,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 147,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 172,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 201,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 230,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 242,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 279,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 296,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 54,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 43,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 106,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 67,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 71,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 76,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 101,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 110,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 13,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 74,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 108,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 122,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 146,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 163,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 183,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 200,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 227,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 249,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 297,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 20,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 61,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 71,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 95,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 128,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 155,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 185,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 190,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 200,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.createReadStream(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 132,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 137,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'web-search.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/playwright-local/templates/authenticated-session.ts",
        "line_number": 27,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFile(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/playwright-local/templates/authenticated-session.ts",
        "line_number": 33,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.readFile(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/playwright-local/templates/basic-scrape.ts",
        "line_number": 29,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/playwright-local/templates/basic-scrape.ts",
        "line_number": 35,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: eval(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 26,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 195,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 241,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/basic-form.tsx",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/react-hook-form-zod/templates/server-validation.ts",
        "line_number": 222,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 98,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 131,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 177,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 197,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/streamlit-snowflake/templates/pages/data_explorer.py",
        "line_number": 76,
        "rule_identifier": "YARA_sql_injection_generic",
        "title": "INJECTION ATTACK detected by YARA",
        "description": "Detects SQL injection attack patterns including keywords, tautologies, and database functions: SELECT table_name, row_count, bytes\n    FROM {quote_identifier(database)}.information_schema",
        "remediation": "Review and remove injection attack pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tailwind-patterns/templates/components/contact-form.tsx",
        "line_number": 259,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/error-boundary.tsx",
        "line_number": 171,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/error-boundary.tsx",
        "line_number": 186,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-infinite-query.tsx",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 23,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 37,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 54,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 40,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 104,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 157,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-query-basic.tsx",
        "line_number": 18,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-query/templates/use-query-basic.tsx",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tanstack-table/templates/server-paginated-table.tsx",
        "line_number": 67,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tinacms/templates/cloudflare-worker-backend/src/index.ts",
        "line_number": 51,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/tiptap/templates/image-upload-r2.tsx",
        "line_number": 87,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/api/base.ts",
        "line_number": 32,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/client.ts",
        "line_number": 92,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 8,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: from 'child_process'",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 175,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: execSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 210,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/typescript-mcp/templates/tool-server.ts",
        "line_number": 55,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-blob/templates/drag-drop-upload.tsx",
        "line_number": 115,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-blob/templates/file-list-manager.tsx",
        "line_number": 30,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-blob/templates/file-list-manager.tsx",
        "line_number": 66,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/vercel-kv/templates/simple-rate-limiting.ts",
        "line_number": 303,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/zustand-state-management/templates/async-actions-store.ts",
        "line_number": 296,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 3,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: require('child_process')",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 21,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 31,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 71,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 79,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 107,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "policy_violation",
        "file_path": "/repo/planning/.",
        "line_number": null,
        "rule_identifier": "EXCESSIVE_FILE_COUNT",
        "title": "Skill package contains many files",
        "description": "Skill package contains 117 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content.",
        "remediation": "Review file inventory and remove unnecessary files."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/planning/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/planning/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/profiles/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/profiles/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/docs/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/docs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.claude/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/planning/clerk-docs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/planning/research-logs/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/planning/research-logs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-python-workers/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-python-workers/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-browser-rendering/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-browser-rendering/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-browser-rendering/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-browser-rendering/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/ai-sdk-ui/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-ui/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/ai-sdk-ui/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-ui/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-worker-base/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-worker-base/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-worker-base/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-worker-base/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-worker-base/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-worker-base/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-worker-base/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/react-hook-form-zod/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-hook-form-zod/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/react-hook-form-zod/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-hook-form-zod/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tinacms/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tinacms/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tinacms/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tinacms/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-gemini-file-search/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-file-search/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-file-search/scripts",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 48% of skill content could be analyzed. 1 of 2 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-gemini-file-search/scripts/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-file-search/scripts/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-gemini-file-search/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-file-search/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-assistants/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-assistants/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-assistants/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-assistants/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/skill-review/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/skill-review/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/responsive-images/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/responsive-images/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/responsive-images/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/responsive-images/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/sveltia-cms/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/sveltia-cms/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/sveltia-cms/templates/cloudflare-workers/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/sveltia-cms/templates/cloudflare-workers/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tanstack-router/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-router/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tanstack-router/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-router/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-responses/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-responses/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-responses/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-responses/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/firebase-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/docs-workflow/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/docs-workflow/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/docs-workflow/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/docs-workflow/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/docs-workflow/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/docs-workflow/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/oauth-integrations/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/oauth-integrations/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/firecrawl-scraper/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firecrawl-scraper/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/nextjs/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/nextjs/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/nextjs/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/nextjs/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/nextjs/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/nextjs/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-workspace/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-workspace/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/mcp-cli-scripts/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-cli-scripts/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-cli-scripts/templates",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 47% of skill content could be analyzed. 1 of 2 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/mcp-cli-scripts/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-cli-scripts/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/mcp-cli-scripts/templates/script-template.ts",
        "line_number": 144,
        "rule_identifier": "DATA_EXFIL_JS_FS_ACCESS",
        "title": "Node.js filesystem access that could read or write sensitive data",
        "description": "Pattern detected: fs.writeFileSync(",
        "remediation": "Review filesystem operations. Ensure they don't access sensitive system files or credential stores"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-gemini-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-gemini-api/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-api/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-chat-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-chat-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/wordpress-plugin-core/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/wordpress-plugin-core/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/wordpress-plugin-core/templates/plugin-simple/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/wordpress-plugin-core/templates/plugin-simple/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/wordpress-plugin-core/templates/plugin-oop/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/wordpress-plugin-core/templates/plugin-oop/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/wordpress-plugin-core/templates/plugin-psr4/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/wordpress-plugin-core/templates/plugin-psr4/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/project-planning/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-planning/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/project-planning/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-planning/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/project-planning/references/example-outputs/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-planning/references/example-outputs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/developer-toolbox/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/developer-toolbox/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-d1/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-d1/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-d1/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-d1/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/vercel-blob/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/vercel-blob/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/playwright-local/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/playwright-local/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": 2335,
        "rule_identifier": "SECRET_CONNECTION_STRING",
        "title": "Database connection string with embedded credentials",
        "description": "Pattern detected: post****",
        "remediation": "Remove credentials from connection strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": 2367,
        "rule_identifier": "SECRET_CONNECTION_STRING",
        "title": "Database connection string with embedded credentials",
        "description": "Pattern detected: post****",
        "remediation": "Remove credentials from connection strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": 2411,
        "rule_identifier": "SECRET_CONNECTION_STRING",
        "title": "Database connection string with embedded credentials",
        "description": "Pattern detected: post****",
        "remediation": "Remove credentials from connection strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": 3740,
        "rule_identifier": "SECRET_CONNECTION_STRING",
        "title": "Database connection string with embedded credentials",
        "description": "Pattern detected: post****",
        "remediation": "Remove credentials from connection strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": 3768,
        "rule_identifier": "SECRET_CONNECTION_STRING",
        "title": "Database connection string with embedded credentials",
        "description": "Pattern detected: post****",
        "remediation": "Remove credentials from connection strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": 3932,
        "rule_identifier": "SECRET_CONNECTION_STRING",
        "title": "Database connection string with embedded credentials",
        "description": "Pattern detected: post****",
        "remediation": "Remove credentials from connection strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "hardcoded_secrets",
        "file_path": "/repo/skills/cloudflare-hyperdrive/references/SKILL.md",
        "line_number": 3942,
        "rule_identifier": "SECRET_CONNECTION_STRING",
        "title": "Database connection string with embedded credentials",
        "description": "Pattern detected: post****",
        "remediation": "Remove credentials from connection strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-hyperdrive/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-hyperdrive/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-queues/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-queues/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-queues/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-queues/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/react-native-expo/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-native-expo/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-native-expo/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/react-native-expo/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/react-native-expo/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/email-gateway/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/email-gateway/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-workflows/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workflows/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-workflows/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workflows/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/ai-sdk-core/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-core/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/ai-sdk-core/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/ai-sdk-core/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-images/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-images/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-images/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-images/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/elevenlabs-agents/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/elevenlabs-agents/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/elevenlabs-agents/assets",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 61% of skill content could be analyzed. 3 of 8 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/elevenlabs-agents/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/elevenlabs-agents/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "prompt_injection",
        "file_path": "/repo/skills/elevenlabs-agents/assets/agent-config-schema.json",
        "line_number": 60,
        "rule_identifier": "ASSET_PROMPT_INJECTION",
        "title": "Role reassignment pattern in asset file",
        "description": "Pattern 'You are now ...' detected in asset file",
        "remediation": "Review the asset file and remove any malicious or unnecessary dynamic patterns"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx",
        "line_number": 14,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx",
        "line_number": 24,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/project-session-management/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-session-management/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/project-session-management/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-session-management/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/project-session-management/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-session-management/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/zustand-state-management/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/zustand-state-management/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/zustand-state-management/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/zustand-state-management/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/django-cloud-sql-postgres/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/django-cloud-sql-postgres/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/django-cloud-sql-postgres/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/django-cloud-sql-postgres/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/firebase-firestore/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-firestore/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/open-source-contributions/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/open-source-contributions/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/open-source-contributions/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/open-source-contributions/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/open-source-contributions/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-r2/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-r2/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-r2/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-r2/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-agents/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-agents/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-agents/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-agents/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/snowflake-platform/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/snowflake-platform/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/snowflake-platform/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/snowflake-platform/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/snowflake-platform/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/firebase-storage/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/firebase-storage/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/jquery-4/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/jquery-4/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/color-palette/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/color-palette/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/color-palette/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/color-palette/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/color-palette/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-spaces-updates/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-spaces-updates/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/agent-development/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/agent-development/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-api/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-api/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/electron-base/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/electron-base/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/electron-base/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/electron-base/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/typescript-mcp/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/typescript-mcp/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/typescript-mcp/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/typescript-mcp/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/typescript-mcp/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/typescript-mcp/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tanstack-start/planning/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-start/planning/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/auto-animate/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/auto-animate/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-kv/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-kv/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-kv/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-kv/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-turnstile/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-turnstile/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-turnstile/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-turnstile/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/neon-vercel-postgres/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/neon-vercel-postgres/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/neon-vercel-postgres/templates",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 36% of skill content could be analyzed. 3 of 5 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/neon-vercel-postgres/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/neon-vercel-postgres/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/skills/neon-vercel-postgres/templates/drizzle-schema.ts",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'drizzle-schema.ts' extension (.ts) suggests one format but Magika detected a different text format: JavaScript source (javascript). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-durable-objects/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-durable-objects/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-durable-objects/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-durable-objects/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/drizzle-orm-d1/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/drizzle-orm-d1/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/drizzle-orm-d1/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/drizzle-orm-d1/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/drizzle-orm-d1/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/drizzle-orm-d1/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/drizzle-orm-d1/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/better-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/better-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/better-auth/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/better-auth/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/better-auth/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/better-auth/assets/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/skills/better-auth/references/nextjs",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 46% of skill content could be analyzed. 1 of 2 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/better-auth/references/nextjs/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/better-auth/references/nextjs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/azure-auth/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/azure-auth/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/azure-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/azure-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/seo-meta/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/seo-meta/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/seo-meta/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/seo-meta/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/seo-meta/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/project-workflow/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/project-workflow/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/hono-routing/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/hono-routing/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/hono-routing/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/hono-routing/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tanstack-query/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-query/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tanstack-query/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-query/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/favicon-gen/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/favicon-gen/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/favicon-gen/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/favicon-gen/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/favicon-gen/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/image-gen/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/image-gen/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/image-gen/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/image-gen/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/image-gen/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/claude-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-api/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/claude-api/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-api/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/clerk-auth/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/clerk-auth/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/clerk-auth/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/clerk-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/clerk-auth/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/clerk-auth/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/clerk-auth/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/accessibility/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/accessibility/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/accessibility/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/accessibility/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/accessibility/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/accessibility/rules/SKILL.md",
        "line_number": 14,
        "rule_identifier": "YARA_script_injection_generic",
        "title": "INJECTION ATTACK detected by YARA",
        "description": "Detects malicious script injection patterns in agent skills: href=\"javascript:v",
        "remediation": "Review and remove injection attack pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/accessibility/rules/SKILL.md",
        "line_number": 200,
        "rule_identifier": "YARA_script_injection_generic",
        "title": "INJECTION ATTACK detected by YARA",
        "description": "Detects malicious script injection patterns in agent skills: <html",
        "remediation": "Review and remove injection attack pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/accessibility/rules/accessibility.md",
        "line_number": 14,
        "rule_identifier": "YARA_script_injection_generic",
        "title": "INJECTION ATTACK detected by YARA",
        "description": "Detects malicious script injection patterns in agent skills: href=\"javascript:v",
        "remediation": "Review and remove injection attack pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/skills/accessibility/rules/accessibility.md",
        "line_number": 200,
        "rule_identifier": "YARA_script_injection_generic",
        "title": "INJECTION ATTACK detected by YARA",
        "description": "Detects malicious script injection patterns in agent skills: <html",
        "remediation": "Review and remove injection attack pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-agents/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-agents/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/streamlit-snowflake/templates-container-runtime/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/streamlit-snowflake/templates-container-runtime/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/streamlit-snowflake/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/streamlit-snowflake/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/streamlit-snowflake/templates-native-app/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/streamlit-snowflake/templates-native-app/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/claude-agent-sdk/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-agent-sdk/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/claude-agent-sdk/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/claude-agent-sdk/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-mcp-server/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-mcp-server/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-mcp-server/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-mcp-server/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-mcp-server/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-mcp-server/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tailwind-patterns/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-patterns/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tailwind-patterns/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-patterns/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/fastmcp/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/fastmcp/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/fastmcp/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/fastmcp/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/fastmcp/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/sub-agent-patterns/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-gemini-embeddings/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-embeddings/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-gemini-embeddings/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-gemini-embeddings/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tailwind-v4-shadcn/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-v4-shadcn/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tailwind-v4-shadcn/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-v4-shadcn/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tailwind-v4-shadcn/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tailwind-v4-shadcn/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-workers-ai/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workers-ai/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-workers-ai/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-workers-ai/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/openai-apps-mcp/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/openai-apps-mcp/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/vercel-kv/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/vercel-kv/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tiptap/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tiptap/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tiptap/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tiptap/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tanstack-table/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-table/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/tanstack-table/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/tanstack-table/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/motion/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/motion/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/motion/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/motion/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-app-engine/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-app-engine/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/google-app-engine/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/google-app-engine/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-vectorize/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-vectorize/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/cloudflare-vectorize/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/cloudflare-vectorize/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/icon-design/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/icon-design/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/icon-design/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/icon-design/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/icon-design/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/office/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/office/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/office/agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/skills/office/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/office/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/.github/ISSUE_TEMPLATE/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.github/ISSUE_TEMPLATE/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name 'Skill Request' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.github/ISSUE_TEMPLATE/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "high",
        "category": "policy_violation",
        "file_path": "/repo/examples/cloudflare-worker-base-test",
        "line_number": null,
        "rule_identifier": "LOW_ANALYZABILITY",
        "title": "Critically low analyzability score",
        "description": "Only 65% of skill content could be analyzed. 6 of 18 files are opaque to the scanner. The safety assessment has low confidence.",
        "remediation": "Replace opaque files (binaries, encrypted content) with inspectable source code to improve scan confidence."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/examples/cloudflare-worker-base-test/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/examples/cloudflare-worker-base-test/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/public/script.js",
        "line_number": 25,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/public/script.js",
        "line_number": 35,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/public/script.js",
        "line_number": 51,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/public/script.js",
        "line_number": 68,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/src/index.ts",
        "line_number": 77,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 217,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 315,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 392,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "data_exfiltration",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 1452,
        "rule_identifier": "DATA_EXFIL_JS_NETWORK",
        "title": "Outbound network request primitives in JavaScript/TypeScript",
        "description": "Pattern detected: fetch(",
        "remediation": "Ensure network operations are necessary and document allowed destinations"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 2263,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: exec(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/examples/cloudflare-worker-base-test/worker-configuration.d.ts",
        "line_number": 7061,
        "rule_identifier": "COMMAND_INJECTION_EVAL",
        "title": "Dangerous code execution functions that can execute arbitrary code",
        "description": "Pattern detected: exec(",
        "remediation": "Avoid eval(), exec(), and compile(). Use safer alternatives like ast.literal_eval() or operator module"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/tools/statusline/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/tools/statusline/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/tools/statusline-npm/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/tools/statusline-npm/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 3,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: require('child_process')",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 21,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 31,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 71,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 79,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "critical",
        "category": "command_injection",
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 107,
        "rule_identifier": "COMMAND_INJECTION_JS_CHILD_PROCESS",
        "title": "Node.js child_process module usage for shell command execution",
        "description": "Pattern detected: spawnSync(",
        "remediation": "Avoid child_process. If required, use execFile with explicit arguments instead of exec with shell strings"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/templates/skill-skeleton/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/templates/skill-skeleton/references/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/archive/deprecated-scripts/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/archive/deprecated-scripts/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/archive/session-logs/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/archive/session-logs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      }
    ],
    "execution_duration_seconds": 113.08886256697588,
    "status": "complete",
    "examined": {
      "unit": "skills",
      "count": 299
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
      "report_type": "cisco-skill-sast",
      "analyzers_used": [
        "bytecode",
        "pipeline",
        "static_analyzer"
      ],
      "skills_scanned": [
        "cloudflare-python-workers",
        "cloudflare-browser-rendering",
        "ai-sdk-ui",
        "cloudflare-worker-base",
        "react-hook-form-zod",
        "tinacms",
        "google-gemini-file-search",
        "openai-assistants",
        "skill-review",
        "responsive-images",
        "sveltia-cms",
        "TanStack Router",
        "openai-responses",
        "firebase-auth",
        "skill-creator",
        "docs-workflow",
        "oauth-integrations",
        "firecrawl-scraper",
        "nextjs",
        "google-workspace",
        "mcp-cli-scripts",
        "google-gemini-api",
        "google-chat-api",
        "wordpress-plugin-core",
        "ts-agent-sdk",
        "project-planning",
        "developer-toolbox",
        "cloudflare-d1",
        "vercel-blob",
        "playwright-local",
        "cloudflare-hyperdrive",
        "cloudflare-queues",
        "react-native-expo",
        "email-gateway",
        "cloudflare-workflows",
        "ai-sdk-core",
        "cloudflare-images",
        "elevenlabs-agents",
        "project-session-management",
        "zustand-state-management",
        "django-cloud-sql-postgres",
        "firebase-firestore",
        "open-source-contributions",
        "cloudflare-r2",
        "openai-agents",
        "snowflake-platform",
        "firebase-storage",
        "jquery-4",
        "color-palette",
        "google-spaces-updates",
        "agent-development",
        "fastapi",
        "openai-api",
        "electron-base",
        "typescript-mcp",
        "TanStack Start",
        "auto-animate",
        "cloudflare-kv",
        "cloudflare-turnstile",
        "neon-vercel-postgres",
        "cloudflare-durable-objects",
        "drizzle-orm-d1",
        "better-auth",
        "azure-auth",
        "seo-meta",
        "project-workflow",
        "hono-routing",
        "tanstack-query",
        "favicon-gen",
        "image-gen",
        "claude-api",
        "clerk-auth",
        "accessibility",
        "cloudflare-agents",
        "MCP OAuth Cloudflare",
        "flask",
        "streamlit-snowflake",
        "claude-agent-sdk",
        "cloudflare-mcp-server",
        "tailwind-patterns",
        "fastmcp",
        "sub-agent-patterns",
        "google-gemini-embeddings",
        "tailwind-v4-shadcn",
        "cloudflare-workers-ai",
        "OpenAI Apps MCP",
        "vercel-kv",
        "tiptap",
        "TanStack Table",
        "motion",
        "google-app-engine",
        "cloudflare-vectorize",
        "icon-design",
        "office",
        "[{'TODO': 'lowercase-hyphen-case-name'}]",
        "repo",
        "planning",
        "profiles",
        "docs",
        "commands",
        "templates",
        "a11y-auditor",
        "clerk-docs",
        "research-logs",
        "references",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "cloudflare-debug",
        "rules",
        "commands",
        "references",
        "rules",
        "references",
        "assets",
        "references",
        "scripts",
        "templates",
        "references",
        "rules",
        "references",
        "references",
        "rules",
        "references",
        "cloudflare-workers",
        "references",
        "rules",
        "references",
        "rules",
        "rules",
        "rules",
        "commands",
        "templates",
        "rules",
        "references",
        "references",
        "rules",
        "commands",
        "references",
        "rules",
        "templates",
        "references",
        "rules",
        "references",
        "references",
        "plugin-simple",
        "plugin-oop",
        "plugin-psr4",
        "references",
        "templates",
        "example-outputs",
        "build-verifier",
        "rules",
        "references",
        "rules",
        "references",
        "references",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "expo-build",
        "assets",
        "references",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "assets",
        "references",
        "rules",
        "templates",
        "references",
        "rules",
        "references",
        "rules",
        "rules",
        "references",
        "pr-prepare",
        "assets",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "snowflake-deploy",
        "rules",
        "rules",
        "rules",
        "references",
        "palette-generator",
        "rules",
        "templates",
        "rules",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "rules",
        "commands",
        "planning",
        "references",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "templates",
        "references",
        "rules",
        "references",
        "drizzle-migrate",
        "rules",
        "commands",
        "rules",
        "commands",
        "assets",
        "nextjs",
        "references",
        "rules",
        "references",
        "seo-generator",
        "rules",
        "commands",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "favicon-crafter",
        "rules",
        "references",
        "image-prompter",
        "rules",
        "references",
        "rules",
        "references",
        "clerk-setup",
        "rules",
        "commands",
        "references",
        "a11y-auditor",
        "rules",
        "rules",
        "references",
        "rules",
        "templates-container-runtime",
        "references",
        "templates-native-app",
        "references",
        "rules",
        "references",
        "rules",
        "commands",
        "references",
        "rules",
        "references",
        "mcp-scaffold",
        "rules",
        "rules",
        "references",
        "rules",
        "references",
        "rules",
        "commands",
        "references",
        "rules",
        "references",
        "references",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "rules",
        "references",
        "icon-selector",
        "rules",
        "references",
        "office-docs",
        "rules",
        "Skill Request",
        "cloudflare-worker-base-test",
        "statusline",
        "statusline-npm",
        "references",
        "deprecated-scripts",
        "session-logs"
      ],
      "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
      "severity_counts": {
        "low": 195,
        "high": 207,
        "medium": 593,
        "critical": 42,
        "informational": 295
      },
      "artifact_type_policy": "claude_skill"
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "agent-audit-kit",
    "scanner_version": "0.3.26",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "scripts/deep-audit-scrape.py",
        "line_number": 156,
        "rule_identifier": "AAK-SECRET-004",
        "title": "Generic high-entropy secret",
        "description": "A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key.",
        "remediation": "Move to environment variables or secrets manager."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "skills/firecrawl-scraper/templates/firecrawl-crawl-example.py",
        "line_number": 36,
        "rule_identifier": "AAK-SECRET-004",
        "title": "Generic high-entropy secret",
        "description": "A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key.",
        "remediation": "Move to environment variables or secrets manager."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "skills/firecrawl-scraper/templates/firecrawl-scrape-python.py",
        "line_number": 37,
        "rule_identifier": "AAK-SECRET-004",
        "title": "Generic high-entropy secret",
        "description": "A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key.",
        "remediation": "Move to environment variables or secrets manager."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "skills/clerk-auth/templates/env-examples/.env.local.vite.example",
        "line_number": 39,
        "rule_identifier": "AAK-SECRET-004",
        "title": "Generic high-entropy secret",
        "description": "A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key.",
        "remediation": "Move to environment variables or secrets manager."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 152,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 173,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 180,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 187,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 203,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 204,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 353,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 354,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 354,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 354,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 354,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 393,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 403,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 410,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 411,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 436,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 438,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 439,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 609,
        "rule_identifier": "AAK-AGENT-002",
        "title": "Agent instructions reference external URLs",
        "description": "Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints.",
        "remediation": "Remove external URL references from agent instructions."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 612,
        "rule_identifier": "AAK-AGENT-002",
        "title": "Agent instructions reference external URLs",
        "description": "Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints.",
        "remediation": "Remove external URL references from agent instructions."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 613,
        "rule_identifier": "AAK-AGENT-002",
        "title": "Agent instructions reference external URLs",
        "description": "Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints.",
        "remediation": "Remove external URL references from agent instructions."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 614,
        "rule_identifier": "AAK-AGENT-002",
        "title": "Agent instructions reference external URLs",
        "description": "Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints.",
        "remediation": "Remove external URL references from agent instructions."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "agent-config",
        "file_path": "CLAUDE.md",
        "line_number": 719,
        "rule_identifier": "AAK-AGENT-002",
        "title": "Agent instructions reference external URLs",
        "description": "Agent instruction files reference external URLs that could serve as C2 channels or data exfiltration endpoints.",
        "remediation": "Remove external URL references from agent instructions."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/ai-sdk-ui/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-worker-base/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tinacms/templates/nextjs/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tinacms/templates/astro/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tinacms/templates/vite-react/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/openai-assistants/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tanstack-router/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/openai-responses/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/nextjs/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/google-gemini-api/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/vercel-blob/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-images/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/openai-agents/templates/shared/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/openai-api/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/neon-vercel-postgres/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-durable-objects/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/hono-routing/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tanstack-query/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/clerk-auth/templates/vite/package.json",
        "line_number": 5,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/claude-agent-sdk/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-mcp-server/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/google-gemini-embeddings/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/openai-apps-mcp/templates/basic/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/vercel-kv/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tiptap/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tanstack-table/templates/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "examples/cloudflare-worker-base-test/package.json",
        "line_number": 2,
        "rule_identifier": "AAK-LEGAL-002",
        "title": "Dependency with no declared license",
        "description": "A dependency has no declared license, creating legal uncertainty about usage rights.",
        "remediation": "Contact the maintainer to clarify licensing or replace with a properly licensed alternative."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 14,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 25,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 48,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 69,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 90,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 105,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 114,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 125,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 135,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 145,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 154,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 164,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 172,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/tinacms/SKILL.md",
        "line_number": 28,
        "rule_identifier": "AAK-SKILL-001",
        "title": "SKILL.md contains a post-install / side-effect command",
        "description": "A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk.",
        "remediation": "Remove the post-install command. If setup is genuinely required, document it for the user rather than auto-running it."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/tinacms/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/google-gemini-file-search/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/openai-responses/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/firebase-auth/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/skill-creator/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/firecrawl-scraper/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/nextjs/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/google-gemini-api/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/playwright-local/SKILL.md",
        "line_number": 902,
        "rule_identifier": "AAK-SKILL-001",
        "title": "SKILL.md contains a post-install / side-effect command",
        "description": "A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk.",
        "remediation": "Remove the post-install command. If setup is genuinely required, document it for the user rather than auto-running it."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/email-gateway/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/ai-sdk-core/SKILL.md",
        "line_number": 198,
        "rule_identifier": "AAK-SKILL-001",
        "title": "SKILL.md contains a post-install / side-effect command",
        "description": "A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk.",
        "remediation": "Remove the post-install command. If setup is genuinely required, document it for the user rather than auto-running it."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/ai-sdk-core/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/elevenlabs-agents/SKILL.md",
        "line_number": 30,
        "rule_identifier": "AAK-SKILL-001",
        "title": "SKILL.md contains a post-install / side-effect command",
        "description": "A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk.",
        "remediation": "Remove the post-install command. If setup is genuinely required, document it for the user rather than auto-running it."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/elevenlabs-agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/django-cloud-sql-postgres/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/openai-agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/openai-api/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/tanstack-start/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/cloudflare-turnstile/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/neon-vercel-postgres/SKILL.md",
        "line_number": 154,
        "rule_identifier": "AAK-SKILL-001",
        "title": "SKILL.md contains a post-install / side-effect command",
        "description": "A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk.",
        "remediation": "Remove the post-install command. If setup is genuinely required, document it for the user rather than auto-running it."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/neon-vercel-postgres/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/better-auth/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/clerk-auth/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/fastmcp/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/google-gemini-embeddings/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/vercel-kv/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/google-app-engine/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-SKILL-003",
        "title": "SKILL.md embeds data-exfiltration primitives",
        "description": "A SKILL.md references outbound HTTP tools (fetch/curl/request) combined with instructions to send local data (files, environment, credentials).",
        "remediation": "Remove the exfil instruction. Skills that genuinely need outbound HTTP should declare it explicitly with a documented purpose."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "tool-poisoning",
        "file_path": "skills/cloudflare-vectorize/SKILL.md",
        "line_number": 519,
        "rule_identifier": "AAK-SKILL-001",
        "title": "SKILL.md contains a post-install / side-effect command",
        "description": "A SKILL.md frontmatter or body declares a post-install or auto-run command (bash, curl, pipe-to-sh, wget). Skills should be declarative; arbitrary installation commands are a rug-pull risk.",
        "remediation": "Remove the post-install command. If setup is genuinely required, document it for the user rather than auto-running it."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/resource-server.ts",
        "line_number": 14,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/tasks-server.ts",
        "line_number": 22,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/basic-mcp-server.ts",
        "line_number": 14,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/tool-server.ts",
        "line_number": 14,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/full-server.ts",
        "line_number": 14,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-agents/templates/mcp-server-basic.ts",
        "line_number": 3,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/mcp-oauth-cloudflare/templates/index.ts",
        "line_number": 14,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 7,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-http-fundamentals.ts",
        "line_number": 27,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-oauth-proxy.ts",
        "line_number": 42,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 15,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 41,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-with-d1.ts",
        "line_number": 60,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-stateful-do.ts",
        "line_number": 9,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/fastmcp/templates/client-example.py",
        "line_number": 153,
        "rule_identifier": "AAK-MCP-018",
        "title": "Missing rate limiting on MCP endpoint",
        "description": "An MCP server endpoint does not declare rate limiting. Unrestricted access allows credential stuffing and enumeration attacks.",
        "remediation": "Add per-IP and per-token rate limits. Reject bursts above the limit with 429."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/basic-mcp-server.ts",
        "line_number": 102,
        "rule_identifier": "AAK-SSRF-001",
        "title": "Unvalidated outbound HTTP in MCP tool handler",
        "description": "An MCP tool handler fetches a URL provided by the caller with no host/scheme validation. This is the classic SSRF shape (CWE-918).",
        "remediation": "Validate the scheme (https only), resolve the host, and reject private-range IPs (RFC 1918, 169.254.*, 127.*, ::1/128, fc00::/7)."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/basic-mcp-server.ts",
        "line_number": 14,
        "rule_identifier": "AAK-SSRF-002",
        "title": "Localhost/loopback reachable from MCP tool",
        "description": "An MCP tool handler forwards user-supplied URLs that could target 127.0.0.1/localhost/::1, reaching internal services bound to loopback.",
        "remediation": "Block loopback and link-local addresses after DNS resolution."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "mcp-config",
        "file_path": "skills/typescript-mcp/templates/basic-mcp-server.ts",
        "line_number": null,
        "rule_identifier": "AAK-SSRF-005",
        "title": "Missing SSRF allowlist on outbound fetch",
        "description": "An MCP tool performs outbound HTTP but has no allowlist of permitted destinations. Deny-by-default with an explicit allowlist is the only reliable defense against SSRF chains.",
        "remediation": "Maintain an explicit allowlist of hostnames; reject anything else."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-oauth-proxy.ts",
        "line_number": 32,
        "rule_identifier": "AAK-SSRF-002",
        "title": "Localhost/loopback reachable from MCP tool",
        "description": "An MCP tool handler forwards user-supplied URLs that could target 127.0.0.1/localhost/::1, reaching internal services bound to loopback.",
        "remediation": "Block loopback and link-local addresses after DNS resolution."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/basic-mcp-server.ts",
        "line_number": 28,
        "rule_identifier": "AAK-SSRF-002",
        "title": "Localhost/loopback reachable from MCP tool",
        "description": "An MCP tool handler forwards user-supplied URLs that could target 127.0.0.1/localhost/::1, reaching internal services bound to loopback.",
        "remediation": "Block loopback and link-local addresses after DNS resolution."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": 194,
        "rule_identifier": "AAK-SSRF-001",
        "title": "Unvalidated outbound HTTP in MCP tool handler",
        "description": "An MCP tool handler fetches a URL provided by the caller with no host/scheme validation. This is the classic SSRF shape (CWE-918).",
        "remediation": "Validate the scheme (https only), resolve the host, and reject private-range IPs (RFC 1918, 169.254.*, 127.*, ::1/128, fc00::/7)."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-with-workers-ai.ts",
        "line_number": null,
        "rule_identifier": "AAK-SSRF-005",
        "title": "Missing SSRF allowlist on outbound fetch",
        "description": "An MCP tool performs outbound HTTP but has no allowlist of permitted destinations. Deny-by-default with an explicit allowlist is the only reliable defense against SSRF chains.",
        "remediation": "Maintain an explicit allowlist of hostnames; reject anything else."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "mcp-config",
        "file_path": "skills/fastmcp/templates/error-handling.py",
        "line_number": 189,
        "rule_identifier": "AAK-SSRF-001",
        "title": "Unvalidated outbound HTTP in MCP tool handler",
        "description": "An MCP tool handler fetches a URL provided by the caller with no host/scheme validation. This is the classic SSRF shape (CWE-918).",
        "remediation": "Validate the scheme (https only), resolve the host, and reject private-range IPs (RFC 1918, 169.254.*, 127.*, ::1/128, fc00::/7)."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "mcp-config",
        "file_path": "skills/fastmcp/templates/error-handling.py",
        "line_number": null,
        "rule_identifier": "AAK-SSRF-005",
        "title": "Missing SSRF allowlist on outbound fetch",
        "description": "An MCP tool performs outbound HTTP but has no allowlist of permitted destinations. Deny-by-default with an explicit allowlist is the only reliable defense against SSRF chains.",
        "remediation": "Maintain an explicit allowlist of hostnames; reject anything else."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": null,
        "rule_identifier": "AAK-OAUTH-005",
        "title": "Bearer token used where DPoP or mTLS is required",
        "description": "An MCP remote server accepts plain Bearer tokens on a flow that MCP spec 2025-11-25 flags for DPoP (Demonstrating Proof of Possession) or mTLS-bound tokens. A stolen Bearer token is fully replayable.",
        "remediation": "Require DPoP proofs or mTLS-bound tokens for high-privilege flows. Validate the token's cnf claim."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": null,
        "rule_identifier": "AAK-OAUTH-005",
        "title": "Bearer token used where DPoP or mTLS is required",
        "description": "An MCP remote server accepts plain Bearer tokens on a flow that MCP spec 2025-11-25 flags for DPoP (Demonstrating Proof of Possession) or mTLS-bound tokens. A stolen Bearer token is fully replayable.",
        "remediation": "Require DPoP proofs or mTLS-bound tokens for high-privilege flows. Validate the token's cnf claim."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "skills/cloudflare-agents/templates/scheduled-agent.ts",
        "line_number": null,
        "rule_identifier": "AAK-TASKS-003",
        "title": "MCP task has no TTL or cancellation path",
        "description": "A task record has no expiration and no cancellation endpoint. Orphaned tasks accumulate forever, including their inputs.",
        "remediation": "Set a TTL on every task; expose a cancellation endpoint that zeroizes inputs and credentials."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "CHANGELOG.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/RESEARCH_FINDINGS_openai-apps-mcp.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/RESEARCH_FINDINGS_google-gemini-file-search.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/RESEARCH_FINDINGS_ai-sdk-ui.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/RESEARCH_FINDINGS_cloudflare-vectorize.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/RESEARCH_FINDINGS_google-gemini-embeddings.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/SKILL_REVIEW_PROCESS.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": ".claude/agents/cloudflare-debug.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "planning/research-logs/session-handoff-protocol.md",
        "line_number": 347,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/research-logs/cloudflare-zero-trust-access.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "planning/research-logs/cloudflare-full-stack-integration.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "planning/research-logs/openai-api.md",
        "line_number": 342,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-worker-base/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/google-gemini-file-search/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/README.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-r2/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/snowflake-platform/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/fastapi/README.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/openai-api/SKILL.md",
        "line_number": 716,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/openai-api/NEXT-SESSION.md",
        "line_number": 111,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/README.md",
        "line_number": 75,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/SKILL.md",
        "line_number": 88,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/favicon-gen/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/flask/README.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/sub-agent-patterns/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/google-gemini-embeddings/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tailwind-v4-shadcn/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/motion/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/ai-sdk-ui/references/top-ui-errors.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-worker-base/agents/cloudflare-debug.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tanstack-router/references/common-errors.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/openai-responses/references/top-errors.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/google-gemini-api/references/code-execution-patterns.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/google-gemini-api/references/grounding-guide.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/developer-toolbox/agents/build-verifier.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/developer-toolbox/agents/debugger.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/developer-toolbox/agents/debugger.md",
        "line_number": 299,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-hyperdrive/references/query-caching.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/references/cost-optimization.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/references/workflow-examples.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/references/compliance-guide.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/references/system-prompt-guide.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/assets/agent-config-schema.json",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/elevenlabs-agents/assets/system-prompt-template.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/django-cloud-sql-postgres/references/migrations-in-production.md",
        "line_number": 166,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/open-source-contributions/references/pr-checklist.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/open-source-contributions/assets/bad-pr-example.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/snowflake-platform/rules/snowflake-jwt-auth.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/snowflake-platform/rules/snowflake-marketplace-listing.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/color-palette/references/dark-mode-palette.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/color-palette/references/contrast-checking.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/openai-api/references/top-errors.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/references/title-patterns.md",
        "line_number": 26,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/references/twitter-cards.md",
        "line_number": 71,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/references/meta-description.md",
        "line_number": 31,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/references/open-graph.md",
        "line_number": 26,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/references/json-ld.md",
        "line_number": 186,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/seo-meta/rules/seo-meta.md",
        "line_number": 10,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tanstack-query/references/top-errors.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/favicon-gen/references/shape-templates.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/favicon-gen/references/monogram-patterns.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/claude-api/references/top-errors.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/clerk-auth/rules/clerk-auth.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-mcp-server/references/debugging-guide.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-mcp-server/references/common-issues.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/google-gemini-embeddings/references/dimension-guide.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tailwind-v4-shadcn/references/common-gotchas.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-workers-ai/rules/cloudflare-workers-ai-prefixes.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/tanstack-table/references/common-errors.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/cloudflare-vectorize/references/embedding-models.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "skills/icon-design/references/semantic-mapping.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "legal-compliance",
        "file_path": "skills/icon-design/references/semantic-mapping.md",
        "line_number": 100,
        "rule_identifier": "AAK-HEALTHCARE-AI-005",
        "title": "Crisis keywords handled without escalation path",
        "description": "A healthcare AI surface mentions suicide / self-harm / crisis but never references 988 / 911 / 112 / 999 / a crisis line. Tennessee HB 1951 (2026) creates criminal liability for encouraging suicide; lacking an escalation path materially worsens the exposure.",
        "remediation": "Add explicit crisis-line escalation instructions in the prompt / system message; test for the most common suicide / self-harm phrases and escalate before generating any other reply."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 23,
        "rule_identifier": "AAK-SPLUNK-TOKLOG-001",
        "title": "Session token written to log sink in cleartext",
        "description": "An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern \u2014 session tokens ended up in the Splunk `_internal` index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius.",
        "remediation": "Redact token-shaped values before logging. Never interpolate a raw `Authorization`, `Bearer`, JWT, `splunkd_session`, or `st-` credential into a log message. Pin `splunk-mcp-server >= 1.0.3`."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 212,
        "rule_identifier": "AAK-SPLUNK-TOKLOG-001",
        "title": "Session token written to log sink in cleartext",
        "description": "An MCP server, agent, or tool logs a session token, JWT, or Bearer credential through a generic log sink (logger.info / .warn / .error, print) without redaction. CVE-2026-20205 (splunk-mcp-server < 1.0.3) shipped this exact pattern \u2014 session tokens ended up in the Splunk `_internal` index, readable by anyone with index-read. Any token written to a log sink is also a supply-chain risk: the log file, shipper, and SIEM are now in scope for the token's blast radius.",
        "remediation": "Redact token-shaped values before logging. Never interpolate a raw `Authorization`, `Bearer`, JWT, `splunkd_session`, or `st-` credential into a log message. Pin `splunk-mcp-server >= 1.0.3`."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "planning/RESEARCH_FINDINGS_drizzle-orm-d1.md",
        "line_number": 253,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": ".claude/agents/d1-migration.md",
        "line_number": 157,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/cloudflare-d1/SKILL.md",
        "line_number": 82,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/drizzle-orm-d1/SKILL.md",
        "line_number": 465,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/better-auth/SKILL.md",
        "line_number": 1678,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/cloudflare-worker-base/agents/d1-migration.md",
        "line_number": 157,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/cloudflare-d1/references/query-patterns.md",
        "line_number": 349,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/cloudflare-d1/references/best-practices.md",
        "line_number": 34,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/cloudflare-hyperdrive/references/query-caching.md",
        "line_number": 78,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "taint-analysis",
        "file_path": "skills/tanstack-table/references/server-side-patterns.md",
        "line_number": 329,
        "rule_identifier": "AAK-IPI-WILD-CORPUS-001",
        "title": "Indirect-prompt-injection wild payload checked into repo",
        "description": "A source / config file (`.md`, `.txt`, `.yml`, `.yaml`, `.json`, `.py`) embeds a known wild IPI payload from the 2026-04-24 Help Net Security + Infosec Magazine catalogue. Common shapes: ignore-prior + exfil, system-role override, reveal-system-prompt, credential exfil via cURL, tool-call rerouting, delete-repository, admin role escalation, obfuscated prompt break, image-attached IPI, RAG-poisoned document. Refresh the corpus with `aak corpus update --ipi`.",
        "remediation": "Remove the payload from the file. If the file is intentionally an attack-corpus fixture, exclude it via `--ignore-paths`. The real risk is checked-in poisoned templates / system-prompt files / RAG seed corpora \u2014 those need to be sanitized at ingestion time, not at scan time."
      }
    ],
    "execution_duration_seconds": 30.177505459985696,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 1595
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
      "report_type": "agent-audit-kit-sast",
      "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
      "rules_evaluated": 211,
      "severity_counts": {
        "low": 0,
        "high": 55,
        "medium": 103,
        "critical": 118,
        "informational": 0
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "bearer",
    "scanner_version": "2.0.2",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 175,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in OS command",
        "description": "## Description\n\nIncorporating unsanitized dynamic input directly into operating system commands poses a significant security risk. This practice could give attackers the opportunity to execute harmful commands on your system.\n\n## Remediations\n\n- **Do** use static, hardcoded values in command strings - wherever possible - to avoid relying on dynamic data.\n  ```javascript\n  let filePattern = \"*.js\";\n  cp.exec(`cp ${filePattern} destinationFolder`, (error, stdout, stderr) => {});\n  ```\n- **Do** san",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/auto-animate/templates/form-validation.tsx",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Usage of hard-coded secret",
        "description": "## Description\n\nStoring secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.\n\n## Remediations\n\n- **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.\n  ```javascript\n    passport.use(new OAuth2Strategy({\n        authorizationURL: 'https://www.example.com/oauth2/authorize',\n        tokenURL: 'https://www.example.com/oauth2/token',\n        clientID: 'my-i",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/auto-animate/templates/form-validation.tsx",
        "line_number": 45,
        "rule_identifier": null,
        "title": "Usage of hard-coded secret",
        "description": "## Description\n\nStoring secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.\n\n## Remediations\n\n- **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.\n  ```javascript\n    passport.use(new OAuth2Strategy({\n        authorizationURL: 'https://www.example.com/oauth2/authorize',\n        tokenURL: 'https://www.example.com/oauth2/token',\n        clientID: 'my-i",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/auto-animate/templates/form-validation.tsx",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Usage of hard-coded secret",
        "description": "## Description\n\nStoring secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.\n\n## Remediations\n\n- **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.\n  ```javascript\n    passport.use(new OAuth2Strategy({\n        authorizationURL: 'https://www.example.com/oauth2/authorize',\n        tokenURL: 'https://www.example.com/oauth2/token',\n        clientID: 'my-i",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 96,
        "rule_identifier": null,
        "title": "Usage of hard-coded secret",
        "description": "## Description\n\nStoring secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.\n\n## Remediations\n\n- **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.\n  ```javascript\n    passport.use(new OAuth2Strategy({\n        authorizationURL: 'https://www.example.com/oauth2/authorize',\n        tokenURL: 'https://www.example.com/oauth2/token',\n        clientID: 'my-i",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 101,
        "rule_identifier": null,
        "title": "Usage of hard-coded secret",
        "description": "## Description\n\nStoring secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.\n\n## Remediations\n\n- **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.\n  ```javascript\n    passport.use(new OAuth2Strategy({\n        authorizationURL: 'https://www.example.com/oauth2/authorize',\n        tokenURL: 'https://www.example.com/oauth2/token',\n        clientID: 'my-i",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/firebase-auth/templates/auth-context.tsx",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Usage of hard-coded secret",
        "description": "## Description\n\nStoring secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.\n\n## Remediations\n\n- **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.\n  ```javascript\n    passport.use(new OAuth2Strategy({\n        authorizationURL: 'https://www.example.com/oauth2/authorize',\n        tokenURL: 'https://www.example.com/oauth2/token',\n        clientID: 'my-i",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/skills/firebase-auth/templates/auth-context.tsx",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Usage of hard-coded secret",
        "description": "## Description\n\nStoring secrets directly in your code is a security risk. Instead, opt for environment variables or a secret management system to safeguard your secrets.\n\n## Remediations\n\n- **Do not** store plaintext secrets in your code. This exposes sensitive information to unnecessary risk.\n  ```javascript\n    passport.use(new OAuth2Strategy({\n        authorizationURL: 'https://www.example.com/oauth2/authorize',\n        tokenURL: 'https://www.example.com/oauth2/token',\n        clientID: 'my-i",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/scripts/deep-audit-bulk.py",
        "line_number": 137,
        "rule_identifier": null,
        "title": "Unsanitized user input in OS command",
        "description": "## Description\n\nDirectly incorporating external or user-defined input into an OS command exposes the system to possible command injection attacks. This vulnerability allows attackers to execute unauthorized commands on the operating system, potentially leading to a compromise of system integrity.\n\n## Remediations\n\n- **Do not** use OS commands that include dynamic input directly. Instead, explore safer alternatives such as libraries or built-in functions that achieve the same goal without executi",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "critical",
        "category": null,
        "file_path": "/repo/scripts/deep-audit-bulk.py",
        "line_number": 176,
        "rule_identifier": null,
        "title": "Unsanitized user input in OS command",
        "description": "## Description\n\nDirectly incorporating external or user-defined input into an OS command exposes the system to possible command injection attacks. This vulnerability allows attackers to execute unauthorized commands on the operating system, potentially leading to a compromise of system integrity.\n\n## Remediations\n\n- **Do not** use OS commands that include dynamic input directly. Instead, explore safer alternatives such as libraries or built-in functions that achieve the same goal without executi",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Unsanitized user input in dynamic HTML insertion (XSS)",
        "description": "## Description\n\nUnsanitized user input in dynamic HTML insertion can lead to Cross-Site Scripting (XSS) attacks. This vulnerability arises when user-provided data is directly inserted into the DOM without proper sanitization, potentially allowing attackers to execute malicious scripts.\n\n## Remediations\n\n- **Do** use an HTML sanitization library to clean user input before inserting it into the HTML. This step helps prevent XSS attacks by removing or neutralizing any potentially harmful scripts.\n ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 64,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 148,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 183,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 210,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 237,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 265,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 273,
        "rule_identifier": null,
        "title": "Unsanitized user input in HTTP request (SSRF)",
        "description": "## Description\n\nConstructing URLs based on user input puts your application at risk of Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate the application into making unintended HTTP requests.\n\n## Remediations\n\n- **Do not** directly incorporate user input into URLs for HTTP requests. This can lead to SSRF vulnerabilities.\n  ```javascript\n  const response = axios.get(`https://${req.params.host}`) // unsafe\n  ```\n- **Do** validate or map user input against",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Usage of manual HTML sanitization (XSS)",
        "description": "## Description\n\nManually sanitizing HTML is prone to mistakes and can lead to Cross-Site Scripting (XSS) vulnerabilities. This occurs when user input is not properly sanitized, allowing attackers to inject malicious scripts into web pages viewed by other users.\n\n## Remediations\n\n- **Do not** manually escape HTML to sanitize user input. This method is unreliable and can easily miss certain exploits.\n  ```javascript\n  const sanitizedUserInput = user.Input\n    .replaceAll('<', '&lt;')\n    .replaceA",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 325,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 329,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 330,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 354,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 12,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 60,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 61,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 160,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 215,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 314,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 318,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/mcp-cli-scripts/templates/script-template.ts",
        "line_number": 144,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 72,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 138,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 174,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 178,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 172,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 172,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 101,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 110,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 118,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nAllowing unsanitized dynamic input in file paths can lead to unauthorized file and folder access. This vulnerability arises when dynamic data is used within the file system operations, potentially allowing attackers to access unauthorized or hidden files and folders.\n\n## Remediations\n\n- **Do** sanitize all dynamic data and function arguments before using them in file system operations. This step is crucial to prevent unauthorized access.\n- **Do** use a combination of hard-coded s",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/screenshot-capture.ts",
        "line_number": 26,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nUsing unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.\n\n## Remediations\n\n- **Do not** directly use user input to construct file paths. This can lead to unauthorized file access.\n- **Do** sanitize user input used in file paths. Replace patterns that can nav",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/screenshot-capture.ts",
        "line_number": 41,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nUsing unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.\n\n## Remediations\n\n- **Do not** directly use user input to construct file paths. This can lead to unauthorized file access.\n- **Do** sanitize user input used in file paths. Replace patterns that can nav",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/screenshot-capture.ts",
        "line_number": 51,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nUsing unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.\n\n## Remediations\n\n- **Do not** directly use user input to construct file paths. This can lead to unauthorized file access.\n- **Do** sanitize user input used in file paths. Replace patterns that can nav",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/screenshot-capture.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Unsanitized dynamic input in file path",
        "description": "## Description\n\nUsing unsanitized dynamic input to determine file paths can allow attackers to gain access to files and folders outside of the intended scope. This vulnerability occurs when input provided by users is directly used to access the filesystem without proper validation or sanitization.\n\n## Remediations\n\n- **Do not** directly use user input to construct file paths. This can lead to unauthorized file access.\n- **Do** sanitize user input used in file paths. Replace patterns that can nav",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts",
        "line_number": 325,
        "rule_identifier": null,
        "title": "Unsanitized user input in raw HTML strings (XSS)",
        "description": "## Description\n\nIncluding unsanitized user input in HTML exposes your application to cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.\n\n## Remediations\n\n- **Do not** include user input directly in HTML strings. This practice can lead to XSS vulnerabilities.\n  ```javascript\n  const html = `<h1>${req.params.title}</h1>` // unsafe\n  ```\n- **Do** use a framework or templating language that automatically handles t",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts",
        "line_number": 651,
        "rule_identifier": null,
        "title": "Unsanitized user input in raw HTML strings (XSS)",
        "description": "## Description\n\nIncluding unsanitized user input in HTML exposes your application to cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.\n\n## Remediations\n\n- **Do not** include user input directly in HTML strings. This practice can lead to XSS vulnerabilities.\n  ```javascript\n  const html = `<h1>${req.params.title}</h1>` // unsafe\n  ```\n- **Do** use a framework or templating language that automatically handles t",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-ui/templates/custom-message-renderer.tsx",
        "line_number": 266,
        "rule_identifier": null,
        "title": "Unsanitized user input in React inner HTML method (XSS)",
        "description": "## Description\n\nUsing React's dangerouslySetInnerHTML with unsanitized data can introduce Cross-Site Scripting (XSS) vulnerabilities. This occurs when external input is embedded directly into the HTML without proper sanitization, allowing attackers to inject malicious scripts.\n\n## Remediations\n\n- **Do** sanitize data before using it with dangerouslySetInnerHTML. This step is crucial to prevent XSS attacks by ensuring that the input does not contain harmful scripts.\n```javascript\n<div dangerously",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/nextjs/templates/app-router-async-params.tsx",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Unsanitized user input in React inner HTML method (XSS)",
        "description": "## Description\n\nUsing React's dangerouslySetInnerHTML with unsanitized data can introduce Cross-Site Scripting (XSS) vulnerabilities. This occurs when external input is embedded directly into the HTML without proper sanitization, allowing attackers to inject malicious scripts.\n\n## Remediations\n\n- **Do** sanitize data before using it with dangerouslySetInnerHTML. This step is crucial to prevent XSS attacks by ensuring that the input does not contain harmful scripts.\n```javascript\n<div dangerously",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "high",
        "category": null,
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Unsanitized user input in React inner HTML method (XSS)",
        "description": "## Description\n\nUsing React's dangerouslySetInnerHTML with unsanitized data can introduce Cross-Site Scripting (XSS) vulnerabilities. This occurs when external input is embedded directly into the HTML without proper sanitization, allowing attackers to inject malicious scripts.\n\n## Remediations\n\n- **Do** sanitize data before using it with dangerouslySetInnerHTML. This step is crucial to prevent XSS attacks by ensuring that the input does not contain harmful scripts.\n```javascript\n<div dangerously",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/server-validation.ts",
        "line_number": 122,
        "rule_identifier": null,
        "title": "Missing Helmet configuration on HTTP headers",
        "description": "## Description\n\nHelmet can help protect your app from some well-known web vulnerabilities by setting HTTP headers appropriately. Failing to configure Helmet for HTTP headers leaves your application vulnerable to several web attacks.\n\n## Remediations\n\n- **Do** use Helmet middleware to secure your app by adding it to your application's middleware.\n  ```javascript\n  const helmet = require(\"helmet\");\n  app.use(helmet());\n  ```\n\n## References\n\n- [Express Security Best Practices: Use Helmet](https://e",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/server-validation.ts",
        "line_number": 122,
        "rule_identifier": null,
        "title": "Missing server configuration to reduce server fingerprinting",
        "description": "## Description\n\nReducing server fingerprinting enhances security by making it harder for attackers to identify the software your server is running. Server fingerprinting involves analyzing the unique responses of server software to specific requests, which can reveal information about the server's software and version. While not a direct security vulnerability, minimizing this information leakage is a proactive step to obscure details that could be used in targeted attacks.\n\n## Remediations\n\n- *",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/transactions.ts",
        "line_number": 150,
        "rule_identifier": null,
        "title": "Leakage of sensitive data in exception message",
        "description": "## Description\n\nLeakage of sensitive data in exception messages can lead to data breaches. This vulnerability occurs when sensitive information is included in exceptions, making it accessible to unauthorized users.\n\n## Remediations\n\n- **Do not** include sensitive data in exception messages. This can inadvertently expose personal or confidential information.\n  ```javascript\n  throw new CustomError(`Error with ${user.email}`) // unsafe\n  ```\n- **Do** use non-sensitive, unique identifiers in except",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/better-auth/references/cloudflare-worker-drizzle.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/better-auth/references/cloudflare-worker-kysely.ts",
        "line_number": 82,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/better-auth/references/nextjs/postgres-example.ts",
        "line_number": 105,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 162,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workflows/templates/basic-workflow.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 359,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 215,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 87,
        "rule_identifier": null,
        "title": "Leakage of sensitive information in logger message",
        "description": "## Description\n\nSensitive information leakage through logger messages can compromise user privacy and security. This vulnerability occurs when sensitive data, such as personal identifiable information (PII), is included in log messages, making it accessible to unauthorized individuals.\n\n## Remediations\n\n- **Do not** include sensitive data in logger messages. This can lead to unintended exposure of private information.\n  ```javascript\n  logger.info(`User is: ${user.email}`) // unsafe\n  ```\n- **Do",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 175,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 61,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 221,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/error-handling.ts",
        "line_number": 87,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 133,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/workers-oauth-utils.ts",
        "line_number": 237,
        "rule_identifier": null,
        "title": "Observable Timing Discrepancy",
        "description": "## Description\n\nObservable Timing Discrepancy occurs when the time it takes for certain operations to complete can be measured and observed by attackers. This vulnerability is particularly concerning when operations involve sensitive information, such as password checks or secret comparisons. If attackers can analyze how long these operations take, they might be able to deduce confidential details, putting your data at risk.\n\n## Remediations\n\n- **Do** implement algorithms that process sensitive ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "medium",
        "category": null,
        "file_path": "/repo/skills/flask/templates/config.py",
        "line_number": 20,
        "rule_identifier": null,
        "title": "Usage of Django debug mode",
        "description": "## Description\n  \nWhen debug mode is enabled, Django displays detailed error pages with stack traces and other sensitive information when an error occurs. While this can be useful during development, debug mode should never be enabled in production or other such environments because it can lead to the exposure of sensitive data to unauthorized users.  \n\n## Remediations\n\n- **Do not** set DEBUG to True in production or other such environments\n```python\nDEBUG = True # not safe for production\n```\n- ",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/pipeline/DataFlowPipeline.ts",
        "line_number": 221,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/auto-animate/templates/react-basic.tsx",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 242,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 205,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/motion/templates/layout-transitions.tsx",
        "line_number": 159,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/motion/templates/layout-transitions.tsx",
        "line_number": 464,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/motion/templates/layout-transitions.tsx",
        "line_number": 469,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/nextjs/templates/proxy-migration.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts",
        "line_number": 32,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts",
        "line_number": 63,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-basic.ts",
        "line_number": 23,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts",
        "line_number": 61,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/stealth-mode.ts",
        "line_number": 36,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/stealth-mode.ts",
        "line_number": 41,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/stealth-mode.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/stealth-mode.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-table/templates/virtualized-large-dataset.tsx",
        "line_number": 24,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-table/templates/virtualized-large-dataset.tsx",
        "line_number": 25,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/typescript-mcp/templates/tasks-server.ts",
        "line_number": 266,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/vercel-kv/templates/simple-rate-limiting.ts",
        "line_number": 82,
        "rule_identifier": null,
        "title": "Usage of insufficient random value",
        "description": "## Description\n\nUsing predictable random values compromises your application's security, particularly if these values serve security-related functions.\n\n## Remediations\n\n- **Do** use a robust library for generating random values to enhance security.\n  ```javascript\n  const crypto = require('crypto');\n  crypto.randomBytes(16).toString('hex');\n  ```",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 16,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 17,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 18,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 19,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 20,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 91,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 131,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 135,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 139,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 142,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 165,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/BUN_V136_INTEGRATION_DEMO.ts",
        "line_number": 169,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 17,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 19,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 169,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 187,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 190,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 192,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 213,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 214,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 227,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 228,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 229,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 249,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 250,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/SQL_WEBSOCKET_INTEGRATION_DEMO.ts",
        "line_number": 279,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 97,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 121,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 138,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 158,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 159,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 175,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 199,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 200,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 201,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/cli/omega-profile.ts",
        "line_number": 202,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 175,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 193,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 194,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 195,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 196,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/performance/CRC32Performance.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/pipeline/DataFlowPipeline.ts",
        "line_number": 295,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3Client.ts",
        "line_number": 271,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3Client.ts",
        "line_number": 290,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3Client.ts",
        "line_number": 302,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3Client.ts",
        "line_number": 303,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3Client.ts",
        "line_number": 307,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 328,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 411,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 418,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 440,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 444,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 448,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 473,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 475,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/s3/OMEGAS3RequesterPays.ts",
        "line_number": 511,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 24,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 25,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 51,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.demo.ts",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelper.ts",
        "line_number": 232,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelperWithDefaults.ts",
        "line_number": 256,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelperWithDefaults.ts",
        "line_number": 350,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelperWithDefaults.ts",
        "line_number": 363,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sql/SQLHelperWithDefaults.ts",
        "line_number": 376,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sqlite/OMEGADatabase.ts",
        "line_number": 414,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sqlite/OMEGADatabase.ts",
        "line_number": 422,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sqlite/OMEGADatabase.ts",
        "line_number": 425,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/sqlite/OMEGADatabase.ts",
        "line_number": 429,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/websocket/OMEGAWebSocketProxy.ts",
        "line_number": 242,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/websocket/OMEGAWebSocketProxy.ts",
        "line_number": 244,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/websocket/OMEGAWebSocketProxy.ts",
        "line_number": 275,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/websocket/OMEGAWebSocketProxy.ts",
        "line_number": 284,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/core/websocket/OMEGAWebSocketProxy.ts",
        "line_number": 292,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/agent-with-tools.ts",
        "line_number": 19,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/agent-with-tools.ts",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/agent-with-tools.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/agent-with-tools.ts",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/agent-with-tools.ts",
        "line_number": 82,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/anthropic-setup.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/anthropic-setup.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/anthropic-setup.ts",
        "line_number": 45,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/anthropic-setup.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/anthropic-setup.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/generate-object-zod.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/generate-object-zod.ts",
        "line_number": 32,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/generate-object-zod.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/generate-object-zod.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/generate-text-basic.ts",
        "line_number": 15,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/generate-text-basic.ts",
        "line_number": 16,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/generate-text-basic.ts",
        "line_number": 17,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/google-setup.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/google-setup.ts",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/google-setup.ts",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/google-setup.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/google-setup.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/google-setup.ts",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/google-setup.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 18,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 36,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 88,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/multi-step-execution.ts",
        "line_number": 103,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/nextjs-server-action.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/openai-setup.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/openai-setup.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/openai-setup.ts",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/openai-setup.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/openai-setup.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/openai-setup.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/stream-object-zod.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/stream-object-zod.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/stream-object-zod.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/stream-text-chat.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/stream-text-chat.ts",
        "line_number": 36,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/tools-basic.ts",
        "line_number": 20,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/tools-basic.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/tools-basic.ts",
        "line_number": 62,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/tools-basic.ts",
        "line_number": 65,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/tools-basic.ts",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/tools-basic.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-core/templates/tools-basic.ts",
        "line_number": 70,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-ui/templates/message-persistence.tsx",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-ui/templates/message-persistence.tsx",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-ui/templates/message-persistence.tsx",
        "line_number": 57,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/ai-sdk-ui/templates/nextjs-chat-app-router.tsx",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/msal-config.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/msal-config.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/msal-config.ts",
        "line_number": 55,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/msal-provider.tsx",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/msal-provider.tsx",
        "line_number": 100,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/protected-route.tsx",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/protected-route.tsx",
        "line_number": 136,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/protected-route.tsx",
        "line_number": 191,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": 154,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/azure-auth/templates/workers-jwt-validation.ts",
        "line_number": 195,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/better-auth/references/cloudflare-worker-drizzle.ts",
        "line_number": 91,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/better-auth/references/cloudflare-worker-kysely.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/better-auth/references/nextjs/postgres-example.ts",
        "line_number": 134,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/better-auth/references/nextjs/postgres-example.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/basic-query.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/basic-query.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/basic-query.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/basic-query.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/basic-query.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/basic-query.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts",
        "line_number": 155,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 31,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 81,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 105,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 127,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 178,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 208,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 257,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 273,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/error-handling.ts",
        "line_number": 278,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": 55,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": 128,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/filesystem-settings.ts",
        "line_number": 169,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 31,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 220,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 258,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 263,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 267,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 272,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 276,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 282,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 283,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 285,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/multi-agent-workflow.ts",
        "line_number": 313,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/permission-control.ts",
        "line_number": 26,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/permission-control.ts",
        "line_number": 45,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/permission-control.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/permission-control.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/permission-control.ts",
        "line_number": 177,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/permission-control.ts",
        "line_number": 199,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/permission-control.ts",
        "line_number": 206,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/query-with-tools.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/query-with-tools.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/query-with-tools.ts",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/query-with-tools.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/query-with-tools.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 54,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 70,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/session-management.ts",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/subagents-orchestration.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/subagents-orchestration.ts",
        "line_number": 96,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-agent-sdk/templates/subagents-orchestration.ts",
        "line_number": 160,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 24,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 59,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/basic-chat.ts",
        "line_number": 96,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 199,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 215,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 262,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 19,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 20,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 21,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 116,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 175,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 178,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 179,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 186,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 201,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 281,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 303,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 336,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/error-handling.ts",
        "line_number": 337,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 36,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 45,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 99,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 103,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 125,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 139,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 188,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 191,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 192,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 196,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 227,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 231,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 280,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 281,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/extended-thinking.ts",
        "line_number": 292,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 32,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 88,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 169,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 236,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nextjs-api-route.ts",
        "line_number": 275,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 110,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 135,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 144,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 176,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 177,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 203,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 230,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/nodejs-example.ts",
        "line_number": 283,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 51,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 113,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 183,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 184,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 224,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 249,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 250,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 251,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/prompt-caching.ts",
        "line_number": 252,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 31,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 117,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 155,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/streaming-chat.ts",
        "line_number": 165,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 19,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 115,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 126,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 144,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 167,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 191,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 195,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 221,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 225,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 230,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 263,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 265,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 117,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 118,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 134,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 177,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 184,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 282,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/tool-use-basic.ts",
        "line_number": 286,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 97,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 151,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 191,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 209,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 243,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 247,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 276,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 308,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 340,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 344,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 352,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/claude-api/templates/vision-image.ts",
        "line_number": 379,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 112,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 126,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 133,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 150,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 189,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 207,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 212,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 223,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 225,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 231,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/scripts/generate-session-token.js",
        "line_number": 235,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/templates/cloudflare/worker-auth.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/templates/cloudflare/worker-auth.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/clerk-auth/templates/cloudflare/worker-auth.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/basic-agent.ts",
        "line_number": 26,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/basic-agent.ts",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/basic-agent.ts",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/basic-agent.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/chat-agent-streaming.ts",
        "line_number": 104,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/chat-agent-streaming.ts",
        "line_number": 105,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/chat-agent-streaming.ts",
        "line_number": 115,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/hitl-agent.ts",
        "line_number": 168,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/hitl-agent.ts",
        "line_number": 232,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/mcp-server-basic.ts",
        "line_number": 148,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx",
        "line_number": 125,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx",
        "line_number": 130,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/react-useagent-client.tsx",
        "line_number": 227,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/scheduled-agent.ts",
        "line_number": 113,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/scheduled-agent.ts",
        "line_number": 127,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/scheduled-agent.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/state-sync-agent.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/state-sync-agent.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/state-sync-agent.ts",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/websocket-agent.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/websocket-agent.ts",
        "line_number": 113,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/websocket-agent.ts",
        "line_number": 120,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/websocket-agent.ts",
        "line_number": 131,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/websocket-agent.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/websocket-agent.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/workflow-agent.ts",
        "line_number": 97,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/workflow-agent.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/workflow-agent.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-agents/templates/workflow-agent.ts",
        "line_number": 120,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts",
        "line_number": 24,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-browser-rendering/templates/session-reuse.ts",
        "line_number": 56,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 139,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 163,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 183,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 274,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 296,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 322,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 342,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 373,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 417,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 452,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 489,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 527,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-d1/templates/d1-worker-queries.ts",
        "line_number": 582,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 51,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 53,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 98,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 175,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 200,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/alarms-api-do.ts",
        "line_number": 223,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 56,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 98,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 116,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 174,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 184,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 188,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/multi-do-coordination.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 136,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-durable-objects/templates/websocket-hibernation-do.ts",
        "line_number": 169,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/drizzle-mysql.ts",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/drizzle-postgres.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/mysql2-basic.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-basic.ts",
        "line_number": 53,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-js.ts",
        "line_number": 97,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/postgres-pool.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-hyperdrive/templates/prisma-postgres.ts",
        "line_number": 137,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 286,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/transform-via-workers.ts",
        "line_number": 293,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/upload-api-basic.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-images/templates/upload-via-url.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-kv/templates/kv-caching-pattern.ts",
        "line_number": 284,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 206,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 32,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 65,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 112,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 126,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 41,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 99,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 127,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 155,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 32,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 41,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 53,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 54,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 55,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 56,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 99,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 168,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 186,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 214,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 112,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 129,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 151,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-retry-with-delay.ts",
        "line_number": 163,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts",
        "line_number": 133,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-multipart-upload.ts",
        "line_number": 165,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts",
        "line_number": 88,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts",
        "line_number": 159,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-presigned-urls.ts",
        "line_number": 219,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts",
        "line_number": 139,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts",
        "line_number": 174,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-r2/templates/r2-simple-upload.ts",
        "line_number": 209,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 57,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 63,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 112,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 211,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx",
        "line_number": 124,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx",
        "line_number": 272,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-react-component.tsx",
        "line_number": 335,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 121,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 159,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 173,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 182,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 214,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 217,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 243,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 244,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 255,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-widget-explicit.ts",
        "line_number": 256,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/basic-search.ts",
        "line_number": 88,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/basic-search.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/basic-search.ts",
        "line_number": 176,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 199,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 211,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 274,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/document-ingestion.ts",
        "line_number": 328,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts",
        "line_number": 206,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/metadata-filtering.ts",
        "line_number": 315,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/rag-chat.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/rag-chat.ts",
        "line_number": 204,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-vectorize/templates/rag-chat.ts",
        "line_number": 265,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-worker-base/templates/public/script.js",
        "line_number": 20,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workers-ai/templates/ai-gateway-integration.ts",
        "line_number": 339,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workers-ai/templates/ai-text-generation.ts",
        "line_number": 288,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workflows/templates/basic-workflow.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts",
        "line_number": 171,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts",
        "line_number": 201,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts",
        "line_number": 190,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts",
        "line_number": 315,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/cloudflare-worker-integration.ts",
        "line_number": 324,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/transactions.ts",
        "line_number": 25,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/transactions.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/drizzle-orm-d1/templates/transactions.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 65,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 100,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 133,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 155,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/electron-base/templates/main.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/electron-base/templates/main.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js",
        "line_number": 31,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js",
        "line_number": 61,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js",
        "line_number": 65,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js",
        "line_number": 72,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js",
        "line_number": 130,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/javascript-sdk-boilerplate.js",
        "line_number": 139,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx",
        "line_number": 26,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx",
        "line_number": 85,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-sdk-boilerplate.tsx",
        "line_number": 96,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 99,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 127,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 211,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/mailgun-webhooks.ts",
        "line_number": 251,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-bulk.ts",
        "line_number": 245,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firebase-auth/templates/api-session.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firebase-auth/templates/api-session.ts",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firebase-auth/templates/api-session.ts",
        "line_number": 117,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 65,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 86,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 88,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 92,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-scrape-typescript.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 223,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 232,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 256,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 266,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 301,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-chat-api/templates/bearer-token-verify.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-chat-api/templates/bearer-token-verify.ts",
        "line_number": 118,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 86,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 115,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 183,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 186,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/code-execution.ts",
        "line_number": 204,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 103,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 111,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 130,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 136,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 137,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 156,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 176,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 239,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 242,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 246,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 253,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/combined-advanced.ts",
        "line_number": 276,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 51,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 60,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 110,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 131,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 138,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/context-caching.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 72,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 82,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 110,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-basic.ts",
        "line_number": 113,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-parallel.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-parallel.ts",
        "line_number": 86,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-parallel.ts",
        "line_number": 125,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/function-calling-parallel.ts",
        "line_number": 128,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 45,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 97,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 104,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 105,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 112,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 116,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 118,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 162,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 168,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 187,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 188,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 202,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 203,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 209,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 227,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 235,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 236,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 238,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 245,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 246,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/grounding-search.ts",
        "line_number": 264,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 72,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-image.ts",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 120,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/multimodal-video-audio.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-chat.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-chat.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 100,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-basic.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-basic.ts",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-basic.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-basic.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-basic.ts",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-basic.ts",
        "line_number": 56,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 120,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/thinking-mode.ts",
        "line_number": 36,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/thinking-mode.ts",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/thinking-mode.ts",
        "line_number": 63,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/thinking-mode.ts",
        "line_number": 64,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/thinking-mode.ts",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/thinking-mode.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-api/templates/thinking-mode.ts",
        "line_number": 97,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/basic-embeddings.ts",
        "line_number": 87,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 53,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 124,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 145,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 150,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 226,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 230,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 231,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 232,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/batch-embeddings.ts",
        "line_number": 235,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 127,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 188,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 192,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 193,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 200,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 203,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 234,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 248,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 251,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 286,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 287,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 288,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 289,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 290,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 291,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/clustering.ts",
        "line_number": 295,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts",
        "line_number": 115,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 199,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 206,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 232,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 255,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 280,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 319,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 117,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 128,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 236,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 237,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 249,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 250,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 261,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 262,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 276,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 277,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-embeddings/templates/semantic-search.ts",
        "line_number": 284,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 72,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 81,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/google-gemini-file-search/scripts/create-store.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 92,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 103,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 172,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 177,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 182,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 187,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 196,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 235,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 279,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 344,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 367,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/context-extension.ts",
        "line_number": 407,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/error-handling.ts",
        "line_number": 134,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/error-handling.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/error-handling.ts",
        "line_number": 232,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/error-handling.ts",
        "line_number": 384,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 255,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 256,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 257,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/middleware-composition.ts",
        "line_number": 284,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 56,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 115,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 120,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 125,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 127,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 163,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 177,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 188,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 210,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/rpc-client.ts",
        "line_number": 233,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/validation-valibot.ts",
        "line_number": 192,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/hono-routing/templates/validation-zod.ts",
        "line_number": 240,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-cli-scripts/templates/script-template.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-cli-scripts/templates/script-template.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-cli-scripts/templates/script-template.ts",
        "line_number": 154,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/index.ts",
        "line_number": 41,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/google-handler.ts",
        "line_number": 111,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 103,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 148,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 42,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 54,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 55,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 85,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/scripts/test-connection.ts",
        "line_number": 91,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/neon-vercel-postgres/templates/drizzle-queries.ts",
        "line_number": 363,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 208,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 215,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 220,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 323,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/office/templates/docx-basic.ts",
        "line_number": 264,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/office/templates/pdf-basic.ts",
        "line_number": 281,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/office/templates/xlsx-basic.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/cloudflare-workers/worker-text-agent.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/nextjs/api-agent-route.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/nextjs/api-realtime-route.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts",
        "line_number": 132,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts",
        "line_number": 137,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-agent-basic.ts",
        "line_number": 150,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts",
        "line_number": 166,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts",
        "line_number": 170,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts",
        "line_number": 174,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts",
        "line_number": 178,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts",
        "line_number": 179,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-handoffs.ts",
        "line_number": 183,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 145,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/realtime-agents/realtime-session-browser.tsx",
        "line_number": 165,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 57,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 62,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 81,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 86,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 87,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 96,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 103,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 129,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 134,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 135,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/error-handling.ts",
        "line_number": 138,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 51,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 81,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 82,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 84,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/shared/tracing-setup.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-basic.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-basic.ts",
        "line_number": 45,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-basic.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-basic.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 138,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 139,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 151,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 154,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 187,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 196,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-input.ts",
        "line_number": 201,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 144,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 145,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 158,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 184,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 185,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 187,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 192,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 198,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 200,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-guardrails-output.ts",
        "line_number": 213,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts",
        "line_number": 109,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts",
        "line_number": 115,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts",
        "line_number": 116,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-handoffs.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 86,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 88,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 91,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 112,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 122,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 169,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-human-approval.ts",
        "line_number": 194,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 63,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 64,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 65,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 70,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 77,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 81,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 82,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 125,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 139,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 144,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 148,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 158,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 163,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 166,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 167,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 173,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 215,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-parallel.ts",
        "line_number": 245,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 59,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 85,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 91,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 92,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 142,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 163,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 166,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-streaming.ts",
        "line_number": 171,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 86,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 88,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 103,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 104,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 105,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 118,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 122,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 124,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 127,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-agents/templates/text-agents/agent-structured-output.ts",
        "line_number": 136,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 53,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 76,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 98,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 134,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 148,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 156,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 163,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 180,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 181,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/chat-completion-basic.ts",
        "line_number": 21,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/chat-completion-nodejs.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/chat-completion-nodejs.ts",
        "line_number": 54,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/chat-completion-nodejs.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/chat-completion-nodejs.ts",
        "line_number": 59,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/chat-completion-nodejs.ts",
        "line_number": 60,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/chat-completion-nodejs.ts",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 55,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 84,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 172,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 192,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 209,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/embeddings.ts",
        "line_number": 213,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/function-calling.ts",
        "line_number": 98,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/function-calling.ts",
        "line_number": 113,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/function-calling.ts",
        "line_number": 118,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/function-calling.ts",
        "line_number": 121,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/function-calling.ts",
        "line_number": 128,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 96,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 134,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 150,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 179,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 199,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 219,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 291,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 55,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 65,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 85,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 132,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 150,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 151,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 173,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 203,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 213,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 222,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 247,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/image-generation.ts",
        "line_number": 287,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 63,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 64,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 109,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 110,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 117,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 142,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 218,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 246,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 289,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 343,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/moderation.ts",
        "line_number": 380,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/rate-limit-handling.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/rate-limit-handling.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 167,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 222,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 241,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 285,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 337,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/structured-output.ts",
        "line_number": 384,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 59,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 162,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 190,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 203,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 233,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 234,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 266,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 307,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 109,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 148,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 174,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 200,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 229,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 282,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 313,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 327,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 340,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 364,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-api/templates/vision-gpt4o.ts",
        "line_number": 396,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 56,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 62,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/basic-assistant.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 61,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 75,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 100,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 120,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 122,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/code-interpreter-assistant.ts",
        "line_number": 133,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 80,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 121,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 160,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 195,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 202,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 203,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/file-search-assistant.ts",
        "line_number": 210,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 98,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 108,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 122,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 129,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 141,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 152,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 160,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 184,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 218,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/function-calling-assistant.ts",
        "line_number": 242,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/streaming-assistant.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/streaming-assistant.ts",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/streaming-assistant.ts",
        "line_number": 99,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/streaming-assistant.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/streaming-assistant.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/streaming-assistant.ts",
        "line_number": 131,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 24,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 41,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 73,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 100,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 151,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 165,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 168,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 172,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 188,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 197,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 202,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 207,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 213,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 214,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/thread-management.ts",
        "line_number": 222,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 37,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 102,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 115,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 131,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 132,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 151,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 158,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 161,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 167,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 178,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 179,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 180,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 189,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 190,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 191,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 199,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 200,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 201,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 220,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 223,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 229,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 230,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 232,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 233,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-assistants/templates/vector-store-setup.ts",
        "line_number": 238,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 25,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 26,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 41,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 56,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 64,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 70,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 92,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 96,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 109,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 112,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 144,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 145,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 146,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 154,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 155,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 156,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 168,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 176,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 182,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 189,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 207,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 211,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 214,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 230,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 237,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/background-mode.ts",
        "line_number": 239,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/basic-response.ts",
        "line_number": 22,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/basic-response.ts",
        "line_number": 26,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/basic-response.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/basic-response.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/basic-response.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/basic-response.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 23,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 60,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 84,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 118,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 135,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 140,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 143,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 144,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 165,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 189,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 191,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 208,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/code-interpreter.ts",
        "line_number": 215,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 24,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 43,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 87,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 110,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 120,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 138,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 145,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 170,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 172,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 173,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 216,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 237,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 249,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 251,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 252,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 253,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 254,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/file-search.ts",
        "line_number": 262,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 22,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 58,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 81,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 83,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 101,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 113,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 129,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 157,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 167,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 177,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 190,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 194,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 198,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 208,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 213,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 230,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 30,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 40,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 62,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 128,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 149,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 153,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 156,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/mcp-integration.ts",
        "line_number": 159,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 25,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 46,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 55,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 104,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 105,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 107,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/stateful-conversation.ts",
        "line_number": 114,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 23,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 28,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 29,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 32,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 34,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 50,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 62,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 84,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 101,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 111,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 123,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 135,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 162,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/openai-responses/templates/web-search.ts",
        "line_number": 185,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/authenticated-session.ts",
        "line_number": 95,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/authenticated-session.ts",
        "line_number": 98,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/basic-scrape.ts",
        "line_number": 44,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/basic-scrape.ts",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/infinite-scroll.ts",
        "line_number": 35,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/infinite-scroll.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/infinite-scroll.ts",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/infinite-scroll.ts",
        "line_number": 90,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/infinite-scroll.ts",
        "line_number": 94,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/pdf-generation.ts",
        "line_number": 19,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/pdf-generation.ts",
        "line_number": 22,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/pdf-generation.ts",
        "line_number": 49,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/pdf-generation.ts",
        "line_number": 61,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/pdf-generation.ts",
        "line_number": 67,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/pdf-generation.ts",
        "line_number": 91,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/pdf-generation.ts",
        "line_number": 93,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/screenshot-capture.ts",
        "line_number": 69,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/stealth-mode.ts",
        "line_number": 82,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/playwright-local/templates/stealth-mode.ts",
        "line_number": 85,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/advanced-form.tsx",
        "line_number": 122,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 57,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 210,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 254,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/async-validation.tsx",
        "line_number": 273,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/basic-form.tsx",
        "line_number": 52,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/basic-form.tsx",
        "line_number": 66,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/basic-form.tsx",
        "line_number": 71,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/basic-form.tsx",
        "line_number": 195,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/custom-error-display.tsx",
        "line_number": 138,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/custom-error-display.tsx",
        "line_number": 274,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/dynamic-fields.tsx",
        "line_number": 51,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/dynamic-fields.tsx",
        "line_number": 219,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/multi-step-form.tsx",
        "line_number": 111,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/server-validation.ts",
        "line_number": 106,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/server-validation.ts",
        "line_number": 155,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/server-validation.ts",
        "line_number": 250,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/shadcn-form.tsx",
        "line_number": 68,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/react-hook-form-zod/templates/shadcn-form.tsx",
        "line_number": 226,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/snowflake-platform/templates/snowflake-rest-client.ts",
        "line_number": 187,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tailwind-patterns/templates/components/contact-form.tsx",
        "line_number": 86,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-query/templates/error-boundary.tsx",
        "line_number": 38,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-query/templates/query-client-config.ts",
        "line_number": 48,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 87,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 134,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 181,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-table/templates/column-configuration.tsx",
        "line_number": 113,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-table/templates/column-configuration.tsx",
        "line_number": 119,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tanstack-table/templates/d1-database-example.tsx",
        "line_number": 78,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tinacms/templates/cloudflare-worker-backend/src/index.ts",
        "line_number": 98,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/tiptap/templates/image-upload-r2.tsx",
        "line_number": 116,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/vercel-blob/templates/avatar-upload-flow.tsx",
        "line_number": 74,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/vercel-blob/templates/avatar-upload-flow.tsx",
        "line_number": 100,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/vercel-blob/templates/drag-drop-upload.tsx",
        "line_number": 147,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/vercel-blob/templates/file-list-manager.tsx",
        "line_number": 47,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/skills/vercel-blob/templates/file-list-manager.tsx",
        "line_number": 79,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 23,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 24,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 25,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 26,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 27,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 33,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 39,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 89,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      },
      {
        "tool_name": "bearer",
        "severity": "low",
        "category": null,
        "file_path": "/repo/tools/statusline-npm/bin/cli.js",
        "line_number": 101,
        "rule_identifier": null,
        "title": "Leakage of information in logger message",
        "description": "## Description\n\nInformation leakage through logger messages can compromise sensitive data. This vulnerability arises when dynamic data or variables, which may contain sensitive information, are included in log messages.\n\n## Remediations\n\n- **Do not** include sensitive data directly in logger messages. This can lead to the exposure of such data in log files, which might be accessible to unauthorized individuals.\n  ```javascript\n  logger.info(`Results: ${data}`) // unsafe\n  ```\n- **Do** use loggin",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 183.28366486699088,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 478
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/Bearer/bearer",
      "report_type": "security",
      "rules_loaded": 554,
      "install_command": "curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh -s -- -b /usr/local/bin \"v2.0.2\"",
      "severity_counts": {
        "low": 1441,
        "high": 52,
        "medium": 20,
        "critical": 10,
        "informational": 0
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-behavioral",
    "scanner_version": "0.1.0",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "dynamic-execution",
        "file_path": "/repo/skills/claude-agent-sdk/templates/custom-mcp-server.ts",
        "line_number": 109,
        "rule_identifier": "opt.nerlo-rules.nerlo-dynamic-exec",
        "title": "opt.nerlo-rules.nerlo-dynamic-exec",
        "description": "Dynamic command or code execution with a non-literal argument (child_process exec / eval / new Function) \u2014 a classic backdoor primitive.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 29,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 29,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 76,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 76,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 183,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 183,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 231,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/claude-api/templates/cloudflare-worker.ts",
        "line_number": 231,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "dynamic-execution",
        "file_path": "/repo/skills/claude-api/templates/tool-use-advanced.ts",
        "line_number": 52,
        "rule_identifier": "opt.nerlo-rules.nerlo-dynamic-exec",
        "title": "opt.nerlo-rules.nerlo-dynamic-exec",
        "description": "Dynamic command or code execution with a non-literal argument (child_process exec / eval / new Function) \u2014 a classic backdoor primitive.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/clerk-auth/templates/react/App.tsx",
        "line_number": 150,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/clerk-auth/templates/react/App.tsx",
        "line_number": 150,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-agents/templates/browser-agent.ts",
        "line_number": 132,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-agents/templates/browser-agent.ts",
        "line_number": 132,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 62,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 62,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 97,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 97,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/batch-upload.ts",
        "line_number": 116,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 68,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/direct-creator-upload-backend.ts",
        "line_number": 167,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-api-basic.ts",
        "line_number": 65,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/upload-via-url.ts",
        "line_number": 63,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 35,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 60,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 79,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 105,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 127,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-images/templates/variants-management.ts",
        "line_number": 147,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-mcp-server/templates/mcp-bearer-auth.ts",
        "line_number": 193,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 76,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-basic.ts",
        "line_number": 76,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 107,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-consumer-explicit-ack.ts",
        "line_number": 107,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/cloudflare-queues/templates/queues-dlq-pattern.ts",
        "line_number": 126,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-hono-route.ts",
        "line_number": 39,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-turnstile/templates/turnstile-server-validation.ts",
        "line_number": 82,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/basic-workflow.ts",
        "line_number": 76,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts",
        "line_number": 163,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/scheduled-workflow.ts",
        "line_number": 222,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts",
        "line_number": 71,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts",
        "line_number": 174,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-events.ts",
        "line_number": 204,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts",
        "line_number": 78,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts",
        "line_number": 120,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/cloudflare-workflows/templates/workflow-with-retries.ts",
        "line_number": 186,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 113,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 113,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 144,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 144,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 184,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 184,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 215,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/electron-base/templates/ipc-handlers/auth.ts",
        "line_number": 215,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/electron-base/templates/main.ts",
        "line_number": 140,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/electron-base/templates/main.ts",
        "line_number": 144,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/elevenlabs-agents/assets/react-native-boilerplate.tsx",
        "line_number": 14,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 110,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 153,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/mailgun-send.ts",
        "line_number": 196,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/resend-basic.ts",
        "line_number": 48,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-basic.ts",
        "line_number": 48,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-react-email.tsx",
        "line_number": 120,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/resend-react-email.tsx",
        "line_number": 152,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/resend-react-email.tsx",
        "line_number": 152,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 29,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 29,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 68,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-dynamic-template.ts",
        "line_number": 68,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-transactional.ts",
        "line_number": 61,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/sendgrid-transactional.ts",
        "line_number": 61,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-bulk.ts",
        "line_number": 55,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-bulk.ts",
        "line_number": 55,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 116,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 116,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 179,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/email-gateway/templates/smtp2go-send.ts",
        "line_number": 179,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/fastmcp/templates/openapi-integration.py",
        "line_number": 31,
        "rule_identifier": "opt.nerlo-rules.nerlo-py-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-py-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (requests / httpx / urllib / socket). This is the postmark-mcp supply-chain exfiltration shape: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 94,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 94,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 126,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 126,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/firecrawl-scraper/templates/firecrawl-worker-fetch.ts",
        "line_number": 150,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-chat-api/templates/bearer-token-verify.ts",
        "line_number": 82,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 91,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 91,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 148,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/cloudflare-worker.ts",
        "line_number": 148,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 31,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 31,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 134,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/streaming-fetch.ts",
        "line_number": 134,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 25,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 25,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 99,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-api/templates/text-generation-fetch.ts",
        "line_number": 99,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts",
        "line_number": 72,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/embeddings-fetch.ts",
        "line_number": 72,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 91,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 91,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 124,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-gemini-embeddings/templates/rag-with-vectorize.ts",
        "line_number": 124,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 79,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 79,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 99,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 99,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 127,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 127,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 165,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/google-workspace/templates/oauth-worker.ts",
        "line_number": 165,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/hono-routing/templates/error-handling.ts",
        "line_number": 215,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 87,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 141,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/mcp-oauth-cloudflare/templates/oauth/utils.ts",
        "line_number": 141,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/app-router-async-params.tsx",
        "line_number": 167,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 18,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 77,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 163,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 171,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 215,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 228,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 247,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 256,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 267,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/cache-component-use-cache.tsx",
        "line_number": 271,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/parallel-routes-with-default.tsx",
        "line_number": 109,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 17,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 26,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 123,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 123,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 160,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 160,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/route-handler-api.ts",
        "line_number": 315,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/server-actions-form.tsx",
        "line_number": 28,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/server-actions-form.tsx",
        "line_number": 102,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/server-actions-form.tsx",
        "line_number": 322,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/server-actions-form.tsx",
        "line_number": 399,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/nextjs/templates/server-actions-form.tsx",
        "line_number": 504,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 43,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/audio-transcription.ts",
        "line_number": 43,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/cloudflare-worker.ts",
        "line_number": 42,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/cloudflare-worker.ts",
        "line_number": 42,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 30,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 30,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 58,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 58,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 86,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 86,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 99,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 124,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 124,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 140,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 140,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 169,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 169,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 189,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 189,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 209,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 209,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 269,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/image-editing.ts",
        "line_number": 269,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/rate-limit-handling.ts",
        "line_number": 72,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/rate-limit-handling.ts",
        "line_number": 72,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/streaming-fetch.ts",
        "line_number": 17,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/streaming-fetch.ts",
        "line_number": 17,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 242,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-api/templates/text-to-speech.ts",
        "line_number": 242,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 55,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 55,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 108,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 108,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/cloudflare-worker.ts",
        "line_number": 227,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/openai-responses/templates/image-generation.ts",
        "line_number": 132,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/tanstack-query/templates/custom-hooks-pattern.tsx",
        "line_number": 22,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/tanstack-query/templates/custom-hooks-pattern.tsx",
        "line_number": 34,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-basic.tsx",
        "line_number": 23,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/tanstack-query/templates/use-mutation-optimistic.tsx",
        "line_number": 40,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/tanstack-query/templates/use-query-basic.tsx",
        "line_number": 18,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/client.ts",
        "line_number": 92,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "dynamic-execution",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 175,
        "rule_identifier": "opt.nerlo-rules.nerlo-dynamic-exec",
        "title": "opt.nerlo-rules.nerlo-dynamic-exec",
        "description": "Dynamic command or code execution with a non-literal argument (child_process exec / eval / new Function) \u2014 a classic backdoor primitive.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/ts-agent-sdk/templates/db/client.ts",
        "line_number": 210,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "high",
        "category": "data-exfiltration",
        "file_path": "/repo/skills/typescript-mcp/templates/tool-server.ts",
        "line_number": 55,
        "rule_identifier": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "title": "opt.nerlo-rules.nerlo-js-secret-to-network-egress",
        "description": "A secret / environment variable / token value flows into a network request (fetch / axios / XMLHttpRequest). This is the postmark-mcp supply-chain exfiltration shape reproduced in Node/JS: a credential read from the environment is shipped off-box. Confirm the egress is expected and the value is not being exfiltrated to an attacker-controlled host.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-behavioral",
        "severity": "informational",
        "category": "undisclosed-egress",
        "file_path": "/repo/skills/zustand-state-management/templates/async-actions-store.ts",
        "line_number": 128,
        "rule_identifier": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "title": "opt.nerlo-rules.nerlo-hardcoded-external-egress",
        "description": "Egress inventory: this network request's destination is a literal in source, not a configured value. For an API-wrapping MCP server that is the normal shape, so on its own it is CONTEXT, not a verdict \u2014 it is recorded at INFO so a reviewer can see the artifact's whole outbound surface in one place. What would make a literal destination a finding is that it does not match the artifact's declared purpose, which this pattern cannot determine.",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 31.95052539301105,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 448
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-behavioral",
      "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/exfiltration.yaml",
        "/opt/nerlo-rules/clipboard_exfiltration.yaml",
        "/opt/nerlo-rules/rce_endpoint.yaml",
        "/opt/nerlo-rules/taint_egress.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "severity_counts": {
        "low": 0,
        "high": 87,
        "medium": 0,
        "critical": 0,
        "informational": 96
      },
      "merged_invocation": true
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-install-instruction",
    "scanner_version": "0.1.0",
    "score": 59.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/CLAUDE.md",
        "line_number": 297,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/CONTRIBUTING.md",
        "line_number": 363,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/VERSIONS_REPORT.md",
        "line_number": 72,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/docs/MARKETPLACE.md",
        "line_number": 298,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/planning/RESEARCH_FINDINGS_openai-assistants.md",
        "line_number": 315,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "high",
        "category": "install-instruction-exec",
        "file_path": "/repo/planning/RESEARCH_FINDINGS_playwright-local.md",
        "line_number": 425,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/planning/gemini-skills-verification-2025-10-26.md",
        "line_number": 261,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/skills/open-source-contributions/scripts/clean-branch.sh",
        "line_number": 179,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/skills/open-source-contributions/scripts/pre-pr-check.sh",
        "line_number": 247,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/skills/openai-assistants/SKILL.md",
        "line_number": 164,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/skills/skill-review/SKILL.md",
        "line_number": 36,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "informational",
        "category": "install-instruction-run",
        "file_path": "/repo/skills/sub-agent-patterns/SKILL.md",
        "line_number": 158,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Run-directive inventory: documentation names a run/execute/launch verb next to an opaque-extension artifact (\"run resource.txt\", \"double-click setup.exe\") \u2014 the FakeGit README shape. On its own it is CONTEXT, not a verdict: the same shape covers a repo's own tracked scripts and its toolchain, which this pattern cannot tell from a bundled payload. Recorded at INFO so a reviewer sees every run directive in one place.",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 31.97067104600137,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 1605
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-install-instruction",
      "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/install_instructions.yaml",
        "/opt/nerlo-rules/cursor_rules.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "severity_counts": {
        "low": 0,
        "high": 1,
        "medium": 0,
        "critical": 0,
        "informational": 11
      },
      "merged_invocation": true
    },
    "display_score": 59.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "capslock",
    "scanner_version": "v0.3.2",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.2607291169697419,
    "status": "not_applicable",
    "examined": {
      "unit": "packages",
      "count": 0
    },
    "metadata": {
      "source": "go-module-proxy",
      "source_url": "https://github.com/google/capslock/releases/tag/v0.3.2",
      "report_type": "go-capability",
      "vendor_mode": false,
      "install_command": "GOTOOLCHAIN=local GOFLAGS=-mod=mod GOSUMDB=sum.golang.org GOBIN=/usr/local/bin go install github.com/google/capslock/cmd/capslock@v0.3.2  # github.com/google/capslock v0.3.2 h1:0ZQa9YR8s9ewFu1g5w6Rgd/lW/4dga7qJew3K6Ql7aM=",
      "environment_note": "capslock found no .go files to analyze; reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute",
      "go_files_present": 0,
      "artifact_type_policy": "claude_skill",
      "expected_capabilities": null,
      "artifact_type_explicit": true
    },
    "display_score": null,
    "display_badge": "not_applicable"
  }
]
```
